Tag: recent cybersecurity news

HPE patches critical ArubaOS-CX remote code execution flaw
News

HPE patches critical ArubaOS-CX remote code execution flaw

A serious flaw in the ArubaOS-CX network operating system that might result in remote code execution has been fixed by Hewlett Packard Enterprise (HPE). The security flaw, known as CVE-2026-73749, is a buffer overflow that enables unauthenticated remote attackers to transmit specially constructed packets to an impacted daemon process, resulting in code execution with elevated privileges. According to HPE's advisory, a daemon of ArubaOS-CX has several vulnerabilities that could enable incorrect processing of corrupted input. By sending specially constructed packets to the compromised service, an unauthenticated remote attacker could take advantage of these vulnerabilities. The notice lists the following affected release branches and fixes: 10.18.0001 → upgrade to 10.18.1002+ 1...
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
News

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

BraZetsu, a sophisticated Python-based Windows malware architecture that powers an underground marketplace that sells access to compromised hosts, has been revealed by cybersecurity experts. According to a technical analysis by Group-IB malware specialists Julio Guapo Menezes and Miguel Salazar, BraZetsu is a complete master toolkit that helps Initial Access Brokers (IABs) by transforming compromised computers into extremely valuable commercial assets, in contrast to the conventional infostealer paradigm. Using a modular design and stealth approaches, the framework demonstrates excellent operational maturity, enabling some samples to stay completely undetectable on VirusTotal at the time of analysis. BraZetsu is a combination of "Brazil" and "Zetsu," a fictional character from th...
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
News

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

In addition to an IOS XR hardening release that bundles seven umbrella CVEs, two of which are rated 9.8, with no workaround for any IOS XR version, Cisco has released patches to address a critical security flaw affecting ten Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root. The Nexus vulnerability, identified as CVE-2026-20212 (CVSS score: 9.8), involves binding to an uncontrolled IP address that allows the default Layer 3 virtual routing and forwarding (VRF) instance to access TCP ports 43210 and 43211. An attacker can establish a direct connection to the service if they are able to access a switch's IP on either port. After being delivered to that service, crafted input is run as root-level code. Additionally, an at...
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
News

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can result in remote code execution, is being actively exploited by attackers. The majority of Switchvox systems that are exposed to the internet have either already been targeted or will soon be, according to security researchers at Horizon3. Business phone systems can be configured and monitored using Switchvox, an enterprise VoIP management platform. The most critical of the 12 vulnerabilities that Horizon3 found and reported to Sangoma on April 10 is CVE-2026-9586. They were resolved by the vendor in Switchvox version 8.4.0.2, which was made available on July 14. The /pa HTTP endpoint of Sangoma Switchvox has an unauthenticated SQL injection vulnerability. According to the r...
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
News

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

False software-download websites are being used by an ongoing malware effort to deliver harmful installers and pose as reliable vendors. According to Microsoft, the effort has targeted users who want to download popular software and has led to compromises in a number of industries and organizations, mostly affecting Chinese-speaking users and international corporations' activities in China. Once activated, the installers spread malware that can communicate with infrastructure under attacker control, undermine security measures, and establish persistence. Victims of the activity have come from a variety of industries, including healthcare, manufacturing, gaming, technology, logistics, government, and education. The Windows manufacturer has determined with a considerable degree of ...
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
News

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

According to Virtualizor, hackers redirected Softaculous traffic by using a Border Gateway Protocol (BGP) hijack. The hackers then sent a malicious Virtualizor package to select installations via the redirected update traffic. Five of the 34 Virtualizor hypervisors that the hosting provider account separately examined had root-level penetration. The incident occurred between August 28 at 20:57 Coordinated Universal Time (UTC) and August 30 at 06:10 UTC. Because the firm does not have a precise list of installations that got the package or an affected-version range, Virtualizor advised all operators to check their servers. On September 1, Virtualizor issued Patch 9 with a Security Analyzer; nevertheless, the company stated that cryptographic package signing was still a work in progre...
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
News

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Cybersecurity experts have revealed information on a new Android banking malware known as StreamRat, which may offer operators almost total control over compromised devices and was advertized to Spanish-speaking users via a phony television-streaming campaign on Meta. According to ThreatFabric, the campaign's advertisement targeted Spain and was seen at least once by an estimated 570,950 Meta accounts in the EU; however, the number of infected devices and confirmed victims is still unknown. After sideloading the Android Package (APK), the victim must authorize a series of controls in order for the device to be taken over. When a streaming app asks for system controls unrelated to streaming, users should halt the installation. According to ThreatFabric's StreamRat study, there is ...
Dropbox accounts breached through Lenovo email verification flaw
News

Dropbox accounts breached through Lenovo email verification flaw

Some customers are being alerted by Dropbox that an unauthorized person gained access to their accounts by registering false Lenovo IDs by taking advantage of a weakness in Lenovo's email verification procedure. The cloud storage service claimed to employ Lenovo Identity service Services as part of its authentication architecture, despite the fact that some impacted users did not have Lenovo accounts. This enables users to utilize validated Lenovo IDs to access Dropbox accounts. A problem with Lenovo's email verification procedure "allowed an unauthorized party to register a Lenovo ID using your email address," according to the message provided to affected users, made the illegal access feasible. The attacker then gained access to the Dropbox account linked to the same email address...
Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads
News

Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads

As part of a concerted law enforcement effort, the U.S. Department of Justice (DoJ) stated on Tuesday that the long-running peer-to-peer (P2P) botnet known as Sality had been taken down. Authorities from the United States, Bulgaria, Hungary, and Romania launched the initiative on August 31, 2026, working with private industry partners CrowdStrike and the Shadowserver Foundation. In order to remove the danger, a peer-to-peer sinkhole operation was conducted. Concurrently, Sality-related domains have been taken over in Europe and the United States. First Assistant US Attorney Bill Essayli stated that malware, botnets, and cybercriminals pose a serious threat to the security and economics of our country. This successful attempt to dismantle the Sality botnet demonstrates how the public...
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
News

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

According to watchTowr, threat actors are taking advantage of a recently fixed critical security vulnerability affecting JFrog Artifactory just days after it was made public. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), an instance of an Artifactory authentication bypass that may grant administrative access. According to a description of the defect on CVE.org, JFrog Artifactory has an authentication vulnerability that, under normal settings, may enable an unauthenticated attacker with network access to achieve administrative rights. On August 28, 2026, JFrog published Artifactory version 7.161.20, which fixed the vulnerability. The following versions are impacted: 7.161.0 > 7.161.19 7.146.0 > 7.146.36 7.133.0 > 7.133.28 7.125.0 > 7.125.19 7.1...