vulnerability CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2026-45247, affecting the Mirasvit Cache Warmer Magento extension to its KEV catalog. This flaw allows for remote c… The Hacker News · Jun 4, 2026 Critical CVE-2026-45247USUKFRphpobjectdeserialization
threat-intel YARA-X 1.17.0 Release, (Sun, May 31st) The SANS Internet Storm Center released version 1.17.0 of YARA-X, a tool used for identifying and analyzing malware. This update includes several performance enhancements and a single bug fix, indicating ongoing maintena… SANS Internet Storm Center · May 31, 2026 Info yaramalwarethreat-detection
malware An Example of Stack String in High Level Language, (Sat, May 23rd) This article discusses a malware obfuscation technique called "stack strings," where strings are dynamically constructed on the stack at runtime rather than being stored as contiguous data in the binary. The example demo… SANS Internet Storm Center · May 23, 2026 Medium obfuscationstackassembly
threat-intel [Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th) This SANS Internet Storm Center diary details a new observation of the long-running mdrfckr campaign, a Shellbot associated with the Outlaw/Dota group. The key finding is the identification of a previously undocumented v… SANS Internet Storm Center · May 15, 2026 Medium USCNshellbotlibsshmdrfckr
threat-intel Patch Tuesday, May 2026 Edition This article reports on Patch Tuesday, May 2026, highlighting a significant increase in security vulnerabilities addressed by major software vendors like Microsoft, Apple, Google, Mozilla, and Oracle. The updates, spurre… Krebs on Security · May 12, 2026 Critical CVE-2026-41089CVE-2026-41096CVE-2026-41103USpatch tuesdayaivulnerability