π¨ ACTIVE EXPLOITATION
- U.S. Agencies Warn of Active Threat to Siemens S7 PLCs
Threat actors are actively targeting Siemens S7 Series PLCs.- U.S.-based Siemens PLC installations in manufacturing, energy, water, chemical, food and agriculture, and commercial facilities are targeted.
- Affected models include S7-200, S7-300, S7-400, S7-1200, and S7-1500 series PLCs, including F-series safety controllers.
- Attackers use Censys and ZoomEye to find Internet-exposed or poorly segmented PLCs running outdated software or weak authentication.
- AI-generated Python tools using snap7.dll or python-snap7 masquerade as monitoring software and provide S7comm read/write access to memory, configuration data, and ladder logic.
π Source: cisa.gov Β· π Coverage: yahoo.com Β· π via CISA Advisories
π΅οΈ RESEARCH & DEEP DIVES
-
China-Nexus Actor Uses JPEG-Masquerading VHDs to Deliver QUICAgent
A China-nexus actor targeted Myanmar government personnel with QUICAgent malware.- Targets Myanmar government, diplomatic, and technology personnel with Burmese-language lures impersonating ITCSD.
- Malicious VHD files masquerade as JPEG images and contain a decoy graduation invitation plus QUICAgent, a Go-based backdoor.
- An LNK abuses ftp.exe to run scripts, reconstruct split payloads, and launch the implant from the userβs application-data folder.
- QUICAgent resolves C2 through Cloudflare Workers, communicates over HTTP/3 QUIC with RC4 encryption, and persists via a Startup-folder shortcut.
- Reported IOCs include 38.60.244.141, maui-cocktailbar.com, register.mediumser.com, and SHA-256 26f735cbbb1257be94e6d01656a35bf66a8ae9c34868548d69ec5cb588f9f916.
π Source: seqrite.com Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
PoC Escapes WABT wasm2c Sandbox to Execute Host Shell Commands
A proof of concept escaped WABT's wasm2c sandbox and executed shell commands on the host.- WABT wasm2c users are affected, including projects using Firefox through RLBox.
- The generated C code does not preserve WebAssembly sandbox security, allowing host command execution.
- A published proof of concept demonstrates the sandbox escape and arbitrary shell execution.
π Source: threads.net Β· π Coverage: trustsig.eu Β· π via r/netsec
-
Mirage2FA Steals Microsoft 365 Sessions After Users Complete MFA
Mirage2FA is stealing Microsoft 365 sessions after users complete MFA.- Microsoft 365 users, especially in U.S. technology, manufacturing, and education sectors, are targeted.
- Researchers identified 4,532 potentially compromised addresses among 9,426 targets.
- The AiTM proxy relays credentials and MFA in real time before capturing session cookies and refresh tokens.
- HTML-smuggled attachments, fake CAPTCHA pages, QR codes, JavaScript obfuscation, and WebSocket communications support delivery and evasion.
- Reported indicators include cheacker[.]store and 185.174.100.224.
π Coverage: brinztech.com Β· π via Cyber Security News
-
Cloudflare Revisits Remote Spectre Attacks Against Workers
Cloudflare has reassessed remote Spectre attacks targeting its Workers infrastructure.- Cloudflare Workers infrastructure is affected.
- Remote Spectre attacks target isolation between Workers workloads.
- The research examines Spectre gadgets, remote timers, and achieving co-location.
- Cloudflare describes additional defenses that harden Workers against these attacks.
π Coverage: blog.cloudflare.com Β· π via Cloudflare Blog
-
Kimi K3 reportedly succeeds on CyScenarioBench cyber evaluations
Kimi K3 has demonstrated near-autonomous cyber campaign capabilities.- Moonshot AIβs Kimi K3 is the first reported open-weight model to succeed on CyScenarioBench.
- K3 can conduct cyber campaigns autonomously or near-autonomously.
- The model turns partial access into complete attack chains by adapting public exploit techniques to constrained environments.
- K3 builds custom tooling, diagnoses implementation failures, and validates each stage before proceeding.
- K3 trails closed frontier models by about six months and costs roughly three times less than Fable 5.
π Coverage: reddit.com Β· π via r/cybersecurity
-
Black Kite finds mid-market firms account for 73% of ransomware victims
Black Kite found that mid-market firms accounted for 73% of ransomware victims.- Organizations with $10 million to $1 billion in revenue across North America and Europe were the primary targets.
- Manufacturing represented 26% of mid-market ransomware victims, followed by professional, scientific and technical services and construction.
- Black Kite analyzed 13,336 disclosed incidents since January 2023 and scanned 120,128 mid-market companies.
- Exposure findings included known exploited vulnerabilities at 28% of firms and significant patch-management issues on public-facing software at 55%.
- Other findings included high-severity vulnerabilities at 48% of firms, stealer-log exposures at 32% and inadequate DMARC at 47%.
π Source: blackkite.com Β· π Coverage: infosecurity-magazine.com Β· π via Cybersecurity Dive
π ADVISORIES
-
U.S. Agencies Warn of Active Threat to Siemens S7 PLCs
Threat actors are actively targeting Siemens S7 Series PLCs.- U.S.-based Siemens PLC installations in manufacturing, energy, water, chemical, food and agriculture, and commercial facilities are targeted.
- Affected models include S7-200, S7-300, S7-400, S7-1200, and S7-1500 series PLCs, including F-series safety controllers.
- Attackers use Censys and ZoomEye to find Internet-exposed or poorly segmented PLCs running outdated software or weak authentication.
- AI-generated Python tools using snap7.dll or python-snap7 masquerade as monitoring software and provide S7comm read/write access to memory, configuration data, and ladder logic.
π Source: cisa.gov Β· π Coverage: yahoo.com Β· π via CISA Advisories
-
Critical NetScaler Flaws Enable Authentication Bypass and Denial of Service
CVE-2026-19489CVE-2026-19490
Cloud Software Group disclosed two critical NetScaler vulnerabilities.- NetScaler ADC and NetScaler Gateway customers, including customer-managed Secure Private Access Hybrid deployments, are affected.
- CVE-2026-19490 enables authentication bypass on SSL VPN, ICA Proxy, CVPN, RDP Proxy, and AAA virtual-server configurations.
- On newer builds, CVE-2026-19490 requires a SAML action; earlier builds are exposed through any Gateway or AAA virtual server.
- CVE-2026-19489 is a memory overflow triggered by SIP ALG enabled in an LSN group, causing unpredictable behavior or denial of service.
- Affected versions are NetScaler 14.1 before 73.32 and 13.1 before 63.21, including corresponding FIPS and NDcPP variants.
π Source: support.citrix.com Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
CISA and partners expand SBOM minimum elements to cover AI and SaaS
CISA and international partners released updated SBOM minimum-elements guidance.- The guidance applies to all software, including open source, AI systems, and software-as-a-service products.
- CISA, NSA, FBI, and 15 international agencies replaced the 2021 NTIA baseline on July 29, 2026.
- Ten new fields include component hashes, licenses, SBOM tool name, and generation context.
- AI-specific models, datasets, and weights remain covered by separate supplemental guidance rather than dedicated general-baseline fields.
π Source: cisa.gov Β· π Coverage: paubox.com Β· π via securityboulevard.com (discovered)
π CVEs & KEV
-
CVE-2026-71176 β CVSS 8.8 β Dell OpenManage Enterprise SQL Injection (CVE-2026-71176)
-
[ADVISORIES] π Source for CISA Adds Actively Exploited Microsoft Windows IKE RCE Flaw β msrc.microsoft.com