๐จ ACTIVE EXPLOITATION
- Fake Claude Opus 5 App Distributes RevStealer Infostealer
RevStealer is being distributed through a fake Claude Opus 5 Windows app.- Windows users downloading unofficial Claude desktop software are targeted.
- RevStealer steals browser data, credentials, session cookies, password-manager records, VPN data and cryptocurrency wallet material.
- The lure is a roughly 101 MB archive named ClaudeOpus5-desktop.zip from GitHub repositories and game-cheat websites.
- A trojanized 64-bit Electron app decrypts an AES-256-CBC payload into AppData and launches it as a hidden process.
- Anti-analysis features include sandbox checks, CAPTCHA gating, 14 indirect syscalls, in-memory encrypted exfiltration and Polygon smart-contract C2 fallback.
๐ https://www.morphisec.com/blog/revstealer-silence-is-its-greatest-weapon/ ยท ๐ https://www.scworld.com/news/revstealer-malware-spread-through-fake-claude-opus-5-download ยท ๐ via https://cybersecuritynews.com/revstealer-inside-fake-claude/, https://www.cryptika.com/hackers-hide-revstealer-inside-fake-claude-opus-5-app-to-steal-passwords-and-crypto/
๐ฅ BREACHES & INCIDENTS
- Attackers Stole METR API Key and Attempted to Access Public Infrastructure
Attackers stole a METR API key and probed its public infrastructure.- METR, a nonprofit evaluating frontier AI models, was targeted in two incidents in 2026.
- A stolen API key was used to consume about $600,000 worth of public-model credits.
- Attackers exposed a publicly accessible agent dashboard through a fail-open authentication flaw and added an SSH key.
- A later campaign used credential stuffing, OAuth attempts, service scanning, and staff phishing.
- Attackers probed a transcript viewer endpoint, but METR found no evidence of non-public data access.
๐ https://metr.org/blog/2026-08-31-security-update ยท ๐ https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html ยท ๐ via https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html, https://infosec.exchange/@metacurity/117195543622756441
๐ต๏ธ RESEARCH & DEEP DIVES
-
Public PoC demonstrates Microsoft Exchange CVE-2026-62911 RCE chain
CVE-2026-62911
A public PoC demonstrates a pre-authentication RCE chain targeting vulnerable on-premises Exchange Server.- Affects on-premises Exchange Server 2016 CU23, 2019 CU14/CU15, and Subscription Edition RTM.
- CVE-2026-62911 is a capture-replay authentication-bypass privilege-escalation flaw that can contribute to SYSTEM-level RCE when chained with file-write weaknesses.
- The PoC uses PetitPotam/MS-EFSR to coerce NTLM authentication and relays it to the MRSProxy endpoint without EPA channel binding.
- WCF MRSProxy methods IMailbox_Config6 and IMailbox_Connect write an ASPX webshell to an IIS-accessible directory.
- Targets and artifacts include /Microsoft.Exchange.MailboxReplicationService.ProxyService, /EWS/MRSProxy.svc, SMB port 445, and c681d488-d850-11d0-8c52-00c04fd90f7e.
๐ https://github.com/hypnguyen1209/CVE-2026-62911 ยท ๐ https://cybersecuritynews.com/poc-microsoft-exchange-server-pre-auth-rce/ ยท ๐ via https://cybersecuritynews.com/poc-microsoft-exchange-server-pre-auth-rce/, https://www.cryptika.com/public-poc-released-for-microsoft-exchange-server-pre-auth-rce-vulnerability/
-
GeoNetwork Pre-Auth RCE Chain Affected 121 Government Deployments
GeoNetwork was vulnerable to pre-authenticated remote code execution.- GeoNetwork deployments, including 121 government installations, were affected.
- Four vulnerabilities enabled unauthenticated file upload and unsafe XSLT processing.
- The attack chain could lead to remote code execution without prior authentication.
- All affected deployments were reported as patched.
๐ https://ethiack.com/info-hub/research/geonetwork-preauth-RCE ยท ๐ via https://www.reddit.com/r/netsec/comments/1w46vwa/geonetwork_preauth_rce_via_unauthenticated_file/
๐ ADVISORIES
- ๐ Source for Live Composer 2.1.19 and earlier expose WordPress sites to stored XSS โ wordfence.com
๐ CVEs & KEV
-
CVE-2026-84165 โ CVSS 8.7 โ Lack of authorisation in OpenNebula by OpenNebula SystemsA vulnerability rela...
-
CVE-2026-59681 โ CVSS 8.7 โ yast2-auth-client: OS command injection via unsanitized Organizational Unit /...
-
CVE-2026-59680 โ CVSS 8.6 โ yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowEx...
-
CVE-2026-25706 โ CVSS 7.5 โ yast2-samba-client: OS command injection via attacker-controlled Organization...