๐จ ACTIVE EXPLOITATION
-
7 | DOJ seizes QTFY domains used to target U.S. critical infrastructure
-
The DOJ and FBI seized domains used by Chinese hacking group QTFY.
-
โข QTFY targeted U.S. critical infrastructure, federal agencies, hospitals, utilities, universities and defense contractors.
-
โข Targets included NASA, the Federal Reserve, the Departments of Energy, Justice and Health and Human Services, NIH and the Senate.
-
โข QScan scanned and automatically infected thousands of internet-connected IoT devices worldwide.
-
โข QTRouter routed attacks through compromised IoT devices, commercial proxies and leased VPSs to conceal their origin.
-
โข Three seized domains were hard-coded into QScan and QTRouter for communication and authentication, making the platforms inoperable.
-
๐ Coverage: spokesman.com ยท ๐ via @campuscodi@mastodon.social
๐ CVEs & KEV
-
CVE-2026-83596 โ CVSS 8.8 โ WebKitGTK Memory Corruption via Malicious Web Content (CVE-2026-83596)
-
CVE-2026-82882 โ CVSS 8.7 โ Devtron through 2.2.0 Missing Authorization via webhook API token endpointDev...
-
CVE-2026-33407 โ Wallosapp Wallos โ CVSS 8.3 โ Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still ...
-
CVE-2026-77348 โ CVSS 8.2 โ Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still ...
-
CVE-2026-82397 โ CVSS 7.5 โ Tornado: Urlencoded body parsing omits max_num_fields, so one request can sta...
-
CVE-2026-82393 โ CVSS 7.5 โ pnpm: A tarball dependency's manifest
nameescapes node_modules โ arbitrary... -
CVE-2026-82392 โ CVSS 7.1 โ pnpm: Virtual store linker path traversal via unvalidated depPath name in loc...
-
CVE-2026-82398 โ CVSS 6.9 โ pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace...
-
CVE-2026-62993 โ CVSS 6.9 โ Smarty: SSRF via redirect bypass of trusted_uri using {fetch}Smarty is a temp...