1h ago
2026-07-30 11:00Z
HIGH

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Kaspersky Securelist·securelist.com

Kaspersky identified two new tailored backdoors, OctLurk and SilkLurk, deployed in a coordinated cyber-espionage campaign targeting government organizations across Central Asia (Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, Syria) since January 2025. Both backdoors feature custom loaders using victim-machine fingerprinting for payload decryption, plugin-based architecture for command shells, file management, keylogging, credential harvesting, and remote access. The campaign demonstrates sophisticated post-compromise activity including event log exfiltration, Impacket secretsdump deployment for domain controller credential theft, and browser password extraction.

SRFOsTACTA0004TACTA0001SRFNetworkTACTA0007TACTA0003TACTA0008TACTA0009
78
Edit Score
1h ago
2026-07-30 11:00Z
HIGH

Building secure Uniswap v4 hooks

Trail of Bits·blog.trailofbits.com

Trail of Bits published a comprehensive security guide for Uniswap v4 hooks, identifying seven recurring failure patterns in hook and application code that have led to $20M+ in losses (Cork ~$12M, Bunni ~$8.4M). The analysis covers missing caller checks, pool validation gaps, accounting bugs, callback timing issues, permission-bit mismatches, denial-of-service vectors, and state-mutation risks during callback sequences.

SRFApplicationTACTA0005SRFWebSWUniswapTYPResearchSTGExecutionSTGImpactEXPAuth Bypass
78
Edit Score
1h ago
2026-07-30 10:35Z
CRIT

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 Research·rapid7.comCVE-2026-59309CVE-2026-59310

Broadcom published VMSA-2026-0006 disclosing two critical unauthenticated vulnerabilities in VMware vCenter Server: CVE-2026-59309 (authentication bypass in Directory Service, CVSS 9.8) and CVE-2026-59310 (directory traversal in Syslog server enabling RCE, CVSS 9.8). Both require only network access and no prior authentication; patches are available across vCenter 8.0, 9.0, and 9.1 versions. No public PoC or in-the-wild exploitation reported at publication, but vCenter has a history of rapid weaponization.

SRFApplicationTACTA0001TACTA0002SRFCloudSWVcenterSWVsphereVNDVmwareVNDBroadcom
92
Edit Score
4h ago
2026-07-30 08:00Z
CRIT

Toy Ghouls’ new toy: the GenieLocker ransomware

Kaspersky Securelist·securelist.comin the wild

Kaspersky disclosed GenieLocker, a custom-built ransomware family deployed by the Toy Ghouls threat group since March 2026 against Russian manufacturing and construction sectors. The malware runs natively on Windows, Linux, and ESXi, uses XChaCha20-Poly1305 for file encryption with Curve25519-XSalsa20-Poly1305 for key wrapping, and includes anti-debugging, process termination, and service shutdown capabilities. The group has transitioned from using third-party ransomware (RedAlert, LockBit, Babuk) to this proprietary variant, reducing operational dependency and unifying their encryption stack across platforms.

SRFApplicationSRFOsTACTA0001TACTA0007TACTA0008TACTA0009OSLinuxOSWindows
78
Edit Score
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-7849 — Due to improper neutralization of special elements, an unauthenticated remote attacker is able to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7849

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44108 — Due to a flaw in the execution order of scripts during shutdown, the firewall

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44108

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to connect to these services, resulting in full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 696TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44104 — This allows an unauthenticated remote attacker to install a modified firmware, resulting in full

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44104

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44101 — CHARX: Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44101

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDCharxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44100 — CHARX: The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44100

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306VNDCharxTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
5h ago
2026-07-30 07:16Z
HIGH

CVE-2026-44098 — This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to perform an OS command injection, resulting in the execution of arbitrary commands as the limited user charx-oa. Charging could be interrupted. CVSSv3.1 8.6 (HIGH)

CWECWE 78TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5h ago
2026-07-30 07:16Z
HIGH

CVE-2026-44094 — This could allow the attacker to gain SSH access to the system as an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44094

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configuration including default credentials. This could allow the attacker to gain SSH access to the system as an unprivileged user "user-app". Charging could be interrupted. CVSSv3.1 8.6 (HIGH)

CWECWE 636TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44092 — This may lead to integrity and availability loss.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44092

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss. CVSSv3.1 9.1 (CRITICAL)

CWECWE 93TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44091 — An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44091

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss. CVSSv3.1 9.1 (CRITICAL)

CWECWE 501TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
5h ago
2026-07-30 07:16Z
CRIT

CVE-2026-44090 — Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44090

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5h ago
2026-07-30 06:25Z
CRIT

CVE-2026-58066 — Rocket: Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58066

Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDRocketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
5h ago
2026-07-30 06:25Z
CRIT

CVE-2026-58046 — Plesk: Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58046

Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89VNDPleskTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
5h ago
2026-07-30 06:25Z
HIGH

CVE-2026-47882 — Spring: When enabling Spring Boot DevTools support for a remote application target (for example a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47882

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tool CVSSv3.1 8.3 (HIGH)

VNDSpringTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
5h ago
2026-07-30 06:25Z
HIGH

CVE-2026-47873 — Boot: The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47873

The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier CVSSv3.1 8.0 (HIGH)

VNDBootTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
5h ago
2026-07-30 06:25Z
HIGH

CVE-2026-47858 — Starting: Spring Boot applications in the Spring Tools with the live information mode enabled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47858

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier CVSSv3.1 8.0 (HIGH)

VNDStartingTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
5h ago
2026-07-30 06:25Z
HIGH

CVE-2026-16526 — PCP: A flaw in the PCP linux_sockets module exposes an unsecured internal connection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16526

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root. CVSSv3.1 8.8 (HIGH)

CWECWE 403VNDPcpTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
7h ago
2026-07-30 05:16Z
CRIT

CVE-2026-16610 — Admin: The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html wi CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
7h ago
2026-07-30 05:16Z
HIGH

CVE-2026-14356 — FleekDash: The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14356

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite the email address and password of any WordPress user, including administrators, enabling full account takeover and complete site compromise. The public /wp CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDFleekdashTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
9h ago
2026-07-30 03:16Z
CRIT

CVE-2026-48449 — Adobe: Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48449

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
9h ago
2026-07-30 03:16Z
HIGH

CVE-2026-48448 — Adobe: Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48448

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 89VNDAdobeTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
14h ago
2026-07-29 22:16Z
HIGH

CVE-2026-67595 — VaahCMS: versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67595

VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added CVSSv3.1 8.1 (HIGH)

CWECWE 506VNDVaahcmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score