Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Categorie: vulnerability

Critical VMware vCenter RCE flaw exploited for reverse SSH access

post, augustus 13, 2026augustus 17, 2026

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. Compromises have been identified at 361 IP addresses across 47 countries, more than half located in Germany, the U.S., Turkey, Iran,…

Continue Reading

Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup

post, augustus 12, 2026augustus 17, 2026

Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews. During that investigation,…

Continue Reading

SonicWall SMA1000 Zero-Days Exploited To Breach Enterprise Networks

post, augustus 11, 2026augustus 17, 2026

Ransomware operators are actively exploiting two recently patched SonicWall Secure Mobile Access 1000 vulnerabilities to obtain root-level control of internet-facing remote-access appliances, steal credentials and move deeper into corporate networks. The US Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities catalogue to identify CVE-2026-15409 and CVE-2026-15410 as…

Continue Reading

New Passkey Attacks Expose Private Keys and Bypass Phishing-Resistant MFA Without Breaking Encryption

post, augustus 10, 2026augustus 17, 2026

Three independent security investigations have exposed weaknesses in the systems surrounding passkeys, demonstrating how attackers with access to a Windows endpoint could impersonate users, bypass phishing-resistant multifactor authentication or recover the private keys behind cloud-synchronised credentials. The findings do not undermine the public-key cryptography at the heart of FIDO2 and…

Continue Reading

SonicWall SMA1000 flaws now exploited by ransomware gangs

post, augustus 10, 2026augustus 17, 2026

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. ​SMA1000 is an enterprise-grade secure remote access gateway used by large corporations, government agencies, and Managed Service Providers (MSSPs) to provide VPN access to internal applications and corporate networks. SonicWall…

Continue Reading

Critical Linux SCTP Flaw Enables Root Access and Container Escape

post, augustus 8, 2026augustus 17, 2026

A memory-safety vulnerability hidden in the Linux kernel for almost two decades can allow a low-privileged user to take complete control of affected systems and, under certain conditions, escape from a container to compromise the underlying host. Tracked as CVE-2026-64564 and named SCTPhantom, the vulnerability is a use-after-free flaw in…

Continue Reading

ClickFix attack pushes macOS infostealer for crypto theft attacks

post, augustus 6, 2026augustus 17, 2026

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. ​The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine…

Continue Reading

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

post, augustus 6, 2026augustus 17, 2026

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were…

Continue Reading

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

post, augustus 4, 2026augustus 17, 2026

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug…

Continue Reading

AI-systeem Claude van Anthropic hackte onbedoeld drie bedrijven

post, juli 31, 2026

Het bekende AI-systeem Claude van het Amerikaanse bedrijf Anthropic heeft ingebroken bij drie bedrijven, nadat het onbedoeld toegang had gekregen tot het internet. Dat heeft Anthropic bekendgemaakt, een week nadat iets soortgelijks was gemeld door concurrent OpenAI. Volgens Anthropic hebben de hacks ergens sinds april plaatsgevonden, tijdens zogeheten ‘capture-the-flag’-oefeningen. Daarbij kreeg Claude…

Continue Reading
  • Previous
  • 1
  • 2
  • 3
  • …
  • 15
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes