๐จ ACTIVE EXPLOITATION
-
CISA warns of cyberattacks disrupting US water utilities via exposed PLCs CISA warns of increased cyberattacks targeting internet-exposed programmable logic controllers (PLCs) in US water utilities, causing operational disruptions.
- Targets: Water and wastewater systems sector in the US, including over 30 Minnesota community water systems
- Vulnerabilities: Internet-exposed PLCs and operational technology (OT), including undocumented cellular modems
- Attack methods: Changing PLC passwords to lock out operators, modifying IP addresses to disconnect devices
- Exposure: Over 4,100 Rockwell Automation/Allen-Bradley, 4,100 Siemens, and 2,000 Schneider Electric hosts exposed online
- Notable affected devices: Rockwell Automation MicroLogix 1400 PLCs, many running end-of-sale firmware versions ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
-
Chinese threat actor uses DeepSeek AI for autonomous cyberattacks on exposed servers A Chinese threat actor used DeepSeek AI and Hermes Agent to autonomously attack vulnerable servers running Langflow and n8n workflow automation platforms.
- Targets: Internet-exposed servers running Langflow and n8n platforms
- Vulnerabilities: CVE-2026-33017 (Langflow), CVE-2026-21858 and CVE-2025-68613 (n8n), plus Citrix NetScaler CVE-2026-3055
- Attack method: DeepSeek AI-driven Hermes Agent scanned, selected exploits, and attempted attacks without human feedback
- Scale: Identified 84 Langflow and 647,000 n8n exposed instances via FOFA search engine
- Outcome: Autonomous attacks failed to compromise targets, but manual attacks succeeded on 3 Citrix NetScaler systems extracting session cookies ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ต๏ธ RESEARCH & DEEP DIVES
-
pgAdmin 4 OS command injection via MASTER_PASSWORD_HOOK username substitution (CVE-2026-17347)
CVE-2026-17347pgAdmin 4's MASTER_PASSWORD_HOOK setting allows OS command injection via untrusted username substitution from external authentication sources.- Applies to pgAdmin 4 versions from 7.2 before 9.17 with MASTER_PASSWORD_HOOK enabled
- Vulnerability in MASTER_PASSWORD_HOOK executes external commands with %u replaced by username
- Usernames from OAuth/OIDC, Kerberos, or webserver auth can include shell metacharacters
- Allows authenticated users to execute arbitrary OS commands as the pgAdmin service account
- Exploit requires non-default configuration using %u and external identity provider usernames ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm A spear-phishing attack used HollowFrame loader to deploy Matryoshka backdoor on law firm endpoints.
- Targets: Two endpoints at an unspecified law firm
- Initial vector: Spear-phishing email with link to encrypted archive containing a malicious Windows Shortcut (LNK)
- Loader: HollowFrame, a Go-based modular loader using DLL side-loading with python.exe and rogue python311.dll
- Backdoor: Matryoshka, a Rust-based malware with HTTP and GitHub-based C2 variants for command execution and payload delivery
- Evasion: Anti-analysis checks based on system uptime, memory, file count, and cursor movement; persistence via scheduled tasks ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ CVEs & KEV
- Other: 19 CVEs (worst 9.9)