๐จ ACTIVE EXPLOITATION
- Hackers Abuse Google Workspace Accounts to Send Phishing and Scam Emails
Hackers are using compromised Google Workspace accounts to send phishing and scam emails.
- Google Workspace customers, including schools and colleges, are affected.
- Compromised organizational accounts are used to send phishing and scam emails.
- Messages originate from real organizational domains, making them harder for filters and recipients to detect. ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
- Poland's MyDr breach exposes medical data of nearly 19 million people
A breach of Poland's MyDr system exposed medical data linked to nearly 19 million people.
- The affected system served doctors and medical institutions across Poland, including about 12,000 facilities.
- Stolen data exceeded 2 TB and included prescriptions, appointments, medications, and patient-submitted documents.
- The breach involved 19 million records containing data fragments that may be linked to individuals.
- Authorities have found no indication of a foreign attack and have not established how the data was removed. ๐ Source: tvpworld.com ยท ๐ Coverage: unn.ua ยท ๐ via @metacurity@infosec.exchange
๐ CVEs & KEV
- CVE-2026-59500 โ CVSS 10.0 โ Priority - CWE-287: Improper AuthenticationCWE-287: Improper Authentication
- CVE-2026-15413 โ CVSS 10.0 โ Link Factory - BackdoorThe Link Factory WordPress plugin is a backdoor. Distr...
- CVE-2026-59507 โ CVSS 9.3 โ Priority โ CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensit...
- CVE-2026-59506 โ CVSS 9.3 โ Priority โ CWE-306: Missing Authentication for Critical FunctionCWE-306: Miss...
- CVE-2026-59504 โ CVSS 9.1 โ Priority โ CWE-602: Client-Side Enforcement of Server-Side SecurityCWE-602: C...
- CVE-2026-59503 โ CVSS 9.1 โ Priority โ CWE-200: Exposure of Sensitive Information to an Unauthorized Acto...
- CVE-2026-12263 โ CVSS 8.8 โ Authentication BypassZohocorp ManageEngine Password Manager Pro versions befo...
- CVE-2026-59505 โ CVSS 8.6 โ Priority - CWE-284: Improper Access ControlCWE-284: Improper Access Control
- CVE-2026-59499 โ CVSS 8.6 โ Priority โ CWE-200: Exposure of Sensitive Information to an Unauthorized Acto...
- CVE-2026-59501 โ CVSS 8.2 โ Priority โ CWE-284: Improper Access ControlCWE-284: Improper Access Control
- CVE-2026-19484 โ CVSS 7.5 โ @fastify/busboy vulnerable to Denial of Service via oversized multipart bound...
- CVE-2026-19481 โ CVSS 7.5 โ @fastify/busboy vulnerable to Denial of Service via prototype-named multipart...
- CVE-2026-16455 โ CVSS 6.9 โ Local privilege escalation via improper input sanitization in execl() callIn ...
- CVE-2026-18368 โ CVSS 6.0 โ Heap buffer overflow in ModbusgwdIn Teltonika Networks RUTOS devices, a vulne...
๐ต๏ธ RESEARCH & DEEP DIVES
-
Internet-Exposed BMCs Expose Data Centers to Hardware-Level Takeover Lava found thousands of internet-exposed BMCs vulnerable to offline password cracking.
- Data centers, GPU clouds, and bare-metal providers using HPE, Supermicro, and other server platforms are affected.
- 36,872 BMC interfaces exposed IPMI on the public internet; 24,650 disclosed authentication material before login.
- CVE-2013-4786 in IPMI v2.0 leaks password-derived HMAC-SHA1 hashes to unauthenticated clients.
- Attackers reaching UDP port 623 can crack weak, reused, factory-set, or predictable passwords offline.
- Lava found evidence of exploitation, including ransomware notes on exposed HPE BMC interfaces. ๐ Source: lavahq.io ยท ๐ Coverage: darkreading.com ยท ๐ via Cyber Security News
-
Cisco Talos identifies JWR phishing framework targeting payment and shopping platforms Cisco Talos identified the undocumented JWR phishing framework.
- Customers of major payment and shopping platforms are targeted.
- JWR creates convincing counterfeit checkout and login pages.
- The framework impersonates trusted platform interfaces to facilitate phishing. ๐ Source: cmu.edu ยท ๐ Coverage: blog.talosintelligence.com ยท ๐ via Cisco Talos
-
[City-Forum campaign steals data from Salesforce and ServiceNow portals](https://www.bleepingcomputer.com/news/security/city-for