π¨ ACTIVE EXPLOITATION
- Cosmos EVM flaw drains funds from three blockchains
Attackers exploited a Cosmos EVM flaw to drain funds from three blockchains.- Cosmos SDK chains running the shared Cosmos EVM module were affected, including KiiChain, TAC and MANTRA.
- Cosmos EVM versions below v0.6.2 or v0.7.2 were vulnerable, with vesting accounts enabled increasing exposure.
- KiiChain lost 148,326,583.15 KII across 18 attacks; TAC reported 2,985,651,403 TAC moved from one account.
- Attackers precomputed an exploit contract address, converted it into a vesting account and delegated one wei beyond its spendable balance.
- The staking precompile underflowed the mirrored EVM balance to roughly 2^256, enabling drains capped at victimsβ real balances.
π Source: github.com Β· π Coverage: thedefiant.io Β· π via The Hacker News
π CVEs & KEV
-
CVE-2026-55634 β CVSS 9.9 β Pimcore: Remote Code Execution via DataObject Class-Definition Field NamePimc...
-
CVE-2026-82329 β CVSS 9.8 β Potential authentication bypass leading to administrative access in Artifacto...
-
CVE-2026-55220 β CVSS 9.3 β Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserializ...
-
CVE-2026-55378 β CVSS 9.3 β JS Recon: Command injection in PR Branch Checker workflow via untrusted pull ...
-
CVE-2026-82021 β CVSS 9.0 β Hermes Agent 0.18.2 before 0.19.0 MCP Catalog Supply Chain RCE via Mutable Branch ...
-
CVE-2026-55245 β CVSS 8.7 β Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64...
-
CVE-2026-82020 β CVSS 7.6 β Hermes Agent 0.16.0 before 0.17.0 Credential Store Overwrite via File-Write ToolHe...
-
CVE-2026-55215 β CVSS 7.5 β MariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM ...
-
CVE-2026-55673 β CVSS 7.1 β PowSyBl: Command Injection in LocalCommandExecutor-sPowSyBl (Power System Blo...
π ADVISORIES
-
π Source for Qilin claims cyberattack on ATF system holding investigation-target data β atf.gov
-
π Source for GiveWP fixes CVSS 10 flaw enabling unauthenticated remote code execution β patchstack.com
-
π Source for Five MongoDB BI Connector and Transition Tool output-injection flaws disclosed β mongodb.com