๐ต๏ธ RESEARCH & DEEP DIVES
-
Trojanized npm Packages Deliver RedC2 4.0 Linux Backdoor
Trojanized npm packages are delivering the RedC2 4.0 Linux backdoor.- npm users of calendar and streak utility packages are affected.
- The packages contain the RedC2 4.0 Linux implant.
- When loaded, the module locates its bundled binary and marks it executable.
- The binary launches as a detached background process.
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Broadcom discloses 91 Spring CVEs affecting 209,569 tracked components
Broadcom disclosed 91 CVEs across Spring projects.- Spring Framework users and applications using Spring Security, Spring Cloud Config, Spring AI, Spring Data REST, Spring Integration, Reactor, Spring AMQP, or Spring Batch are affected.
- The disclosure covers insecure deserialization, code execution, sensitive-information exposure, SSRF, path traversal, denial of service, and authorization flaws.
- CVE-2026-59285 is a critical Spring for GraphQL deserialization flaw rated CVSS 9.2.
- Exploitation may occur when applications use Jackson 2.x, expose paginated GraphQL fields, and contain abuse-prone classes; AI-assisted scanning is accelerating vulnerability discovery.
๐ Source: spring.io ยท ๐ Coverage: sonatype.com ยท ๐ via securityboulevard.com (discovered)
๐ CVEs & KEV
-
CVE-2026-77810 โ CVSS 9.4 โ Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connect...
-
CVE-2026-67359 โ CVSS 8.7 โ Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3....
-
CVE-2026-74252 โ CVSS 8.6 โ Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1...
-
CVE-2026-54682 โ CVSS 8.2 โ DiscordChatExporter: Stored XSS in HTML export when markdown formatting is di...
-
CVE-2026-54071 โ CVSS 7.8 โ BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldo...
-
CVE-2026-27462 โ CVSS 7.5 โ Combodo iTop: User enumeration via password resetCombodo iTop is a web based ...
-
CVE-2026-30866 โ CVSS 7.5 โ Combodo iTop: Insecured access to uploaded images via sniffed urlCombodo iTop...
-
CVE-2026-67361 โ CVSS 6.9 โ Joomla Extension - j2commerce.com - Unauthenticated file upload with missing ...
-
CVE-2026-67360 โ CVSS 6.3 โ Joomla Extension - j2commerce.com - Cross-customer order replication in J2Sto...
-
CVE-2026-53762 โ CVSS 6.2 โ VeraCryp: wolfCrypt backend bypasses VeraCrypt PBKDF2 iteration count (non-de...