LIVE FEED
Subscribe
//

Category: Exploits

Exploits GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git
HIGH Exploits

GitLab RCE PoC Released: Authenticated Users Can Run Commands as Git

A researcher has published working exploit code for a GitLab vulnerability patched six weeks ago, showing how any authenticated user with push…

by Robbie · 2 weeks ago
Exploits Hackers Hijack Hotel and Conference Wi-Fi to Steal Microsoft 365 Logins
HIGH Exploits

Hackers Hijack Hotel and Conference Wi-Fi to Steal Microsoft 365 Logins

A DNS hijacking campaign targeting Wi-Fi gateways at hotels and conference centers is redirecting traveling employees to fake Microsoft 365 login pages,…

by Robbie · 3 weeks ago
Exploits Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases
MEDIUM Exploits

Upbound Discloses Data Theft Behind $13M in Fraudulent Acima Leases

The fintech parent of Rent-A-Center and Acima told the SEC that attackers used stolen customer data to obtain goods through fraudulent lease-to-own…

by Robbie · 3 weeks ago
Exploits Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks
HIGH Exploits

Microsoft Flags Surge in ACR Stealer Attacks Using ClickFix and WebDAV Tricks

Microsoft says attackers ramped up ACR Stealer campaigns between late April and mid-June, using ClickFix social engineering, WebDAV shares, and MSHTA to…

by Robbie · 4 weeks ago
Exploits Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat
HIGH Exploits

Abbott Investigates Two Separate Breaches Amid ShinyHunters Extortion Threat

Abbott Laboratories is probing unauthorized access to legacy Exact Sciences systems claimed by ShinyHunters, plus a second alleged breach of its LabCentral…

by Robbie · 4 weeks ago
Exploits North Korean Hackers Hide OtterCookie Malware Inside SVG Flag Images
HIGH Exploits

North Korean Hackers Hide OtterCookie Malware Inside SVG Flag Images

The Contagious Interview campaign is using steganography in SVG files to sneak a four-stage payload past victims lured by fake job postings…

by Robbie · 4 weeks ago
Exploits Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access
CRITICAL Exploits

Inc Ransomware Chains SonicWall SMA Zero-Days for Root Access

The Inc ransomware group is exploiting two previously unknown vulnerabilities in SonicWall's Secure Mobile Access appliances, chaining the flaws to achieve root-level…

by Robbie · 4 weeks ago
Exploits Researcher Drops Second Windows Zero-Day PoC in a Month
HIGH Exploits

Researcher Drops Second Windows Zero-Day PoC in a Month

A security researcher who previously published a Windows Defender exploit has now released a proof-of-concept for a User Profile Service privilege escalation…

by Robbie · 4 weeks ago
Exploits US Unseals Indictment, Offers $10M Bounty Over Russian Bulletproof Hosting Ring
MEDIUM Exploits

US Unseals Indictment, Offers $10M Bounty Over Russian Bulletproof Hosting Ring

Federal prosecutors have unsealed charges against three Russian nationals accused of running Media Land and ML Cloud, bulletproof hosting services that allegedly…

by Robbie · 4 weeks ago
Exploits US Treasury Sanctions VPN Provider and Cryptor Seller Tied to Ransomware Gangs
MEDIUM Exploits

US Treasury Sanctions VPN Provider and Cryptor Seller Tied to Ransomware Gangs

OFAC designated First VPN Service, its administrator, and a Belarusian crypter seller for supplying anonymity and detection-evasion tools that fueled ransomware attacks…

by Robbie · 4 weeks ago
Exploits Malicious Jscrambler npm Package Backdoored With Infostealer for Two Hours
HIGH Exploits

Malicious Jscrambler npm Package Backdoored With Infostealer for Two Hours

A threat actor published a rogue version of the Jscrambler npm package using stolen publishing credentials, planting an infostealer that harvested developer…

by Robbie · 4 weeks ago
Exploits Australia Warns of Global Webshell Campaign Hitting Vulnerable CMS Platforms
HIGH Exploits

Australia Warns of Global Webshell Campaign Hitting Vulnerable CMS Platforms

The Australian Cyber Security Centre says a large-scale exploitation campaign is deploying webshells across WordPress, Craft CMS, Joomla and other platforms worldwide,…

by Robbie · 1 month ago
1 2 3 6

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.