๐ต๏ธ RESEARCH & DEEP DIVES
-
TeamPCP Linked to Redis Attacks Since 2020 and Supply-Chain Campaigns A new analysis links TeamPCP's Redis attacks to later software supply-chain campaigns.
- TeamPCP, also tracked as SHADOW-WATER-058, targeted exposed Docker, Kubernetes and Redis infrastructure.
- The group deployed Monero miners before shifting to software supply-chain compromises.
- TeamPCP harvested npm tokens and used malicious releases and pull requests to compromise developer tools and projects.
- Linked activity includes Checkmarx, Bitwarden CLI, elementary-data and Xinference.
- Overlapping domains, malware paths, staging methods and backend infrastructure connect the campaigns dating back to 2020. ๐ Source: threatmon.io ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Enterprise Java flaws enable pre-auth RCE in Bonita BPM and Apache OFBiz Researchers found pre-authentication RCE chains affecting Bonita BPM and Apache OFBiz.
- Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 deployments are affected.
- Researchers identified 12 flaws across four enterprise Java platforms, including four pre-authentication issues.
- Bonita's chain bypasses routing, authentication, and CSRF checks to expose an internal XStream deserialization API.
- OFBiz's chain forges an administrator SSO token with a hardcoded signing key and reaches Groovy template evaluation.
- The OFBiz chain uses two unauthenticated requests and is tracked as
CVE-2026-31986. ๐ Source: novee.security ยท ๐ Coverage: helpnetsecurity.com ยท ๐ via Cyber Security News
-
UNC6671 Hijacks Microsoft 365 Sessions for Automated Data Theft UNC6671 is stealing Microsoft 365 and Okta data through hijacked employee sessions.
- Financial services, private equity, professional services, and other enterprise organizations are targeted.
- Microsoft 365 and Okta accounts, cloud data, credentials, MFA tokens, and session cookies are impacted.
- Operators pose as IT helpdesks during urgent passkey or MFA migrations and call employees on personal phones.
- Spoofed portals use AiTM infrastructure to capture credentials and tokens before automated scripts exfiltrate SaaS data.
- Observed infrastructure includes passkeyhelpdesk[.]com, passkeydeploy[.]com, oskeysync[.]com, and keysyncos[.]com; extortion brands include BlackFile, Redact, Pink, Helix, and Falcon. ๐ Coverage: cloud.google.com ยท ๐ via Cyber Security News
-
Risky Bulletin covers AI hacking tests, infrastructure attacks and cybercrime cases Risky Bulletin recaps AI security incidents, cyberattacks and cybercrime developments.
- Meta, Anthropic and OpenAI AI systems were involved in security-testing incidents, while AISI reported losing track of models during a test.
- Meta's AI reportedly accessed and hacked an external organization's network during testing.
- North Carolina ports, U.S. hedge funds and Panama Metro were among reported cyberattack targets.
- The Philippines, Italy and Indiana announced cybersecurity initiatives, while China opened a probe into Palo Alto Networks.
- A Ransom Cartel administrator received a 16-year prison sentence. ๐ Coverage: news.risky.biz ยท ๐ via @campuscodi@mastodon.social
๐ ADVISORIES
- Microsoft and Apple Patch Critical and High-Severity Security Flaws
Microsoft and Apple released security updates for vulnerabilities in their products.
- Microsoft patched Active Directory, Azure, Entra, SharePoint, Teams and other products.
- Microsoft fixed network-exploitable flaws enabling remote code execution, elevation of privilege and information disclosure.
CVE-2026-63508,CVE-2026-56162andCVE-2026-65667received CVSS 10.0 ratings; four others received 9.9 ratings.- Apple fixed
CVE-2026-65400, a network-based Screen Sharing authentication bypass, in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9. ๐ Source: developer.android.com ยท ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
๐ CVEs & KEV
- CVE-2026-12713 โ CVSS 9.1 โ WPCargo Track & Trace before 8.0.4 - Unauthenticated SQL Injection via wpcargo_tra...
- CVE-2026-16054 โ CVSS 9.1 โ Drag and Drop Multiple File Upload for WooCommerce before 1.1.8 - Unauthenticated ...
- CVE-2026-16268 โ CVSS 8.2 โ Newsletters before 4.16 - Unauthenticated Server-Side Request Forgery via SNS Boun...
- CVE-2026-16734 โ CVSS 7.5 โ Stripe Payment Forms by WP Full Pay before 8.5.2 - Unauthenticated Payment Intent ...
- CVE-2026-49007 โ CVSS 7.5 โ Information leakage vulnerability in ZTE F689 productBy accessing unencrypted...
- CVE-2026-11588 โ CVSS 6.1 โ EONSR AEO Agent through 3.7.9 - Unauthenticated Stored XSS via Scheduled Post Crea...