CISA Confirms Exploitation of LoadMaster Command Injection
CISA confirms exploitation of a pre-authentication LoadMaster command-injection flaw. API-enabled appliances need a fixed release and an exposure review.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
CISA confirms exploitation of a pre-authentication LoadMaster command-injection flaw. API-enabled appliances need a fixed release and an exposure review.
Read article →OVSwrap exploits a 16-bit nested-action limit in the Linux kernel, leaving defenders to verify both the running fix and the earlier exposure window.
Read article →A Microsoft case study traces mshta execution to one isolated QNET host and shows which workstations qualify for the preview action.
Read article →A remote SCTP peer can trigger the kernel flaw, while Tencent separately demonstrated local privilege escalation and container escape. Defenders need both reachability and running-kernel checks.
Read article →An automated npm campaign uses hundreds of disposable packages to launch detached native malware, with DNS TXT records as a fallback delivery channel.
Read article →WordPress 7.0.3 fixes a pre-auth login-page XSS that can turn administrator interaction with a malicious site into PHP execution.
Read article →Remus uses an Ethereum smart contract to resolve changing command infrastructure before stealing browser sessions, credentials, and wallet data.
Read article →BINDCLOAK collects Windows user and process tokens, duplicates them, and starts modular malware components inside more privileged security contexts.
Read article →SpecterOps shows how relayed WSUS machine-account access can forge targeted updates and bypass payload signature checks when SUSDB runs on a separate SQL Server.
Read article →CISA confirms exploitation of a TeamCity flaw that lets an unauthenticated network attacker run commands as the server process, putting secrets and build integrity at risk.
Read article →A targeted npm cluster split its downloader across ordinary-looking modules, then escaped Node.js vm isolation to install a cross-platform RAT on developer systems using Alibaba tools.
Read article →TP-Link TL-WR940N hardware revision 6 can let an unauthenticated attacker turn a LAN client's outbound RTSP session into code execution inside the router kernel.
Read article →Flare found that BTMOB's official operation now sits among resellers, source-code buyers, private servers, and offers of uncertain authenticity, weakening infrastructure-only detection.
Read article →