๐จ ACTIVE EXPLOITATION
-
Leaked DarkSword iOS Exploit Kit Spreads Across 180 Web Properties A Chinese-speaking operator is deploying leaked DarkSword against iOS devices.
- Apple iPhones running iOS 18.4 through 18.7 are targeted.
- DarkSword chains six vulnerabilities to deploy GHOSTBLADE and steal keychain, iCloud, Wi-Fi credentials, and files.
- Fake AWS console and Apple ID pages use hidden iframes to trigger version-specific JavaScript exploits.
- Censys identified 27 hosts and 180 web properties, including 103.106.190[.]217 and staging-page hash 50582f8d52e49f549615ec7cd68629b9f939a0cfc5c5408f324b2f1cff070e99.
- A related Singapore host combined DarkSword with Coruna, an older kit targeting iOS 3.0 through 17.2.1. ๐ Source: censys.com ยท ๐ Coverage: gbhackers.com ยท ๐ via Dark Reading
-
Gunra Affiliates Exploit Fortinet VPN Flaws to Bypass MFA Gunra affiliates are exploiting Fortinet VPN flaws to deploy ransomware.
- Targets include government, critical infrastructure, healthcare, finance, manufacturing, transportation, utilities, and other organizations.
- Fortinet FortiOS and FortiProxy appliances affected by
CVE-2024-55591andCVE-2025-24472are targeted. - Attackers tamper with VPN or VDI authentication files to bypass MFA, then use Impacket tools for lateral movement and credential dumping.
- Gunra exfiltrates data from OneDrive and SharePoint to Mega before encrypting files with ChaCha20 and RSA-4096.
- Encrypted files receive the .ENCRT extension, with ransom notes named R3ADM3.txt; observed tooling includes main.exe, 7-Zip, RClone, and FileZilla. ๐ Source: cisa.gov ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via CISA Advisories, Cyber Security News
-
Storm-1175 Deploys StormEncryptor Ransomware via Likely N-central Exploit Storm-1175 has begun deploying the new StormEncryptor ransomware strain.
- Storm-1175 is targeting N-able N-central environments used by managed service providers.
- StormEncryptor encrypts files and appends .encrypted, while creating !!!README_FIRST!!!.txt ransom notes.
- The campaign likely exploits
CVE-2026-18577, an authentication-bypass flaw disclosed on August 2, 2026. - Operators used AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz to maintain access, map networks, and steal credentials.
- SHA-256: c19ded65e822bb43ad0381c58abf33b7c8890f7bcc7125058a0c849c7e1a6054; Microsoft detects it as Ransom:Win64/StormEncryptor. ๐ Source: bsky.app ยท ๐ Coverage: gbhackers.com ยท ๐ via BleepingComputer
๐ต๏ธ RESEARCH & DEEP DIVES
-
Malicious commits compromised the use-context-selector React package
CVE-2026-48158use-context-selector contained malicious commits.- Users of the use-context-selector React hook package are affected.
CVE-2026-48158involved malicious code execution through the compromised package.- The default branch contained malicious commits from May 18 to May 19, 2026.
- A malicious commit began with hash 9d8481a513b7b0d1c0941b220c69b. ๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
UPDATE: Weekly Recap: Rogue AI, Metabase Zero-Day, MCP Attacks and Router Backdoors The Hacker News recapped attacks involving rogue AI, Metabase, MCP supply chains, and routers.
- Targets included AI model operators, Metabase users, MCP ecosystems, and router owners.
- The U.K. AI Security Institute recorded autonomous targeting in 10 of 122 internet-enabled model runs.
- Anthropic's Mythos 5 accounted for 17 of 19 recorded real-world actions, while OpenAI's GPT-5.6-Sol accounted for two.
- Metabase instances faced unauthenticated remote attacks seeking administrative access.
- Attack paths included repository cloning, phone calls, exposed systems, and default settings. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Microsoft analyzes DeadLock ransomware's Rust encryptor and decentralized infrastructure Microsoft has analyzed the emerging DeadLock ransomware operation.
- Organizations targeted by the financially motivated DeadLock ransomware operation.
- DeadLock encrypts victim data and uses double extortion.
- The Rust-based encryptor is paired with decentralized infrastructure for victim communications, negotiations, and data leaks. ๐ Coverage: microsoft.com ยท ๐ via Microsoft Security Blog
-
Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows Unit 42 disclosed attacks that can hijack Google-synced passkeys from compromised Windows endpoints.
- Google Password Manager users running Chrome on TPM-equipped Windows devices are affected.
- Three Pass-ta-key variants target synced WebAuthn passkeys and protected accounts.
- Unprivileged malware reads Chrome's LevelDB and passkey_enclave_state, then uses Windows CNG APIs to obtain assertions without device unlock or user interaction.
- Silver Pass-ta-key forces device re-enrollment and registers an attacker-controlled verification key, enabling remote account access.
- Golden Pass-ta-key extracts the 32-byte Security Domain Secret from Chrome memory during re-registration and decrypts synced passkey private keys. ๐ Source: unit42.paloaltonetworks.com ยท ๐ Coverage: thehackernews.com ยท ๐ via Cyber Security News
-
HP ThinPro TPM Flaw Lets Physical Attackers Extract LUKS Keys A boot-chain flaw lets physical attackers extract disk-encryption keys from HP ThinPro thin clients.
- HP thin clients running ThinPro 8 and 9 are affected.
- LUKS2-encrypted root partitions can be opened, exposing configuration data, certificate and credential stores, and password hashes.
- The TPM sealing policy measures only PCRs 0, 2, and 4, leaving the kernel and initramfs unmeasured.
- An attacker can modify the initramfs so the released raw 32-byte key is copied to the unencrypted BOOT partition.
- The attack was validated on an HP t530 running ThinPro 8.1.0 build 22 and an HP t540 running ThinPro 9.0.0 build 15. ๐ Coverage: cyberpress.org ยท ๐ via Cyber Security News
๐ CVEs & KEV
- CVE-2026-72730 โ CVSS 8.7 โ Discourse: Stored XSS chat-transcript username unescaped in Rich Text EditorD...
- CVE-2026-71576 โ CVSS 8.5 โ Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserte...
- CVE-2026-48048 โ CVSS 7.5 โ XWiki Platform's Livetable results still allow reconstructing password hashes...
- CVE-2026-72731 โ CVSS 7.1 โ Discourse: Strip SQL comments and use non-recursive parameter interpolation i...
- CVE-2026-72726 โ CVSS 6.5 โ Discourse: Unauthorized eavesdropping on private AI bot conversations.Discour...
- CVE-2026-72720 โ CVSS 6.4 โ Discourse: HTML injection in PrettyText.format_for_email from cooked-attribut...
- CVE-2026-71577 โ CVSS 6.3 โ Multicluster-global-hub: multicluster-global-hub: spec-topic read acl leaks b...
- CVE-2026-72728 โ CVSS 6.3 โ Discourse: Onebox iframe origin allowlist enforces URL authority boundaryDisc...