Skip to content
feed: live
>_0dayNews
$ news

Vulnerability & Exploit Coverage

732 articles · sorted newest first

~/news --filter

~/articles/2026-09-28-jadepuffer-azure-service-principals-resource-deletion
JADEPUFFER Uses Stolen Service Principals to Destroy Azure
cloud

JADEPUFFER Uses Stolen Service Principals to Destroy Azure

Microsoft Threat Intelligence tracks JADEPUFFER-linked attackers using compromised Azure service principals to delete cloud resources. Audit your tenant's non-human identities now.

read →
~/articles/2026-09-28-shinyhunters-fresh-peoplesoft-campaign-google
ShinyHunters Retooled PeopleSoft Exploit, Google Warns
● Breaking
oracle

ShinyHunters Retooled PeopleSoft Exploit, Google Warns

Google warns ShinyHunters has retooled its CVE-2026-35273 exploit and is running a fresh campaign against Oracle PeopleSoft. Patch or take exposed instances offline now.

read →
~/articles/2026-09-28-bitget-withdrawals-resume-387-million-crypto-heist
Bitget Resumes Withdrawals After $387.5M DPRK Heist
threat intel

Bitget Resumes Withdrawals After $387.5M DPRK Heist

Bitget restored Bitcoin withdrawals September 28, days after suspected North Korean hackers stole $387.5 million from the exchange in a backend compromise.

read →
~/articles/2026-09-28-citrix-netscaler-patches-cve-2026-88771-cve-2026-88772
Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772
● Breaking
citrix

Citrix Patches NetScaler Zero-Days CVE-2026-88771, -88772

Citrix patched CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway. CISA orders federal agencies to apply by September 30.

read →
~/articles/2026-09-28-obot-three-cves-mcp-docker-access-control
Obot AI Platform Patches Three CVEs, Two Critical
mcp

Obot AI Platform Patches Three CVEs, Two Critical

Three GitHub Security Advisories disclose an unauthenticated Docker exposure and two MCP endpoint access control failures in the Obot AI agent platform.

read →
~/articles/2026-09-27-budibase-3-45-0-six-cve-patch
Budibase 3.45.0 Fixes Six Security Flaws
cloud

Budibase 3.45.0 Fixes Six Security Flaws

Budibase 3.45.0 patches six CVEs including arbitrary file write (CVSS 8.8), SSO auth bypass (8.1), and SQL injection (8.0). Update now if Builder is exposed.

read →
~/articles/2026-09-27-citrix-netscaler-two-unpatched-rce-zero-days
Citrix NetScaler: Two Unpatched RCEs Actively Exploited
● Breaking
citrix

Citrix NetScaler: Two Unpatched RCEs Actively Exploited

Two unpatched RCEs in Citrix NetScaler ADC and Gateway are actively exploited in the wild. CVE IDs are pending assignment; Citrix expects patches by end of September 2026.

read →
~/articles/2026-09-27-woocommerce-request-quote-cve-2026-18143-file-upload
Critical File Upload Bug in WooCommerce Quote Plugin
wordpress

Critical File Upload Bug in WooCommerce Quote Plugin

CVE-2026-18143 is a CVSS 9.8 arbitrary file upload flaw in the Request a Quote for WooCommerce plugin through version 2.9.2. Update to 2.9.3.

read →
~/articles/2026-09-27-sharepoint-code-injection-cve-2026-65660-kev
SharePoint Code Injection CVE-2026-65660 Added to KEV
● Breaking
cisa kev

SharePoint Code Injection CVE-2026-65660 Added to KEV

CISA added a SharePoint code injection flaw to its KEV catalog on September 25. CVSS 8.8, active exploitation confirmed, federal patch deadline September 28.

read →
~/articles/2026-09-27-shinyhunters-waf-bypass-oracle-peoplesoft-cve-2026-35273
ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive
● Breaking
oracle

ShinyHunters WAF Bypass Keeps PeopleSoft Attacks Alive

ShinyHunters uses URL encoding to bypass WAF rules protecting against Oracle PeopleSoft CVE-2026-35273, continuing to deploy web shells on servers organizations thought were protected.

read →
~/articles/2026-09-26-elementor-csrf-admin-account-creation
Elementor CSRF Flaw Lets Attackers Create Admin Accounts
wordpress

Elementor CSRF Flaw Lets Attackers Create Admin Accounts

A CSRF flaw in the Elementor WordPress plugin lets attackers create administrator accounts without valid credentials. Site owners should update the plugin immediately.

read →
~/articles/2026-09-26-mikrotik-cve-2026-67279-cisa-kev-chain
CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog
mikrotik

CISA Adds MikroTik RouterOS Chain Flaw to KEV Catalog

CISA added CVE-2026-67279 to KEV on September 25. The medium-severity flaw chains with CVE-2026-86060 to enable full unauthenticated exploitation of MikroTik RouterOS. Federal deadline is September 28.

read →
~/articles/2026-09-26-kiteworks-zero-day-warning-server-shutdown
Kiteworks Flags Potential Zero-Day, Urges Server Shutdown
threat intel

Kiteworks Flags Potential Zero-Day, Urges Server Shutdown

Kiteworks warned customers Thursday of potential zero-day attack activity and asked them to take servers offline for a six-hour window on Saturday, September 26.

read →
~/articles/2026-09-26-clop-moves-leak-site-grav-cms-attack-confirmed
Clop Moves Leak Site After Grav CMS Attack Confirmed
ransomware

Clop Moves Leak Site After Grav CMS Attack Confirmed

Clop ransomware confirmed its Tor leak site was breached via an unpatched Grav CMS path traversal flaw. The group has migrated to a new Tor address.

read →
~/articles/2026-09-26-soldier-70-months-att-verizon-telecom-extortion
U.S. Soldier Gets 70 Months for Telecom Extortion
threat intel

U.S. Soldier Gets 70 Months for Telecom Extortion

A U.S. Army soldier sentenced to 70 months for hacking AT&T and Verizon and extorting the carriers using 100 million customers' stolen call and text metadata.

read →
~/articles/2026-09-25-bitget-dprk-crypto-theft-351-million
Suspected DPRK Hackers Steal $351.6M from Bitget
threat intel

Suspected DPRK Hackers Steal $351.6M from Bitget

Bitget says suspected North Korean actors stole $351.6 million from hot and warm wallets in a backend compromise detected at 18:31 UTC on September 24.

read →
~/articles/2026-09-25-salesbleed-salesforce-agentforce-zero-click-data-exfiltration
SalesBleed: Agentforce Flaws Enable Data Exfiltration
cloud

SalesBleed: Agentforce Flaws Enable Data Exfiltration

Three SalesBleed flaws in Salesforce Agentforce allow attackers to hijack AI agents and exfiltrate data via trusted Slack channels without user interaction.

read →
~/articles/2026-09-25-wso2-adobe-commerce-cisa-kev-cve-2026-5430-cve-2026-71362
CISA KEV: WSO2 and Adobe Commerce Flaws Exploited
cisa kev

CISA KEV: WSO2 and Adobe Commerce Flaws Exploited

CISA added CVE-2026-5430 (WSO2, CVSS 10.0) and CVE-2026-71362 (Adobe Commerce, CVSS 9.1) to KEV on September 24. Federal patch deadline: September 27.

read →
~/articles/2026-09-25-macsync-macos-icloud-calendar-c2
MacSync macOS Malware Abuses Public iCloud Calendars
apple

MacSync macOS Malware Abuses Public iCloud Calendars

Kaspersky found a new MacSync variant that hides C2 commands inside public iCloud calendar events, bypassing domain-based network controls on macOS.

read →
~/articles/2026-09-25-vardanyan-ryuk-ransomware-sentenced-two-years
Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks
ransomware

Ryuk Member Gets 2 Years for $1.2M Ransomware Attacks

Armenian national Karen Vardanyan sentenced to 2 years in US federal prison for Ryuk ransomware attacks, ordered to pay over $1.2M in restitution to victims.

read →
~/articles/2026-09-24-roundcube-cve-2026-48842-active-exploit-sql-injection
Roundcube SQL Injection Flaw Under Active Attack
threat intel

Roundcube SQL Injection Flaw Under Active Attack

Canada's CCCS confirmed active exploitation of CVE-2026-48842, a SQL injection in Roundcube Webmail patched in May. Upgrade to 1.6.16 or 1.7.1 now.

read →
~/articles/2026-09-24-solarwinds-observability-cve-2026-28324-28325-rce
SolarWinds Fixes Two Unauth RCE Flaws in Observability
solarwinds

SolarWinds Fixes Two Unauth RCE Flaws in Observability

SolarWinds patches CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8), two unauthenticated RCE flaws in Observability Self-Hosted. No active exploitation reported.

read →
~/articles/2026-09-24-teamcity-cve-2026-63077-cisa-ransomware-kev
CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw
ransomware

CISA: Ransomware Gangs Exploiting TeamCity RCE Flaw

CISA warns federal agencies that ransomware groups are exploiting CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in JetBrains TeamCity. Patch released July 28.

read →
~/articles/2026-09-24-infratrust-nms-network-management-attacks-rising
InfraTrust: Network Management Systems Under Attack
threat intel

InfraTrust: Network Management Systems Under Attack

InfraTrust's September report finds attackers targeting network management and control infrastructure at or before patch availability. Here's what to prioritize.

read →