π¨ ACTIVE EXPLOITATION
-
Attackers Exploit ownCloud CVE-2023-49105 to Steal Philippine Nuclear Data
CVE-2023-49105
Attackers exploited an ownCloud authentication bypass to steal sensitive Philippine nuclear data.- The target was a Philippine nuclear research agency running self-hosted ownCloud.
- CVE-2023-49105 exposed files including reactor databases, fuel inventories, safety records, staff data, and credential stores.
- Without a configured signing key, attackers forged pre-signed WebDAV requests for known usernames without passwords.
- Five Python scripts enumerated directories and downloaded files with randomized pauses; staging server: 31.58.209[.]241:8000.
π Source: nvd.nist.gov Β· π Coverage: cybersecuritynews.com Β· π via CISA KEV
-
CVE-2026-53362 enables Linux kernel privilege escalation via IPv6
CVE-2026-53362
CVE-2026-53362 enables privilege escalation through the Linux kernelβs IPv6 subsystem.- Linux systems from vendors including SUSE and Red Hat are affected.
- The vulnerability resides in the Linux kernelβs IPv6 networking subsystem.
- An attacker can exploit the flaw to escalate privileges.
π Source: nvd.nist.gov Β· π Coverage: linuxcompatible.org Β· π via CISA KEV
-
CVE-2026-66384 lets authenticated Artifactory users write outside Docker cache paths
CVE-2026-66384
CVE-2026-66384 enables authenticated Artifactory users to write outside intended directories.- JFrog Artifactory customers using affected remote-repository configurations are impacted.
- The vulnerability is an improper pathname limitation affecting Docker cache paths.
- An authenticated user can write data outside the intended cache directory.
- CISA listed CVE-2026-66384 in its Known Exploited Vulnerabilities catalog.
π Source: nvd.nist.gov Β· π Coverage: docs.jfrog.com Β· π via CISA KEV
π₯ BREACHES & INCIDENTS
- (no items)
π CVEs & KEV
-
CVE-2026-81735 β CVSS 10.0 β UI-TARS-desktop @agent-infra MCP Servers Bind Every Interface Without Authent...
-
CVE-2026-74233 β CVSS 9.3 β Zbtlink Firmware Unauthenticated Root Command Injection (UDP/9992)
-
CVE-2026-79988 β CVSS 8.7 β Authenticated RCE through Twig sandbox escapeThe Twig sandbox mechanism in Cr...
-
CVE-2026-81726 β CVSS 8.3 β NLTK through 3.10.3 Path Traversal via Model-Artifact APIsNLTK through 3.10.3...
-
CVE-2026-75871 β CVSS 8.2 β Server-Side Request Forgery (SSRF) in GitLab AI GatewayGitLab has remediated ...
-
CVE-2026-19889 β CVSS 8.2 β Server-Side Request Forgery (SSRF) in GitLab AI GatewayGitLab has remediated ...
-
CVE-2026-75159 β CVSS 8.2 β MongoDB BI Connector Improper Memory Handling During Failed Kerberos Authenti...
-
CVE-2026-34674 β CVSS 7.8 β Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)Substance3D - Sam...
-
CVE-2026-5680 β CVSS 7.5 β Undertow-core: undertow: denial of service via websocket permessage-deflate p...
-
CVE-2026-78002 β CVSS 7.5 β Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript ...
-
CVE-2026-81727 β CVSS 6.9 β NLTK before 3.10.3 Hardlink File Overwrite via downloaderNLTK versions before...
-
CVE-2026-59272 β CVSS 6.8 β Log4j2 AmqpAppender disables TLS hostname verification by defaultAny applicat...
-
CVE-2026-79720 β CVSS 6.8 β Reflected XSS in Netron versions through 9.1.2 on desktop application through unsan...
-
CVE-2026-79719 β CVSS 6.8 β Reflected XSS in Netron versions through 9.1.2 on desktop application through unsan...
-
CVE-2026-79718 β CVSS 6.8 β Reflected XSS in Netron versions through 9.1.2 on desktop application through unsan...
-
CVE-2026-81725 β CVSS 6.3 β NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReade...
-
CVE-2026-19854 β CVSS 6.1 β CVE RecordWhen the ClickHouse plugin uses Native protocol (the...
π΅οΈ RESEARCH & DEEP DIVES
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted and SharePoint RCE
The Hacker News has published a roundup covering 30 cybersecurity stories.- IoT devices, water systems, and SharePoint deployments are among the affected targets.
- A 296,000-device IoT botnet and attacks against more than 100 water systems were reported.
- The roundup covers a SharePoint remote-code-execution chain and exposed-system scanning.
- Attackers used AI-assisted botnets, public infrastructure for command traffic, and delayed malware execution.
π Coverage: thehackernews.com Β· π via The Hacker News
π ADVISORIES
-
GitLab patches Duo Claude AI agent flaw enabling CI command execution
GitLab patched a high-severity flaw enabling authenticated developers to execute arbitrary CI commands.- GitLab Enterprise Edition self-managed customers using the Duo Claude AI agent are affected.
- CVE-2026-18252 affects versions 18.9β19.1.7, 19.2β19.2.5, and 19.3β19.3.1.
- An authenticated Developer-role user could execute arbitrary commands in a CI pipeline.
- The agent processed configuration from a user-controlled source; exploitation requires network access, low privileges, and user interaction.
π Coverage: cryptika.com Β· π via cryptika.com (discovered)
-
AWS extends Bedrock Guardrails to AI-agent tool interactions
AWS details extending Bedrock Guardrails beyond the model boundary to agent tool interactions.- Applies to production AI agents built with the Strands Agents SDK.
- Covers tool calls, external data, and communications with other systems.
- Uses three validation checkpoints to apply Bedrock Guardrails to those interactions.
π Coverage: aws.amazon.com Β· π via AWS Security Blog
π° UNDER-REPORTED
- (no items)