๐ฅ BREACHES & INCIDENTS
- Croatia Arrests Serbian Businessman Suspected of Hacking State Systems
Croatia arrested a Serbian cybersecurity businessman suspected of hacking Croatian state systems.
- The case affects Croatia's Interior and Finance ministries, health and pension funds, HAKOM and REGOS.
- Police suspect Georgije V., 33, owner of Novi Sad cybersecurity firm Elite Security Systems, of unauthorized access and personal-data misuse.
- The intrusions reportedly began in April 2026 and targeted multiple government systems.
- Investigators say the activity was routed through servers in Sweden and Belize using Serbian IP addresses. ๐ Coverage: balkaninsight.com ยท ๐ via @campuscodi@mastodon.social
๐ต๏ธ RESEARCH & DEEP DIVES
-
Ghostjacking Uses Poisoned Logs to Hijack AI Agents Tenet researchers demonstrated attacks that hijack AI agents through poisoned logs and alerts.
- Cloudflare, Datadog, and Sentry users are exposed to the attack pattern.
- AI agents can alter DNS, execute code, steal cloud credentials, and run attacker-controlled fixes.
- Attackers plant instructions in blocked-request logs, fake alerts, or crafted error reports.
- The technique succeeded against Claude Code 9 times out of 10 in testing.
- Tenet found more than 2,700 exposed Datadog front-end keys that could help attackers plant alerts. ๐ Coverage: securityweek.com ยท ๐ via Dark Reading
-
Aeternum Uses Polygon Smart Contracts for Decentralized Botnet C2 Aeternum uses Polygon smart contracts for botnet command and control.
- Organizations with systems infected by the Aeternum botnet loader are affected.
- The loader uses Polygon blockchain smart contracts for decentralized C2 infrastructure.
- The blockchain-based C2 also enables payload execution. ๐ Source: ethereum.org ยท ๐ Coverage: unit42.paloaltonetworks.com ยท ๐ via Palo Alto Unit 42
๐ CVEs & KEV
- CVE-2026-72911 โ CVSS 9.9 โ ERPNext: Possibility of server-side template injection due to missing validat...
- CVE-2026-48161 โ CVSS 9.3 โ react18-use was vulnerable to malicious code execution via compromised commit...
- CVE-2026-48160 โ CVSS 9.3 โ react-tracked was vulnerable to malicious code execution via compromised comm...
- CVE-2025-30237 โ CVSS 8.7 โ Authentication Bypass via Broken Access Control in Web Server in Multiple TP-...
- CVE-2025-30241 โ CVSS 8.6 โ OS Command Injection in Web Interface in Multiple TP-Link Aginet DevicesCerta...
- CVE-2025-30238 โ CVSS 8.6 โ Privilege Escalation via Improper Authorization in User Management in multipl...
- CVE-2025-30239 โ CVSS 8.5 โ Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Li...
- CVE-2026-18947 โ CVSS 8.5 โ Feast Authorization Bypass: DoS via Materialization (CVE-2026-18947)
- CVE-2026-8718 โ CVSS 8.4 โ Out-of-bounds write in DTLS peer Connection ID getsockopt (
TLS_DTLS_PEER_CID... - CVE-2026-72915 โ CVSS 7.5 โ Mastodon: Personally-identifying information disclosure due to incorrect acce...
- CVE-2026-72914 โ CVSS 7.5 โ Mastodon: Exhausting data by an unauthenticated request to the admin retentio...
- CVE-2026-72913 โ CVSS 7.3 โ Kitty: Command injection into the child shell via chained @kitty-echo + @kitt...
- CVE-2026-72910 โ CVSS 7.1 โ ERPNext: Unauthorised modification of master data due to missing validationER...
- CVE-2026-72916 โ CVSS 6.3 โ Mastodon: SSRF Protection Bypass via IPv4-compatible IPv6 AddressesMastodon i...