2026-07-28
2026-07-28 08:00Z
HIGH

Mirage Kitten targets Middle East and Africa region with new malware

Kaspersky Securelist·securelist.comin the wild

Kaspersky researchers documented a previously undisclosed malware toolkit attributed to Mirage Kitten (UNC1549/Smoke Sandstorm/Nimbus Manticore) targeting aerospace, aviation, defense, and telecom sectors across the Middle East and Africa. The toolkit comprises NightLedger (a Windows backdoor using DLL search-order hijacking), BridgeHead, and ArcBridge (two custom WebSocket-based SOCKS5 tunnelers with per-target username validation and enterprise proxy traversal logic). Victims span Egypt, Jordan, Tanzania, Pakistan, Ethiopia, and Burkina Faso, with initial access via spear-phishing using recruitment-themed lures and lookalike videoconferencing pages.

SRFOsTACTA0004TACTA0001TACTA0002SRFNetworkTACTA0003TACTA0008TACTA0011
78
Edit Score
2026-07-28
2026-07-28 07:16Z
CRIT

CVE-2026-14545 — TrueBooker: The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14545

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDTruebookerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-28
2026-07-28 00:00Z
HIGH

Chaos in Teams vishing

Sophos X-Ops·news.sophos.comin the wild

Sophos X-Ops tracked STAC4749, a financially motivated threat group conducting Microsoft Teams vishing campaigns (February–June 2026) targeting North American organizations across services, manufacturing, energy, and construction sectors. The group deployed a custom modular malware chain (Python backdoor, Golang implants, reverse SOCKS proxy) for persistence and lateral movement, ultimately facilitating Chaos ransomware deployment in at least three incidents with sub-17-hour dwell times. The campaign demonstrated rapid tactical iteration—switching from Quick Assist to RemSupp RMM, rotating malware filenames, and evolving registry persistence mechanisms—indicating operational maturity and financial motivation.

SRFApplicationTACTA0005TACTA0001TACTA0003SRFCloudTACTA0011SWChaosSWMicrosoft Teams
78
Edit Score
2026-07-27
2026-07-27 22:16Z
CRIT

CVE-2021-32088 — Quest: An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-32088

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie. CVSSv3.1 9.8 (CRITICAL)

CWECWE 384VNDQuestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 22:16Z
HIGH

CVE-2021-32087 — Quest: This allows remote attackers to trivially gain privileged access to the FTP service interface

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-32087

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems. CVSSv3.1 8.8 (HIGH)

CWECWE 798VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-27
2026-07-27 22:16Z
CRIT

CVE-2021-32086 — Quest: An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-32086

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services. CVSSv3.1 9.8 (CRITICAL)

CWECWE 321VNDQuestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 22:16Z
HIGH

CVE-2021-32085 — Quest: This allows remote attackers to trivially gain privileged access to the MySQL databases.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-32085

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for other systems. CVSSv3.1 8.8 (HIGH)

CWECWE 798VNDQuestTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-27
2026-07-27 22:16Z
CRIT

CVE-2021-32084 — Quest: An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-32084

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284VNDQuestTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
HIGH

CVE-2026-64783 — A use-after-free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64783

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64775 — A memory initialization issue was addressed with improved memory handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64775

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 665TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64774 — An integer overflow was addressed with improved input validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64774

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64772 — An out-of-bounds write issue was addressed with improved input validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64772

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64771 — A buffer overflow was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64771

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64770 — An out-of-bounds write issue was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64770

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64769 — An out-of-bounds write issue was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64769

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
HIGH

CVE-2026-64768 — An out-of-bounds read issue was addressed with improved input validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64768

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may cause an unexpected app termination. CVSSv3.1 8.1 (HIGH)

CWECWE 125TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64767 — A buffer overflow was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64767

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64762 — An out-of-bounds read was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64762

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination. CVSSv3.1 9.8 (CRITICAL)

CWECWE 125TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
HIGH

CVE-2026-64757 — A memory corruption issue was addressed with improved state management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64757

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash. CVSSv3.1 8.8 (HIGH)

CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64751 — A use after free issue was addressed with improved memory management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64751

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64746 — An authorization issue was addressed with improved validation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64746

An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64740 — A parsing issue in the handling of directory paths was addressed with improved path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64740

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
HIGH

CVE-2026-64739 — An out-of-bounds write issue was addressed with improved bounds checking.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64739

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to cause unexpected app termination. CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-27
2026-07-27 21:17Z
CRIT

CVE-2026-64738 — A permissions issue was addressed with additional restrictions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64738

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-27
2026-07-27 21:17Z
HIGH

CVE-2026-64737 — An authorization issue was addressed with improved state management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-64737

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox. CVSSv3.1 8.2 (HIGH)

CWECWE 284TYPVulnerability
8.2
CVSS v3.1
91
Edit Score