๐จ ACTIVE EXPLOITATION
- Huntress and FBI Reveal Silk Typhoon Takedown
Huntress and the FBI disclosed a takedown targeting Silk Typhoon.
- Huntress and the FBI conducted the operation against Silk Typhoon.
- The action disrupted attackers and remediated thousands of compromised systems.
- The operation used Rule 41 authority and precise threat visibility. ๐ Coverage: securityboulevard.com ยท ๐ via securityboulevard.com (discovered)
๐ฅ BREACHES & INCIDENTS
- Wesco investigates ExfilSquad claim of 2.6 million CRM records stolen
Wesco is investigating a cloud CRM data-exfiltration claim by ExfilSquad.
- Wesco is a global supply-chain and distribution company operating across roughly 50 countries.
- ExfilSquad claimed to steal about 2.6 million Wesco CRM records.
- The claimed data includes customer and employee PII, contact data, CRM profiles, business identifiers and authentication metadata.
- Researchers linked ExfilSquad activity to improperly configured Microsoft Power Pages data tables; Wesco has not disclosed the breach path.
- Wesco said it found no ransomware or malicious software and reported no business disruption. ๐ Source: resecurity.com ยท ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ CVEs & KEV
- CVE-2026-72920 โ CVSS 9.8 โ SeaweedFS Filer Unauthenticated IAM Access (CVE-2026-72920)
- CVE-2025-31114 โ CVSS 9.3 โ Fooocus webui vulnerable to Remote Code ExecutionFooocus is an image generati...
- CVE-2026-73069 โ CVSS 9.1 โ Twenty: SQL Injection in the
searchVectorField Settings Allows Arbitrary P... - CVE-2026-19546 โ CVSS 8.8 โ Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via call...
- CVE-2026-14380 โ Perl Dbi โ CVSS 8.8 โ Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via call...
- CVE-2026-73072 โ CVSS 8.5 โ Vim: Heap Buffer Overflow when Loading a Spell FileVim is an open source, com...
- CVE-2026-73076 โ CVSS 8.4 โ Vim: Arbitrary Command Execution via Malicious
.VimballRecordEntry Replay ... - CVE-2026-73074 โ CVSS 7.1 โ Vim: Heap Buffer Overflow in Text Property HandlingVim is an open source, com...
- CVE-2026-73070 โ CVSS 6.8 โ Vim: Stack Buffer Overflow in the Vim Socket ServerVim is an open source, com...
๐ต๏ธ RESEARCH & DEEP DIVES
- CopyEscape Docker Flaw Enables Container-to-Host File Writes and Root Code Execution
CVE-2026-17106CVE-2026-17106 lets malicious containers overwrite Docker host files through copy commands.- Docker Engine, Docker CLI, Docker Desktop, and Docker Sandboxes users are affected.
- The docker cp and sbx cp commands can write outside the selected destination, including host files.
- The exploit combines a filesystem race in archive creation with unsafe symlink handling during extraction.
- Impact includes developer-account compromise and root code execution when