π₯ BREACHES & INCIDENTS
- Tata Nexarc B2B platform exposed OTPs in API responses
Tata Nexarcβs B2B platform exposed one-time passwords through API responses.- Tata Nexarc customers and users were affected.
- The platform returned authentication OTPs in API responses.
- The exposure occurred through the platformβs API response data.
π https://www.reddit.com/r/netsec/comments/1vx4j41/tatas_b2b_platform_returned_otps_in_api_responses/ Β· π https://eaton-works.com/2026/08/24/tata-nexarc-hack/ Β· π via r/netsec
π΅οΈ RESEARCH & DEEP DIVES
-
ToxicPanda 2.0 Expands Android Banking and Device-Control Capabilities
ToxicPanda 2.0 is targeting Android banking and cryptocurrency users with expanded credential-theft capabilities.- Android users of banking and cryptocurrency apps are targeted across Pakistan, South Africa, Mexico, Nigeria, India, and other countries.
- The trojan targets more than 140 apps for PIN theft and 349 financial institutions with credential-stealing overlays.
- A dropper delivered from Amazon AWS-hosted files uses fake installation screens to obtain VPN and Accessibility permissions.
- Accessibility abuse enables screen scraping, touch capture, deceptive overlays, and automated Wireless Debugging and ADB pairing for shell access.
- ToxicPanda 2.0 supports 167 remote commands and can steal device unlock credentials; the local ADB address is 127.0.0.1.
π http://www.prnewswire.com/news-releases/zimperium-zlabs-uncovers-toxicpanda-2-0--a-significantly-more-powerful-android-banking-trojan-302854782.html Β· π https://cybersecuritynews.com/toxicpanda-android-malware/ Β· π via Dark Reading
-
40 Malicious Firefox Extensions Steal Crypto Wallet Secrets
Researchers found 40 malicious Firefox extensions stealing cryptocurrency wallet data and credentials.- Firefox users, especially cryptocurrency wallet users, are targeted by 40 malicious add-ons linked to 37 deceptive sports-score extensions.
- The extensions impersonate OKX, Rabby Wallet, TronLink and other Web3 products to steal recovery phrases, private keys, serialized keyrings, credentials and clipboard data.
- Seven extensions use Supabase-controlled remote content to deliver phishing pages, while 15 embed wallet-theft code and exfiltrate secrets through Cloudflare Workers.
- Thirteen modified Rabby builds send serialized keyrings to hardcoded HTTP servers before local encryption; five others use hardcoded C2 infrastructure for credential and clipboard theft.
- Observed examples include Rabbit For Desktop v8.20.10 (bright-save-feed@tabtools[.]org), Rabby impersonator v2.4.9 (flex-clock-dash@extrakits[.]com), and Safe-Themes v8.12.13 (bliss-heaven@webbrol[.]com).
π https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html Β· π via Graham Cluley
-
Adfinis Document Merge Service flaw enables RCE via XLSX templates
Adfinis Document Merge Service is vulnerable to server-side template injection RCE.- Adfinis Document Merge Service versions before 9.1.0 are affected (CVE-2026-53964).
- The flaw affects XLSX document templates and can expose files, data, and the container.
- Attackers upload malicious XLSX files containing unsandboxed Jinja expressions processed by the xltpl library.
- Injected commands execute as the document-merge-server user, UID 901.
π https://github.com/advisories/GHSA-w47q-945m-q9pc Β· π https://ipurple.team/2026/08/24/text-template/ Β· π via r/netsec
-
Fake Microsoft Security Scans Push Victims to Uninstall Antivirus
Fake Microsoft-branded scanners invent security problems and funnel victims into refund scams.- Windows users with antivirus software are targeted.
- Fake Microsoft security scans falsely claim to find infections or other security problems.
- Browser redirects, malicious ads, hacked sites, notification spam, and adware can deliver the scareware.
- Victims are pressured to uninstall antivirus software and contact fake support for a refund scam.
π https://securityboulevard.com/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus/ Β· π via securityboulevard.com (discovered)
-
Cisco IE 1000 switches affected by stored XSS and DoS flaws
Cisco has disclosed stored XSS and denial-of-service flaws in IE 1000 switches.- Cisco Industrial Ethernet 1000 Series switches are affected regardless of device configuration.
- The web-based management interface contains stored XSS vulnerability CVE-2026-20232, rated medium with CVSS 5.4.
- An authenticated remote attacker can inject malicious code into interface pages and execute scripts in another userβs context.
- A separate medium-severity denial-of-service vulnerability affects the same switch series, rated CVSS 5.3; its CVE identifier is not provided.
π https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ie1k-NgXUFF52 Β· π https://www.systemtek.co.uk/2026/08/cisco-industrial-ethernet-1000-series-switches-stored-cross-site-scripting-vulnerability-cve-2026-20232/ Β· π via InfraTrust Advisories (+1)
-
Cisco RoomOS USB driver has a medium-severity stack overflow flaw
Cisco disclosed a medium-severity stack overflow vulnerability in the RoomOS USB driver.- Cisco RoomOS devices are affected.
- The USB driver contains a stack overflow vulnerability tracked as CVE-2026-20302.
- An unauthenticated local attacker needs physical access to a deviceβs USB port.
- The flaw has a CVSS score of 6.1.
π https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-bof-vTMANZgu Β· π https://infrarepo.com/cisco-%f0%9f%97%93%ef%b8%8f%f0%9f%93%85-august-19-2026/ Β· π via InfraTrust Advisories
π¨ ACTIVE EXPLOITATION
-
Dell discloses critical vulnerabilities in Networking OS10
Dell disclosed critical vulnerabilities in SmartFabric OS10.- Dell SmartFabric OS10 customers are affected.
- The advisory covers 67 CVEs, including six proprietary OS10 vulnerabilities.
- Versions prior to 10.5.6.14 are vulnerable to command execution, denial of service, session theft, and code execution.
- Remote attackers can exploit command injection, authorization flaws, session fixation, and unverified code downloads.
- The advisory rates the update critical, with a maximum CVSS score of 10.0.
π https://www.dell.com/support/kbdoc/en-us/000501840/dsa-2026-322-security-update-for-dell-networking-os10-vulnerabilities Β· π via InfraTrust Advisories
-
Dell Watchdog Timer Driver flaw enables local privilege escalation
Dell disclosed a high-severity privilege-escalation flaw in its Watchdog Timer Driver.- Dell Precision, Dell Pro, and OptiPlex systems listed in the advisory are affected.
- Watchdog Timer Driver versions before 2.0.0.1 contain an exposed IOCTL with insufficient access control.
- A low-privileged attacker with local access could exploit the driver to alter system controls and escalate privileges.
- CVE-2026-61407 has a CVSS score of 8.8.
π https://www.dell.com/support/kbdoc/en-us/000501078/dsa-2026-248-security-update-for-dell-watchdog-timer-driver-for-an-exposed-ioctl-with-insufficient-access-control-vulnerability Β· π via InfraTrust Advisories
-
Metal Gear Online 3 flaw lets match hosts remotely execute code
CVE-2026-19874
Metal Gear Online 3 contains a heap-based buffer overflow enabling remote code execution.- Konamiβs Metal Gear Online 3 version 1.1.2.8 for Steam AppID 287700 is affected.
- The flaw is an input-validation vulnerability in Steam lobby metadata for the player-removal feature.
- Malformed kick_num and Steam ID entries trigger a heap-based buffer overflow.
- A malicious match host can send crafted lobby data to remotely execute arbitrary code on lobby membersβ machines.
- CVE-2026-19874 is assigned to the vulnerability.
π https://kb.cert.org/vuls/id/728712 Β· π via CERT/CC Vulnerability Notes, CVE ThreatInt
-
HP Web Jetadmin has a high-severity arbitrary file read/write flaw
HP Web Jetadmin is affected by a high-severity arbitrary file read/write vulnerability.- HP Web Jetadmin deployments are affected.
- The flaw may allow arbitrary file reading and writing.
- HP rates the issue High with a CVSS score of 8.9.
π https://support.hp.com/us-en/document/ish_15260929-15260951-16/HPSBPI04130 Β· π https://support.hp.com/us-en/document/ish_15260929-15260951-16/HPSBPI04130 Β· π via InfraTrust Advisories
-
HP Smart Tank All-in-One Printers Face Potential Denial-of-Service Issue
HP has disclosed a potential denial-of-service issue affecting certain Smart Tank all-in-one printers.- Certain HP Smart Tank all-in-one printer models are affected.
- The issue could cause a denial-of-service condition and is rated Medium with a CVSS score of 6.9.
- The attack mechanism and affected firmware versions are not specified in the provided material.
π https://support.hp.com/us-en/document/ish_15407218-15407241-16/HPSBPI04142 Β· π via InfraTrust Advisories
-
Dell ThinOS 10 Update Fixes 83 Critical Vulnerabilities
Dell released a critical security update for ThinOS 10 vulnerabilities.- Dell ThinOS 10 customers are affected.
- The update addresses 83 vulnerabilities with a maximum CVSS score of 9.8.
- The vulnerabilities are listed as known exploited vulnerabilities.
- The supplied material does not describe attack vectors, tooling, or evasion techniques.
π https://www.dell.com/support/kbdoc/en-us/000496663/dsa-2026-352 Β· π https://www.dell.com/support/kbdoc/en-us/000496663/dsa-2026-352 Β· π via InfraTrust Advisories
π CVEs & KEV
-
CVE-2026-76071 β CVSS 9.3 β Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost ParameterNetis NC63...
-
CVE-2026-76070 β CVSS 9.3 β Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password ParameterNeti...
-
CVE-2026-13212 β CVSS 8.8 β Zephyr virtio driver calls an arbitrary function pointer from an out-of-range...
-
CVE-2026-78416 β CVSS 8.7 β Authenticated RCE via
condition.configJSON cleanse bypassCraft CMS version... -
CVE-2026-39915 β CVSS 8.5 β TIM Flow before 26.0.6 CRLF Injection via rt Parameter and access_token CookieTIM ...
-
CVE-2026-78414 β CVSS 8.0 β Cross-site scripting in Nx Witness VMS Web Administration allows session toke...
-
CVE-2026-71366 β CVSS 7.7 β Awx: notification backends allow ssrf and credential leakageA server-side req