๐จ ACTIVE EXPLOITATION
-
CISA says ransomware gangs are exploiting a Microsoft SharePoint RCE flaw
CVE-2026-45659CISA says ransomware gangs are exploiting a Microsoft SharePoint RCE flaw.- Microsoft SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition are affected.
- CVE-2026-45659 enables arbitrary code execution on unpatched SharePoint servers.
- Attackers exploit deserialization of untrusted data using low-privilege, low-complexity attacks.
- Shadowserver tracks more than 8,500 internet-exposed SharePoint servers, including over 200 unpatched systems. ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
-
Suspected Iranian Campaign Hits Water Utilities Across 12 U.S. States Suspected Iranian hackers have targeted water utilities in at least 12 U.S. states.
- Municipal water and wastewater utilities in at least 12 U.S. states are affected.
- Internet-connected programmable logic controllers, including Rockwell Automation/Allen-Bradley PLCs, were targeted.
- Attackers accessed PLCs remotely, changed passwords, and disabled operator monitoring and control.
- Reported effects included manual operations, loss of water pressure, flooding, and a temporary boil-water advisory in Georgia. ๐ Source: cisa.gov ยท ๐ Coverage: therecord.media ยท ๐ via securityboulevard.com (discovered)
-
AI Chrome Extension Returns With Malicious Update and Uninstall Tracking A malicious Chrome AI extension returned to enterprise browsers.
- Chrome users and enterprise endpoints were affected by the "AI Sidebar with DeepSeek, ChatGPT, Claude and more" extension.
- The extension previously scraped ChatGPT and DeepSeek conversations and exceeded 300,000 installs with a 4.6-star rating.
- Version 1.7.2.0 was distributed from July 20โ31, 2026, followed by version 1.7.3.0.
- Version 1.7.3.0 added a 21-line payload that opened affiliate links after updates and uninstall events.
- Google CDN-delivered version 1.7.3.0 was classified as Trojan.GenericFCA.Script.37952. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek, r/cybersecurity
-
ErrTraffic Uses Polygon Smart Contracts to Hide ClickFix Malware Infrastructure ErrTraffic uses Polygon smart contracts and ClickFix lures to deliver malware.
- Visitors to compromised WordPress sites are targeted, primarily on Windows.
- The ErrTraffic MaaS has delivered Vidar, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader.
- Injected JavaScript queries Polygon smart contracts through RPC services to resolve changing delivery infrastructure.
- Fake Cloudflare Turnstile or reCAPTCHA prompts trick victims into running commands in Windows Run, PowerShell, or Command Prompt.
- Compromised sites can be identified by the errtraffic_session= value in the HTTP Set-Cookie header. ๐ Source: watchguard.com ยท ๐ Coverage: cyberpress.org ยท ๐ via Cyber Security News
๐ RESEARCH & DEEP DIVES
-
Researchers Chain Windows 11 USB Plug and Play to SYSTEM Access Researchers demonstrated SYSTEM access through Windows Plug and Play.
- Windows 11 systems are affected, including fully updated machines.
- Plug and Play can fetch signed vendor software for an emulated USB device.
- Researchers chained privileged installation components to gain SYSTEM access.
- The attack can also run over Remote Desktop when Plug and Play or low-level USB redirection is enabled. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Malicious MCP Servers Split Instructions to Steal AI Coding-Agent Secrets Malicious MCP servers can trick AI coding agents into exfiltrating secrets.
- AI coding assistants connected to MCP servers are affected.
- Targets include SSH keys, environment secrets, source code, and customer data.
- Attackers split harmful instructions into routine-looking fragments across the assistant's existing input channels. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Sandworm adopts fake IT interviews to deliver malware Russia-linked Sandworm is using fake IT job interviews to deliver malware.
- Russia-linked Sandworm targets IT job applicants.
- The group uses fake job interviews as a malware delivery vector. ๐ Coverage: cert.gov.ua ยท ๐ via @campuscodi@mastodon.social
-
Windows kernel design leaves SMAP effectively disabled on standard IOCTL paths Windows kernel SMAP protections can be bypassed through standard IOCTL dispatch paths.
- Windows 11 kernel code reached through standard IOCTL dispatch is affected.
- SMAP fails to block kernel access to user-mode memory on the normal syscall path.
- Syscall entry arrives with RFLAGS.AC=1, effectively disabling SMAP for that execution path.
- A stack pivot into user-mode memory can therefore proceed without triggering SMAP.
- Microsoft's 2020 assessment said enabling SMAP would require changes at roughly 2,900 locations. ๐ Source: github.com ยท ๐ Coverage: sibouzitoun.tech ยท ๐ via r/netsec, r/cybersecurity
๐ CVEs & KEV
- CVE-2026-58231 โ CVSS 10.0 โ Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)SAP Commerce C...
- CVE-2026-15555 โ CVSS 8.8 โ Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss des...
- CVE-2026-73160 โ CVSS 8.7 โ cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Add...
- CVE-2026-15560 โ CVSS 8.1 โ Openjdk-orb: unauthed class loading via iiop in eapwhen EAP runs with -secmgr...
- CVE-2026-71217 โ CVSS 7.5 โ Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabl...
- CVE-2026-15567 โ CVSS 7.5 โ Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on...
- [CVE-2026-15565](https://cve.threatint.com/CVE/C