๐ ADVISORIES
- U.S. sanctions alleged Iranian hackers after Mabna Institute indictment
The U.S. sanctioned alleged Iranian hackers linked to the Mabna Institute.- The targets included 144 U.S. universities, 178 foreign universities, companies, government agencies, and NGOs.
- The hackers allegedly stole more than 31 terabytes of academic data and intellectual property.
- They targeted more than 100,000 professor accounts and compromised about 8,000 accounts.
- Spearphishing and stolen credentials enabled access to research, academic publications, and proprietary data.
- Six defendants were linked to the 2017 HBO breach and an alleged $6 million Bitcoin extortion attempt.
๐ Coverage: cyberscoop.com ยท ๐ via CyberScoop
๐ CVEs & KEV
-
CVE-2026-39975 โ CVSS 9.4 โ Combodo iTop: Remote code execution using external auth variable valueCombodo...
-
CVE-2026-76835 โ CVSS 9.3 โ OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri ...
-
CVE-2026-40575 โ Oauth2_Proxy_Project Oauth2 Proxy โ CVSS 9.1 โ OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri ...
-
CVE-2026-30864 โ CVSS 8.9 โ Combodo iTop: Reflected XSS in dashboard revertCombodo iTop is a web-based IT...
-
CVE-2026-40877 โ CVSS 8.7 โ Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user p...
-
CVE-2026-76073 โ CVSS 8.7 โ Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped...
-
CVE-2026-76836 โ CVSS 8.7 โ AzuraCast through 0.23.8 Liquidsoap Configuration Write via Profile Edit Seri...
-
CVE-2026-71504 โ CVSS 8.6 โ Dolibarr before 24.0.0 Members REST API Improper Authorization via Password ResetD...
-
CVE-2026-76838 โ CVSS 8.4 โ Hi.Events before 1.11.1-beta Server-Side Request Forgery via Unvalidated Webh...
-
CVE-2026-76072 โ CVSS 8.3 โ Continue CLI through 1.5.47 Incomplete Destructive Command Denylist in Headle...
-
CVE-2026-71506 โ CVSS 7.2 โ Dolibarr before 24.0.0 Payments REST API Improper Authorization via Delete Endpoin...
-
CVE-2026-71511 โ CVSS 7.1 โ Dolibarr before 24.0.0 Members REST API Sensitive Data Exposure via Member Endpoin...
-
CVE-2026-71510 โ CVSS 7.1 โ Dolibarr before 24.0.0 Users REST API SQL Injection via filter parameterDolibarr b...
-
CVE-2026-71509 โ CVSS 7.1 โ Dolibarr before 24.0.0 Expense Report REST API Improper Authorization via Update E...
-
CVE-2026-71508 โ CVSS 7.1 โ Dolibarr before 24.0.0 REST API Improper Authorization via User Update EndpointDol...
-
CVE-2026-71507 โ CVSS 7.1 โ Dolibarr before 24.0.0 REST API Broken Object-Level Authorization via Bank Account...
-
CVE-2026-71505 โ CVSS 7.1 โ Dolibarr before 24.0.0 REST API Broken Object-Level Authorization via Third-Party ...