home.social

Search

5 results for “threatnoir”

  1. ⚠️ CRITICAL: Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Eight malicious npm packages (40,767+ downloads) deliver Overlord RAT and movinlike stealer targeting Windows developers. The MALFEX campaign steals browser data, crypto wallets, and messaging credentials. If your development environment installed these packages, assume compromise.

    threatnoir.com/focus

    🤖 AI generated summary

  2. ⚠️ CRITICAL: FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    FortiBleed campaign continues harvesting credentials from internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. Over 86,644 credentials have been compromised through exploitation of reused/leaked passwords and legacy storage mechanisms. Attackers use these credentials for lateral movem…

    threatnoir.com/focus

    🤖 AI generated summary

  3. ⚠️ CRITICAL: Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

    A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is under active exploitation as of public disclosure. Threat actors attempted exploitation within two hours of details going public, with potential access to credentials and sensitive files. All Atlass…

    threatnoir.com/focus

    🤖 AI generated summary

  4. ⚠️ CRITICAL: Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.

    threatnoir.com/focus

    🤖 AI generated summary

  5. ⚠️ CRITICAL: Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persiste…

    threatnoir.com/focus

    🤖 AI generated summary

Share on Mastodon

Enter the server where you have an account.