๐จ ACTIVE EXPLOITATION
-
UPDATE: CISA Warns Apache Tomcat CVE-2026-34486 Is Under Active Exploitation
CVE-2026-34486CISA added an actively exploited Apache Tomcat encryption flaw to its KEV catalog.- Apache Tomcat deployments using clustered communications are affected, especially internet-facing servers.
- Tomcat 11.0.20, 10.1.53, and 9.0.116 contain CVE-2026-34486.
- Crafted messages bypass the EncryptInterceptor and expose cluster traffic to unencrypted or improperly encrypted communication.
- Unit 42 observed a Chinese-speaking threat actor attempting Java deserialization-based reverse shells against vulnerable servers. ๐ Source: cisa.gov ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
QuickFox Supply-Chain Attack Delivered FDMTP via Trojanized Windows Installers A QuickFox supply-chain attack delivered the FDMTP backdoor through trojanized Windows installers.
- Windows users of QuickFox, a VPN and network acceleration tool popular with overseas Chinese users, were targeted.
- QuickFox version 3.0.51.0 was the earliest affected release; version 3.59.6 removed the malicious components.
- A modified Electron renderer HTML file downloaded an obfuscated JavaScript loader from cdns3.51quickfox[.]cn.
- The loader fingerprinted endpoints, checked running processes, and used DLL side-loading to deploy FDMTP; later payloads stored the implant in encrypted update.bin files. ๐ Source: fortinet.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ CVEs & KEV
- CVE-2026-18898 โ CVSS 7.4 โ UTT HiPER 1200GW ConfigAdvideo strcpy stack-based overflowA security flaw has...
- CVE-2026-18901 โ CVSS 7.3 โ H3C NX15 Web API esps service.add routineA security vulnerability has been de...
- CVE-2026-18900 โ CVSS 7.3 โ H3C NX15 Backend RPC esps file.exec os command injectionA weakness has been i...
๐ ADVISORIES
- Botnet Probes Router Diagnostic Tools for Command Injection โ Source: isc.sans.edu