๐จ ACTIVE EXPLOITATION
- SPIP Before 4.4.20 Hit by Unauthenticated RCE CVE-2026-77647
CVE-2026-77647
SPIP versions before 4.4.20 have been exploited for unauthenticated remote code execution.- SPIP installations running versions before 4.4.20 are affected.
- CVE-2026-77647 allows unauthenticated remote attackers to execute arbitrary code.
- The vulnerability was exploited in the wild in August 2026.
- Exploitation requires no authentication and is remotely reachable.
๐ Coverage: thehackerwire.com ยท ๐ via CVE ThreatInt, thehackerwire.com (discovered)
๐ต๏ธ RESEARCH & DEEP DIVES
- SynkLoader malware uses fake Windows lock screens to steal passwords
SynkLoader uses a fake Windows lock screen to phish system passwords.- Windows users are targeted with a fake system login prompt.
- The loader harvests Windows login passwords through a convincing lock-screen imitation.
- SynkLoader combines Python, C#, C++, and PowerShell components.
- Its modules run in memory, and the loader ships its own runtime environment.
๐ Source: infosec.exchange ยท ๐ Coverage: expel.com ยท ๐ via @malwaretech@infosec.exchange
๐ CVEs & KEV
-
CVE-2026-72843 โ CVSS 9.3 โ EverShop Critical Unauthenticated Account Takeover
-
CVE-2026-77645 โ CVSS 9.2 โ Critical Remote Code Execution (RCE) vulnerability reported in WindchillA cri...
-
CVE-2026-77646 โ CVSS 7.7 โ Server Side Request Forgery (SSRF) vulnerability reported in WindchillA Serve...
-
CVE-2026-49217 โ CVSS 7.5 โ Mailu missing authentication on PATCH /api/v1/token/<id>, which allows unauth...
-
CVE-2026-77113 โ CVSS 6.7 โ Path Traversal Vulnerability in apport-unpackPath traversal in apport-unpack ...