View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Alinto SOGo 5.12.7 hit by actively exploited ICS invitation XSS

๐Ÿšจ ACTIVE EXPLOITATION

  • Alinto SOGo 5.12.7 hit by actively exploited ICS invitation XSS CVE-2026-8496 Attackers are exploiting an XSS flaw in Alinto SOGo 5.12.7 through malicious ICS invitations.
    • Alinto SOGo 5.12.7 deployments and their webmail and calendar users are affected.
    • CVE-2026-8496 exposes the ICS DESCRIPTION field to XSS, enabling mailbox and contact-data theft.
    • Attackers email malformed calendar invitations containing SVG JavaScript event handlers.
    • The payload executes when a user views or previews the calendar, without further interaction.
    • VirusTotal sightings indicate the flaw has been exploited in the wild; SOGo 5.12.8 contains the fix. ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: kb.cert.org ยท ๐Ÿ‘ via CERT/CC Vulnerability Notes

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Swiss FOITT SharePoint breach compromised about 200 accounts Swiss FOITT says attackers compromised about 200 SharePoint accounts.
    • Switzerland's Federal Office for Information Technology and Telecommunications was affected.
    • On-premises Microsoft SharePoint servers were breached, compromising user and technical account credentials.
    • Attackers allegedly exploited SharePoint vulnerabilities disclosed in July 2026; the exact flaw remains unknown.
    • Potentially relevant flaws include CVE-2026-56164 and CVE-2026-50522, but neither has been confirmed as the entry point. ๐Ÿ“Ž Coverage: therecord.media ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • TONTOU Attack Bypasses Spectre v2 Defenses and Leaks Linux Password Hashes MIT researchers demonstrated a local interrupt-injection attack that bypasses Spectre v2 defenses.

    • Linux systems on AMD Zen 1 through Zen 4 processors are affected; testing used Linux 6.14 on Zen 2.
    • The attack leaked arbitrary kernel memory and accessed /etc/shadow password hashes at 5.47 bytes per second with 91.97% accuracy.
    • Unprivileged local code schedules hardware interrupts between Spectre v2 mitigation and kernel use.
    • The technique re-poisons the branch predictor using the Inception primitive (CVE-2023-20569). ๐Ÿ“„ Source: people.csail.mit.edu ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • SilverFox Uses Three-Driver BYOVD Chain to Deliver ValleyRAT in Japan SilverFox targeted a Japanese manufacturer with a BYOVD chain delivering ValleyRAT.

    • The campaign targeted a Japanese organization in the industrial manufacturing sector.
    • SilverFox used BootRepair.sys, EnPortv.sys, and wsftprm.sys to impair security controls at kernel level.
    • An invoice-themed phishing email delivered a ZIP archive through QQ and Tencent Cloud services.
    • PDFCORE8.dll was sideloaded by ConvertToPDF.exe or PDFDirect.exe, then injected ValleyRAT into svchost.exe.
    • The loader contacted 43.128.26[.]132 and used NTDLL unhooking plus watchdog recovery mechanisms to maintain execution. ๐Ÿ“„ Source: catonetworks.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via Cyber Security News
  • Violent crypto attacks steal over $30 million in H1 2026 Chainalysis says violent attacks stole more than $30 million from crypto holders in H1 2026.

    • Crypto holders worldwide were targeted, with France recording 30 publicly known incidents.
    • Chainalysis documented 46 violent attacks through late June, including kidnappings, home invasions and hostage situations.
    • Home invasions accounted for 37% of incidents, while family members or associates were targeted in roughly 25%โ€“30% of cases.
    • Attackers used leaked personal data to identify crypto holders and their relatives, then forced transfers through physical threats.
    • Stolen funds were moved through centralized exchanges, decentralized exchanges, cross-chain bridges and laundering networks. ๐Ÿ“„ Source: chainalysis.com ยท ๐Ÿ“Ž Coverage: theblock.co ยท ๐Ÿ‘ via @campuscodi@mastodon.social

๐Ÿ“‹ ADVISORIES

  • Canadian hacker pleads guilty in Snowflake data extortion campaign โ€” cloud.google.com
  • Ransom Cartel creator Maksim Silnikau sentenced to 16 years โ€” justice.gov

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check