Today's report Older
Source: Security Rabbits
The Rabbit's Foot (TLDR)
Critical Chrome Android Sandbox Escape (CVE-2026-9876)
A critical use-after-free in WebGL allows remote sandbox escape via crafted HTML. Update Chrome on Android to 148.0.7778.216 or later immediately.
Zimbra Collaboration Suite RCE Added to CISA KEV
An unauthenticated OS command injection in ZCS is actively exploited. Apply vendor mitigations and patch per CISA BOD 26-04 guidance without delay.
SPIP RCE Actively Exploited in the Wild
Unauthenticated remote code execution lets attackers fully compromise SPIP servers. Upgrade to version 4.4.21 or later immediately.
GitLab Critical Flaw (CVE-2026-19478) Under Active Exploitation
A critical code injection (CVSS 9.4) allows unauthenticated attackers to modify or delete public projects. Patch GitLab immediately to prevent data loss.
Golf Canada Data Breach Exposes 569K Records
Hundreds of thousands of user records (emails, names, DOB, locations) are circulating on Telegram. If you have a Golf Canada account, change your password and watch for phishing.
Source: CVE Trend
Trending vulnerability
CVE-2026-9876
Google Chrome
    Published: 2026-05-28
    Updated: 2026-07-21




🥕 🥕 🥕
(26%)
Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Source: Have I been pwned?
Have I been pwnd
Golf Canada
(golfcanada.ca)
    Count: 568,972
    Published: 2026-05-14
    Updated: 2026-08-22




In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names, usernames, dates of birth, genders and approximate geographic locations (city, province and postcode). Golf Canada didn't respond to multiple attempts to make contact, and it remains unclear whether the data was obtained via unintentionally exposed website features or a security vulnerability.
Source: CISA
CISA exploits

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-08-21)
Source: NIST
NIST CVE
Actively exploited in the wild, this unauthenticated remote code execution vulnerability allows attackers to take full control of vulnerable SPIP servers. Immediately upgrade to version 4.4.21 or later.
This authentication bypass vulnerability allows any unauthenticated attacker to log in as any user, including administrators, by knowing their email address. Update the plugin immediately to mitigate the risk of complete site takeover.
Multiple critical vulnerabilities in Incus allow specially crafted images or backups to read/write arbitrary files on the host, leading to arbitrary command execution. Upgrade to version 7.2.0 or later to address these issues.
A passive BLE sniffing attack can recover Wi-Fi credentials and session UUIDs from a wide range of DJI drones, allowing an attacker to join the drone's network and decrypt traffic. Apply the vendor's firmware updates to mitigate this risk.
A chain of vulnerabilities, including default credentials and command injection, allows remote attackers to gain administrative access and execute arbitrary OS commands as root. Update to a patched version immediately.
An authenticated tenant can exploit a metalink vulnerability to achieve cross-tenant root access on the KVM hypervisor. Upgrade to version 4.20.3.1 or 4.22.1.1 to prevent this severe privilege escalation.
A user with Neptune access through Athena Federated Query can gain access to properties in the Lambda function supplying the compute. Upgrade to aws-athena-query-federation v2026.30.1 or later.
Other software at risk
\\   ArchitectPanel Web Admin Panel \\   AWS Athena Query Federation \\   BabelDOC \\   Checkmate \\   Cloud Foundry BOSH CLI \\   Combodo iTop \\   Comfast CF-N1-S \\   Datiphy Data Management Center \\   Defuddle \\   DJI Drones \\   DiscordChatExporter \\   Drag and Drop Multiple File Upload for Contact Form 7 \\   GNU Emacs \\   Genians Genian NAC \\   Git for Windows \\   GeoTools \\   Headroom \\   Hydra \\   Incus \\   Jet Admin \\   J2Store \\   JSONata \\   Keystone \\   kin-openapi \\   LeafWiki \\   LibVNCClient \\   llama.cpp \\   MCP Streamable HTTP server \\   Microsoft UFO \\   MISP \\   MISP-STIX \\   multicluster engine (MCE) \\   Nezha Monitoring \\   OctoPrint \\   Omnigent \\   OMEN Gaming Hub \\   ONNX \\   OpenSearch Dashboards \\   OpenViking \\   Paperclip \\   Phalcon \\   RaTeX \\   Recce \\   Reconmap \\   Remote Utilities Host \\   Roskus Prospero Flow CRM \\   Rust internment crate \\   Rust append-only-vec crate \\   Rust arrayref crate \\   SiYuan \\   SpecifyJS \\   SPIP \\   Stable Diffusion WebUI \\   TensorZero \\   TP-Link TL-MR6400 \\   UAC (Unix-like Artifacts Collector) \\   Unleash \\   WeeChat \\   WPForms Pro \\   Xinference \\   xShop \\   YOOtheme Pro \\   Zoo \\   YOURLS \\   Azure SQL Database \\   FreeRTOS-Kernel \\   mod_auth_openidc \\   FORT Validator \\   Atlantis \\   Apache InLong \\   Apache CloudStack \\   Dokan \\   AI Engine \\   Automation Web Platform – Notifications and OTP for WooCommerce \\   Arc \\   Arc Enterprise
News
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 [...] (The Hacker News)
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is [...] (The Hacker News)
Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names [...] (Security Affairs)
Fake Conferences, OAuth and WhatsApp: Inside Russias New Espionage Tactics
Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff. Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber [...] (Security Affairs)
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks (Unsourced)
CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...] (BleepingComputer)
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known [...] (Security Affairs)
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an [...] (The Hacker News)
GitLab Warns of Active Exploitation of Critical GraphQL Flaw
GitLab flaw CVE-2026-19478 is now under active exploitation, allowing unauthenticated attackers to modify or delete public projects. WatchTowr researchers warn of active exploitation of critical GitLab flaw CVE-2026-19478 (CVSS score of 9.4). This [...] (Security Affairs)
Microsoft patches max severity code execution, privilege escalation flaws
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...] (BleepingComputer)
Source: Ransomware.live
Ransomware attacks
🛑 thegentlemen
UOLconsult  \\ Akatake Engineering  \\ Geb Sas  \\ ESCON Group  \\ dlp motive  \\ Lexacaucho  \\ LOG Systems  \\ Magdalena Grand Beach Golf Resort  \\ Oceanica Internacional  \\ CAZ Investments  \\ AWJ Holding  \\ Ariel Energia  \\ ARBEITERKAMMERN  \\ Aquasea  \\ Almeer
🧱 settra
avkvalves.com  \\ gt-tele.com
🐛 rhysida
Battle Creek Public Schools  \\ Fairview Dental Group
👻 qilin
Professional  \\ Quaker State Mexico  \\ The Pendas Law Firm  \\ iPic  \\ Gindre India  \\ Cinépolis  \\ Blake Services
🧨 pear
First Commerce LLC  \\ Clifton Architectural Glass & Metal
👁 Panzer
Nteitalia
🍄 dragonforce
Hogan Omidi P.C.
🕷️ direwolf
NorthStar  \\ Allstar Industries  \\ The Revel Collective  \\ Authenticate Information Systems  \\ Studee  \\ Reviso Cloud Accounting Limited  \\ Aztec Software  \\ ProSim Aviation Research  \\ MCT Group of Companies  \\ Deer Creek-Mackinaw CUSD  \\ Diaco Global  \\ iSON XPERIENCES  \\ HP Carriers
🦇 anubis
Interim HealthCare [Head office]
🔒 akira
JC Sales
Source: Hybrid Analysis
Top malicious URL
Source: Hybrid Analysis
Top malicious files