#threatalert — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatalert, aggregated by home.social.
-
Obsidian plugin was abused to deploy a remote access trojan
https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
#HackerNews #ObsidianPlugin #RemoteAccessTrojan #CyberSecurity #ThreatAlert #Malware
-
Obsidian plugin was abused to deploy a remote access trojan
https://cyber.netsecops.io/articles/obsidian-plugin-abused-in-campaign-to-deploy-phantom-pulse-rat/
#HackerNews #ObsidianPlugin #RemoteAccessTrojan #CyberSecurity #ThreatAlert #Malware
-
🚨 This week’s CrowdSec Threat Alert: CVE-2026-21859, a critical SSRF vulnerability in Mailpit, is being actively exploited to map internal networks and access sensitive infrastructure.
See how the exploit works, what targeted reconnaissance reveals, and why exposed dev tools can become high-impact entry points in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2026-21859
-
🚨 This week’s CrowdSec Threat Alert: CVE-2026-21859, a critical SSRF vulnerability in Mailpit, is being actively exploited to map internal networks and access sensitive infrastructure.
See how the exploit works, what targeted reconnaissance reveals, and why exposed dev tools can become high-impact entry points in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2026-21859
-
🚨 This week’s CrowdSec Threat Alert: CVE-2025-14528, a remotely exploitable vulnerability in end-of-life D-Link DIR-803 routers, is exposing admin credentials and opening the door to botnet recruitment.
Discover how the exploit works, what early scanning activity reveals, and why legacy routers remain prime low-level cybercriminal targets in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2025-14528
-
🚨 This week’s CrowdSec Threat Alert: CVE-2025-14528, a remotely exploitable vulnerability in end-of-life D-Link DIR-803 routers, is exposing admin credentials and opening the door to botnet recruitment.
Discover how the exploit works, what early scanning activity reveals, and why legacy routers remain prime low-level cybercriminal targets in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2025-14528
-
🚨 This week’s CrowdSec Threat Alert: CVE-2025-56520, an actively exploited SSRF vulnerability in Dify, is enabling reconnaissance and internal network probing across exposed AI platforms.
Discover attack patterns, momentum trends, and mitigation steps in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2025-56520
-
🚨 This week’s CrowdSec Threat Alert: CVE-2025-56520, an actively exploited SSRF vulnerability in Dify, is enabling reconnaissance and internal network probing across exposed AI platforms.
Discover attack patterns, momentum trends, and mitigation steps in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2025-56520
-
🚨 This week’s CrowdSec Threat Alert: CVE-2026-1281, a pre-auth RCE in Ivanti EPMM, is actively exploited in the wild, putting Enterprise Mobile Management at risk worldwide.
Discover attack details, threat trends, and actionable mitigation steps in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2026-1281
-
🚨 This week’s CrowdSec Threat Alert: CVE-2026-1281, a pre-auth RCE in Ivanti EPMM, is actively exploited in the wild, putting Enterprise Mobile Management at risk worldwide.
Discover attack details, threat trends, and actionable mitigation steps in our latest article 👉 https://crowdsec.net/vulntracking-report/cve-2026-1281
-
🚨 This week’s CrowdSec Threat Alert article highlights CVE-2025-68645 (LFI) and CVE-2022-27926 (XSS), actively exploited in the wild against Zimbra Collaboration servers.
Explore attack details, threat trends, and mitigation steps in the article 👉 https://www.crowdsec.net/vulntracking-report/zimbra-collaboration-coordinated-attack
-
🚨 This week’s CrowdSec Threat Alert article highlights CVE-2025-68645 (LFI) and CVE-2022-27926 (XSS), actively exploited in the wild against Zimbra Collaboration servers.
Explore attack details, threat trends, and mitigation steps in the article 👉 https://www.crowdsec.net/vulntracking-report/zimbra-collaboration-coordinated-attack
-
🚨 This week’s CrowdSec Threat Alert highlights CVE-2025-34291, a critical LangFlow RCE actively exploited in the wild.
👀 Security teams: patch your LangFlow instances and harden configurations to prevent account takeovers and full AI workflow compromise.
Explore the attack details, threat patterns, and mitigation steps in the latest article: https://www.crowdsec.net/vulntracking-report/cve-2025-34291
#CVE #CVE202534291 #RCE #LangFlow #ThreatAlert #cybersecurity
-
🚨 This week’s CrowdSec Threat Alert highlights CVE-2025-34291, a critical LangFlow RCE actively exploited in the wild.
👀 Security teams: patch your LangFlow instances and harden configurations to prevent account takeovers and full AI workflow compromise.
Explore the attack details, threat patterns, and mitigation steps in the latest article: https://www.crowdsec.net/vulntracking-report/cve-2025-34291
#CVE #CVE202534291 #RCE #LangFlow #ThreatAlert #cybersecurity
-
🚨 This week’s CrowdSec Threat Alert article highlights CVE-2025-59287, a critical WSUS RCE being actively probed and exploited in real-world environments.
Dive into the data, attack patterns, and mitigation steps 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-59287
-
🚨 This week’s CrowdSec Threat Alert article highlights CVE-2025-59287, a critical WSUS RCE being actively probed and exploited in real-world environments.
Dive into the data, attack patterns, and mitigation steps 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-59287
-
🚨In this week’s Threat Alert article (the first one of 2026), we break down an active exploitation spike targeting CVE-2024-20767 in Adobe ColdFusion, observed across the CrowdSec Network.
Read the full analysis and protect your systems 👉 https://crowdsec.net/vulntracking-report/cve-2024-20767
-
🚨In this week’s Threat Alert article (the first one of 2026), we break down an active exploitation spike targeting CVE-2024-20767 in Adobe ColdFusion, observed across the CrowdSec Network.
Read the full analysis and protect your systems 👉 https://crowdsec.net/vulntracking-report/cve-2024-20767
-
🚨 In this week’s newsletter, we revisit React2Shell (CVE-2025-55182) as exploitation surged from hundreds to over 10K daily attackers. We break down what changed, how attackers shifted to mass automated campaigns, and what defenders can do to stay protected.
Read the full analysis and protect your systems 👉 https://crowdsec.net/vulntracking-report/cve-2025-55182-react2shell
-
🚨 In this week’s newsletter, we revisit React2Shell (CVE-2025-55182) as exploitation surged from hundreds to over 10K daily attackers. We break down what changed, how attackers shifted to mass automated campaigns, and what defenders can do to stay protected.
Read the full analysis and protect your systems 👉 https://crowdsec.net/vulntracking-report/cve-2025-55182-react2shell
-
🚨 In this week’s Threat Alert article, we’re tracking the explosive rise of React2Shell (CVE-2025-55182) attacks. The CrowdSec Network has observed 15,725+ signals in 4 days, a single-day peak of 8,925, and 381 unique IPs already weaponizing the flaw.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-55182
-
🚨 In this week’s Threat Alert article, we’re tracking the explosive rise of React2Shell (CVE-2025-55182) attacks. The CrowdSec Network has observed 15,725+ signals in 4 days, a single-day peak of 8,925, and 381 unique IPs already weaponizing the flaw.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-55182
-
🚨 In this week’s Threat Alert article, CrowdSec highlights active exploitation of CVE-2025-64095, a critical DNN file upload flaw. Attackers are probing sites for defacement and XSS attacks.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-64095
-
🚨 In this week’s Threat Alert article, CrowdSec highlights active exploitation of CVE-2025-64095, a critical DNN file upload flaw. Attackers are probing sites for defacement and XSS attacks.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-64095
-
TamperedChef malware (HIGH severity) is spreading globally via fake software installers—no CVE. Risks: system compromise, data theft. EU orgs with high software downloads most at risk. Enforce whitelisting & educate users. More: https://radar.offseq.com/threat/tamperedchef-malware-spreads-via-fake-software-ins-70f04923 #OffSeq #Malware #ThreatAlert
-
🚨 In this week’s Threat Alert, CrowdSec detects a surge in exploitation of CVE-2025-55748, a path traversal vulnerability in XWiki exposing sensitive configuration files.
📈 Observed activity is rising, yet this flaw is not yet listed in CISA’s KEV, increasing the risk of under-prioritized patching.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-55748
#CVE #CVE202555748 #threatalert #threatintel #cybersecurity #xwiki
-
🚨 In this week’s Threat Alert, CrowdSec detects a surge in exploitation of CVE-2025-55748, a path traversal vulnerability in XWiki exposing sensitive configuration files.
📈 Observed activity is rising, yet this flaw is not yet listed in CISA’s KEV, increasing the risk of under-prioritized patching.
Read the full analysis and protect your systems 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-55748
#CVE #CVE202555748 #threatalert #threatintel #cybersecurity #xwiki
-
🚨 Major breach alert
Hackers linked to Scattered Spider compromised Vietnam Airlines’ Salesforce CRM, leaking over 23 million government records from multiple countries.Sensitive data from officials in 🇻🇳 🇺🇸 🇯🇵 🇰🇷 🇦🇺 was exposed through a social engineering attack - not a software flaw.
Link in bio.#CyberSecurity #DataBreach #ScatteredSpider #InfoSec #ThreatAlert #TechNadu
-
🚨 Major breach alert
Hackers linked to Scattered Spider compromised Vietnam Airlines’ Salesforce CRM, leaking over 23 million government records from multiple countries.Sensitive data from officials in 🇻🇳 🇺🇸 🇯🇵 🇰🇷 🇦🇺 was exposed through a social engineering attack - not a software flaw.
Link in bio.#CyberSecurity #DataBreach #ScatteredSpider #InfoSec #ThreatAlert #TechNadu
-
First Malicious MCP in the Wild: The Postmark Backdoor Stealing Your Emails
https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft
#HackerNews #MaliciousMCP #PostmarkBackdoor #EmailTheft #Cybersecurity #ThreatAlert
-
First Malicious MCP in the Wild: The Postmark Backdoor Stealing Your Emails
https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft
#HackerNews #MaliciousMCP #PostmarkBackdoor #EmailTheft #Cybersecurity #ThreatAlert
-
In this attack, Russian UAC-0063 group is using blurred MS Word documents to trick victims into enabling macros leading to malware infection.
Read: https://hackread.com/russian-uac-0063-europe-central-asia-advanced-malware/
-
In this attack, Russian UAC-0063 group is using blurred MS Word documents to trick victims into enabling macros leading to malware infection.
Read: https://hackread.com/russian-uac-0063-europe-central-asia-advanced-malware/
-
🚨 The infamous North Korean Lazarus Group is back at it! Recently, they targeted nuclear workers with sophisticated malware in a continuation of their DreamJob campaign. 🎯 This operation involves fake job offers to steal sensitive info and cryptocurrency. Stay alert! 🔒💻 Read more: https://www.techradar.com/pro/security/north-korean-lazarus-hackers-are-targeting-nuclear-workers #CyberSecurity #LazarusGroup #Malware #ThreatAlert #newz
-
🚨 The infamous North Korean Lazarus Group is back at it! Recently, they targeted nuclear workers with sophisticated malware in a continuation of their DreamJob campaign. 🎯 This operation involves fake job offers to steal sensitive info and cryptocurrency. Stay alert! 🔒💻 Read more: https://www.techradar.com/pro/security/north-korean-lazarus-hackers-are-targeting-nuclear-workers #CyberSecurity #LazarusGroup #Malware #ThreatAlert #newz
-
🚨 A new report reveals that critical infrastructure is under threat from dangerous malware targeting routers, firewalls, and fuel systems! 🔒⚠️ Stay informed! Read more: https://www.techradar.com/pro/security/critical-infrastructure-being-hit-by-dangerous-new-malware-routers-firewalls-and-fuel-systems-all-under-threat #CyberSecurity #Malware #ThreatAlert #newz
-
🚨 A new report reveals that critical infrastructure is under threat from dangerous malware targeting routers, firewalls, and fuel systems! 🔒⚠️ Stay informed! Read more: https://www.techradar.com/pro/security/critical-infrastructure-being-hit-by-dangerous-new-malware-routers-firewalls-and-fuel-systems-all-under-threat #CyberSecurity #Malware #ThreatAlert #newz
-
"🚨 Major Bluetooth Flaw in BlueZ: Keystroke Injection Risk! 🚨"
A Bluetooth vulnerability, CVE-2023-45866, has been uncovered, posing a significant threat to various devices. Discovered by Marc Newlin, this flaw in BlueZ allows unauthenticated devices to inject HID events, leading to potential keystroke injections and arbitrary command executions on affected devices. Particularly alarming, this vulnerability affects a wide range of operating systems including Android, Linux, macOS, and iOS, even those in Lockdown Mode.
Key details include:
- BlueZ not properly restricting non-bonded devices from injecting HID events into the input subsystem.
- Potential for an unauthenticated Peripheral role HID Device to establish an encrypted connection without user interaction, injecting HID messages.
- CVE-2023-45866 carries a critical severity rating with a CVSS base score of 9.8, indicating a high level of threat.
Marc Newlin's analysis highlights that this attack exploits an unauthenticated pairing mechanism within the Bluetooth specification, allowing fake keyboards to connect to target devices.
Stay vigilant and update your devices! 🛡️📱💻
Tags: #CyberSecurity #BluetoothVulnerability #BlueZ #CVE202345866 #KeystrokeInjection #DeviceSecurity #MarcNewlin #ThreatAlert
Sources:
- NVD: CVE-2023-45866
- Tenable: CVE-2023-45866 Details
- Hackread Article by Waqas: Bluetooth Vulnerability Report
-
"🚨 Major Bluetooth Flaw in BlueZ: Keystroke Injection Risk! 🚨"
A Bluetooth vulnerability, CVE-2023-45866, has been uncovered, posing a significant threat to various devices. Discovered by Marc Newlin, this flaw in BlueZ allows unauthenticated devices to inject HID events, leading to potential keystroke injections and arbitrary command executions on affected devices. Particularly alarming, this vulnerability affects a wide range of operating systems including Android, Linux, macOS, and iOS, even those in Lockdown Mode.
Key details include:
- BlueZ not properly restricting non-bonded devices from injecting HID events into the input subsystem.
- Potential for an unauthenticated Peripheral role HID Device to establish an encrypted connection without user interaction, injecting HID messages.
- CVE-2023-45866 carries a critical severity rating with a CVSS base score of 9.8, indicating a high level of threat.
Marc Newlin's analysis highlights that this attack exploits an unauthenticated pairing mechanism within the Bluetooth specification, allowing fake keyboards to connect to target devices.
Stay vigilant and update your devices! 🛡️📱💻
Tags: #CyberSecurity #BluetoothVulnerability #BlueZ #CVE202345866 #KeystrokeInjection #DeviceSecurity #MarcNewlin #ThreatAlert
Sources:
- NVD: CVE-2023-45866
- Tenable: CVE-2023-45866 Details
- Hackread Article by Waqas: Bluetooth Vulnerability Report
-
🚨 Alert: "Stayin' Alive" Cyber Campaign Targets Asia
Since 2021, the "Stayin' Alive" cyber campaign has hit government and telcos in Asia with diverse, disposable malware. Spear-phishing, custom tools, and ToddyCat group involvement. RELIANOID offers solutions for preemptive cyber defense.
#StayinAlive #Telco #Telecom #telecommunications #Cybersecurity #ThreatAlert #Malware #CyberAttack #InfoSec #TechSecurity #StaySecure #DigitalThreats #ToddyCat #AsiaCyberThreats
https://www.relianoid.com/blog/asian-telecoms-in-the-eye-of-the-storm-for-toddycat-hackers/