Tag: cve
-
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.The iPhone maker…
-
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.The iPhone maker…
-
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.The iPhone maker…
-
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.The iPhone maker…
-
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.The iPhone maker…
-
Shinyhunters starten neue Angriffswelle gegen Oracle-Peoplesoft
Tags: cve, cyberattack, cybercrime, firewall, google, group, intelligence, mandiant, oracle, threat, vulnerability, wafDie Cybercrime-Gruppe Shinyhunters hat ihre Angriffe auf Oracle-Peoplesoft deutlich ausgeweitet. Mandiant und die Google Threat Intelligence Group beobachten eine erneute massenhafte Ausnutzung der Schwachstelle CVE-2026-35273. Dabei umgehen die Angreifer vorhandene Web-Application-Firewalls (WAFs) und installieren Web-Shells sowie weitere Schadsoftware auf kompromittierten Systemen. Während die Schwachstelle zunächst vor allem gegen Einrichtungen aus dem Hochschulbereich eingesetzt wurde, hat…
-
Oracle PeopleSoft Servers Targeted Again as ShinyHunters Expands Extortion Operations
Tags: cve, cyber, exploit, extortion, government, healthcare, oracle, technology, threat, vulnerabilityThe ShinyHunters-linked threat cluster tracked as UNC6240 has renewed mass exploitation of Oracle PeopleSoft servers vulnerable to CVE-2026-35273. Expanding beyond its earlier focus on higher education into technology, healthcare, government, transportation, agriculture, and IT services. The campaign demonstrates how quickly financially motivated actors can adapt when organizations rely on perimeter workarounds rather than applying vendor-issued…
-
Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack
Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. On September 27, the company confirmed that attackers had already exploited both in the wild. The same update addresses six other vulnerabilities. One of the two exploited bugs affects every deployment running a…
-
Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack
Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. On September 27, the company confirmed that attackers had already exploited both in the wild. The same update addresses six other vulnerabilities. One of the two exploited bugs affects every deployment running a…
-
Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack
Citrix has released fixes for two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-88771 and CVE-2026-88772. On September 27, the company confirmed that attackers had already exploited both in the wild. The same update addresses six other vulnerabilities. One of the two exploited bugs affects every deployment running a…
-
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772) have been exploited … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/
-
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.The vulnerabilities are listed below – CVE-2026-88771 (CVSS score: 9.5) – An improper input validation vulnerability that could allow an unauthenticated attacker to First seen…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
U.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, citrix, cve, cybersecurity, exploit, flaw, infrastructure, kev, remote-code-execution, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-88771 (CVSS score: 9.5) is a remote code execution vulnerability caused by improper input validation that could allow an unauthenticated remote…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild
Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of database compromise. A Roundcube Webmail vulnerability, tracked as CVE-2026-48842 (CVSS score of 8.1) and patched four months ago, is now being exploited in the wild. The Canadian Centre for Cyber Security added the warning to its advisory…
-
Citrix Confirms NetScaler Zero-Day RCE Flaws Actively Exploited in Attacks
Citrix has released emergency security updates for NetScaler ADC and NetScaler Gateway after confirming active exploitation of two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772. Both bugs have a CVSS v4.0 score of 9.5 and can enable remote code execution (RCE) against vulnerable customer-managed appliances. The flaws are part of a wider set of eight vulnerabilities…
-
Citrix confirms two NetScaler RCE zero-days exploited in attacks
Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks and that it has released security updates to fix the flaws. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/
-
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
-
ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
ShinyHunters exploit CVE-2026-35273 in Oracle PeopleSoft using URL encoding to bypass WAF rules, deploy web shells and spread the SIDEEYE backdoor. First seen on hackread.com Jump to article: hackread.com/shinyhunters-bypass-waf-rules-oracle-peoplesoft-attacks/
-
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.The vulnerability was first exploited as a zero-day First seen…
-
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out…
-
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out…
-
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Tags: cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, microsoft, office, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerabilities in question are as follows – CVE-2026-65660 (CVSS score: 8.8) – A code injection vulnerability in Microsoft Office SharePoint First seen on…
-
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPressflaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 (CVSS score of 9.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-87902 allows an unauthenticated attacker to make the get_page_template() function include a readable local…
-
Red Heron Exploits Critical Gitea Flaw to Steal Repositories and Deploy Linux Rootkit
Tags: access, cve, cyber, data-breach, exploit, flaw, Internet, linux, remote-code-execution, threat, vulnerabilityA threat actor tracked as Red Heron has exploited the critical Gitea remote code execution vulnerability CVE-2026-60004 to steal source-code repositories, establish persistent access, and deploy a covert Linux toolset consisting of the JITTERLY implant and SIXZUT LD_PRELOAD rootkit. Acronis reported that the actor rapidly weaponized the flaw against internet-exposed Gitea environments, turning initial access…
-
Roundcube Webmail Under Attack: 523,000 Instances Exposed Online
Roundcube CVE-2026-48842 is being actively exploited, with more than 523,000 Roundcube instances still exposed on the internet. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-roundcube-cve-2026-48842-active-exploitation/
-
U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, injection, kev, microsoft, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary…

