π¨ ACTIVE EXPLOITATION
- FBI Disrupts Chinese Espionage Platform Targeting U.S. Agencies
The FBI disrupted a Chinese espionage proxy network targeting U.S. agencies.- QTFY, linked to China-based Nanjing Xinjiuwei Network Technology Company, targeted NASA, the Federal Reserve, and other U.S. agencies.
- The operation also affected healthcare, defense, energy, financial, university, aerospace, and software organizations.
- QScan scanned and exploited vulnerable internet-of-things devices, while QTRouter managed access and routing.
- The Fast Labyrinth relay network used compromised IoT devices, commercial proxies, and leased VPS infrastructure to conceal attackersβ origins.
- Authorities seized qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com; the platforms reportedly enabled access to sensitive networks for more than eight years.
π Coverage: cyberscoop.com Β· π via CyberScoop
π CVEs & KEV
-
CVE-2026-70419 β CVSS 9.1 β Dell Cloud Disaster Recovery RCE via OS Command Injection
-
CVE-2026-74770 β CVSS 8.8 β Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutr...
-
CVE-2026-79938 β CVSS 7.6 β Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper...
-
CVE-2026-54245 β CVSS 7.6 β Fleet: SQL injection in Okta conditional access endpoint allows host-controll...
-
CVE-2026-66003 β CVSS 7.1 β Frappe: Access control bypass via REST API dot-notation fields on linked doct...
-
CVE-2026-71054 β CVSS 6.5 β Vulnerability in Oracle Java SE (component: 2D). Supported versions that are ...
-
CVE-2026-49809 β CVSS 6.5 β Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Imprope...
-
CVE-2026-47842 β CVSS 6.5 β Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows ...
-
CVE-2026-74771 β CVSS 6.5 β Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization ...
-
CVE-2026-46371 β CVSS 6.5 β Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on App...
-
CVE-2026-47848 β CVSS 6.1 β Reactor Netty WebSocket Client Leaks Credentials On RedirectIn specific scena...