threat-intel China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access A Chinese-made router manufacturer, Zhibotong Electronics (ZBT) through its brand Zbtlink, ships routers with two factory-installed implants – SPEAKINGSTONE and DARKLANTERN – that provide unauthenticated remote access to the devices. These implants allow an attacker to execute commands as root, exfiltrate data, and est… The Hacker News · 2d ago High CVE-2026-74232CVE-2026-74233CVE-2026-66747CHc2routerfirmware
vulnerability Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Cisco has released patches to address 15 critical and high-severity vulnerabilities across its products, including Crosswork and BroadWorks. These flaws could lead to remote code execution, authentication bypasses, and d… SecurityWeek · Aug 20, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans les produits Cisco (20 août 2026) Multiple vulnerabilities have been discovered in Cisco products, including BroadWorks Application Delivery Platform, BroadWorks Application Server, and BroadWorks Profile Server. These vulnerabilities allow for remote co… CERT-FR · Aug 20, 2026 High CVE-2026-20030CVE-2026-20231CVE-2026-20315ciscovulnerabilityremote code execution
threat-intel Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies A new Linux botnet, dubbed Evooo1Bot, leveraging Mirai's code, is actively exploiting vulnerabilities in internet-facing devices to turn them into SOCKS5 proxies. The botnet utilizes a range of capabilities including enc… The Hacker News · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558botnetsocks5proxy
threat-intel Multiples vulnérabilités dans le noyau Linux de SUSE (14 août 2026) Multiple vulnerabilities have been discovered in the SUSE Linux kernel. Several of these vulnerabilities can lead to privilege escalation, denial of service, and data confidentiality breaches. The vulnerabilities are bei… CERT-FR · Aug 14, 2026 High CVE-2022-4994CVE-2023-2058CVE-2023-53995linuxkernelvulnerability
vulnerability Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root OpenWrt has released version 24.10.8 to address a critical vulnerability (CVE-2026-53921) in its DHCPv6 stack, allowing unauthenticated attackers to execute code as root on devices running the firmware. The vulnerability… The Hacker News · Jul 28, 2026 High CVE-2026-53921CVE-2026-62948CVE-2026-62947dhcpv6stack-overflowluci
threat-intel Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot Researchers at Binarly discovered six new vulnerabilities in U-Boot, the firmware that starts up many hardware devices, including routers and servers. These flaws could allow attackers to execute malicious code at boot,… The Hacker News · Jul 10, 2026 High CVE-2026-33243firmwarebootloadervulnerability
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
vulnerability Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service This article details six newly discovered vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway software, potentially allowing for denial-of-service attacks and arbitrary file reads. The vulnerabilities, ranging… The Hacker News · Jul 1, 2026 High CVE-2026-8451CVE-2026-8452CVE-2026-8655samlhttp2memory
vulnerability Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands as root by manipulating API requests. The flaw stems from a lack of proper sanitization… The Hacker News · Jun 30, 2026 Critical CVE-2026-8037CVE-2026-33691CVE-2024-1212CAcommand-injectionrootapi
vulnerability Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks A high-severity Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-20230, in Cisco Unified Communications Manager is currently being actively exploited by threat actors. This allows attackers to gain root privile… BleepingComputer · Jun 23, 2026 High CVE-2026-20230ssrfcve-2026-20230root
threat-intel CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices CISA has issued a warning to Fortinet customers regarding FortiBleed, a campaign targeting 86,644 FortiGate devices globally. The attack, attributed to Russian-speaking threat actors, leverages a two-step approach involv… The Hacker News · Jun 19, 2026 High USINMEcredential_stuffingdefault_credentialspassword_reuse
vulnerability CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation CISA has added three newly exploited vulnerabilities to its KEV catalog, impacting Cisco, Google Chrome, and Arista Networks. These vulnerabilities – one in Cisco SD-WAN Manager, another in Chrome’s V8 engine, and a thir… The Hacker News · Jun 10, 2026 High CVE-2026-20245CVE-2026-11645CVE-2026-7473cvesd-wanchrome
vulnerability Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available A high-severity vulnerability, CVE-2026-20245, in Cisco Catalyst SD-WAN Manager has been actively exploited by threat actors. The flaw, stemming from insufficient input validation, allows authenticated attackers to execu… The Hacker News · Jun 6, 2026 Critical CVE-2026-20245CVE-2026-20182CVE-2026-20127sd-wancvezero-day
threat-intel Chinese Cybercrime Group in Spotlight for Record Campaign Pace A Chinese cybercrime group, TA4922, is experiencing a record surge in campaign activity, utilizing sophisticated social engineering tactics to target organizations globally. The group’s primary objectives involve data th… SecurityWeek · Jun 4, 2026 High GBDEITsocial engineeringcredential phishingremote access
threat-intel Asia's Cyber Insurance Market Shows Signs of Life The Asian cyber insurance market has historically lagged behind other regions due to low penetration rates, particularly among larger organizations and small businesses. However, a recent report indicates a potential shi… Dark Reading · May 29, 2026 High CHJASIcyberinsuranceransomwareapac
threat-intel GreyVibe hackers use ChatGPT, Gemini to power cyberattacks GreyVibe, a threat actor likely linked to Russia, has been conducting cyber espionage campaigns targeting Ukrainian organizations since August 2025, utilizing a diverse range of custom malware and AI-generated lures. The… BleepingComputer · May 28, 2026 High RUUKaiphishingmalware
other Flipper One project needs community help to build open Linux platform This article reports on Flipper Devices’ ambitious project, Flipper One, an open Linux platform designed for networking and hardware experimentation, utilizing an ARM-based Rockchip RK3576 SoC. The project aims to provid… BleepingComputer · May 21, 2026 Low linuxarmopen source
vulnerability CVE-2025-68670: discovering an RCE vulnerability in xrdp This report details a remote code execution (RCE) vulnerability, CVE-2025-68670, discovered in the Kaspersky xrdp server. The vulnerability exists within the xrdp_wm_parse_domain_information function due to a buffer over… Securelist · May 8, 2026 Critical CVE-2025-68670buffer_overflowrcexrdp