2026-05-06
2026-05-06 13:00Z
HIGH

OceanLotus suspected of using PyPI to deliver ZiChatBot malware

Kaspersky Securelist·securelist.comin the wild

Kaspersky researchers discovered malicious Python wheel packages uploaded to PyPI in July 2025 that delivered a previously unknown malware family called ZiChatBot, attributed to OceanLotus APT. The attack targeted both Windows and Linux users through three fake libraries (uuid32-utils, colorinal, termncolor) that acted as droppers, with ZiChatBot using Zulip's public REST APIs as command-and-control infrastructure instead of traditional servers. The packages were removed from PyPI and the attacker's Zulip organization deactivated before widespread infections occurred.

SRFApplicationTACTA0005TACTA0001TACTA0003SRFSupply ChainOSLinuxOSWindowsSWZulip
82
Edit Score
2026-05-06
2026-05-06 13:00Z
HIGH

Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware

Rapid7 Research·rapid7.comin the wild

Rapid7 researchers identified a sophisticated intrusion initially attributed to Chaos ransomware that was actually a false-flag operation by MuddyWater (Seedworm), an Iranian APT affiliated with MOIS. The attackers used interactive Microsoft Teams social engineering to harvest credentials and MFA, established persistence via DWAgent and AnyDesk, deployed a custom RAT (Game.exe) masquerading as WebView2, and exfiltrated data while avoiding file encryption. Attribution was anchored by a code-signing certificate ("Donald Gay") previously linked to MuddyWater's Operation Olalampo, C2 infrastructure overlap (moonzonet.com), and signature tradecraft including pythonw.exe process injection and Teams-based credential harvesting.

SRFApplicationTACTA0004TACTA0005TACTA0001SRFIdentityTACTA0003TACTA0008TACTA0009
82
Edit Score
2026-05-06
2026-05-06 13:00Z
CRIT

CVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM Proxy

Bishop Fox Labs·bishopfox.comCVE-2026-42208in the wild

Bishop Fox researchers confirmed CVE-2026-42208, a critical pre-authentication SQL injection in LiteLLM proxy (versions 1.81.16–1.83.6) affecting the bearer-token verification logic. An unauthenticated attacker can inject SQL via a malformed Authorization header into any LLM API endpoint, exploiting an f-string interpolation sink to extract database contents via timing-based blind SQLi. In-the-wild exploitation was observed within 36 hours of the GitHub advisory publication; the fix (v1.83.7) introduces proper parameter binding.

SRFApplicationTACTA0001SRFCloudSWLitellmVNDBerriaiTYPVulnerabilitySTGInitial AccessSTGCred Access
92
Edit Score
2026-05-06
2026-05-06 13:00Z
CRIT

Otto Support - Excessive Agency and Tool Privileges

Bishop Fox Labs·bishopfox.com

Bishop Fox research demonstrates how AI agents with excessive tool privileges and production-level permissions have caused real-world infrastructure failures, including data loss, email deletion, and multi-hour outages. The post details the 'excessive agency' vulnerability pattern where agents can combine available tools in unintended ways, and presents otto-support, a CTF demonstrating how tiered permissions and role-aware tool registration can mitigate blast radius.

TACTA0002SRFAiTYPResearchSTGExecutionSTGImpactTECT1059EXPPrivilege EscalationEXPRce
82
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43283 — Linux: This would lead to improper unmapping of the buffer.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43283

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle dma_free_coherent() in error path takes priv->rx_buf.alloc_len as the dma handle. This would lead to improper unmapping of the buffer. Change the dma handle to priv->rx_buf.alloc_phys. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43274 — Linux: In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-of-bounds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43274

In the Linux kernel, the following vulnerability has been resolved: mailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq() The cluster_cfg array is dynamically allocated to hold per-CPU configuration structures, with its size based on the number of online CPUs. Previously, this array was indexed using hartid, which may be non-contiguous or exceed the bounds of the array, leading to out-of-bounds access. Switch to using cpuid as the index, as it i CVSSv3.1 8.4 (HIGH)

TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43249 — Linux: In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43249

In the Linux kernel, the following vulnerability has been resolved: 9p/xen: protect xen_9pfs_front_free against concurrent calls The xenwatch thread can race with other back-end change notifications and call xen_9pfs_front_free() twice, hitting the observed general protection fault due to a double-free. Guard the teardown path so only one caller can release the front-end state at a time, preventing the crash. This is a fix for the following double-free: [ 27.052347] Oop CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43239 — Linux: In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43239

In the Linux kernel, the following vulnerability has been resolved: smb: client: prevent races in ->query_interfaces() It was possible for two query interface works to be concurrently trying to update the interfaces. Prevent this by checking and updating iface_last_update under iface_lock. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43233 — Linux: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43233

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() In decode_choice(), the boundary check before get_len() uses the variable `len`, which is still 0 from its initialization at the top of the function: unsigned int type, ext, len = 0; ... if (ext || (son->attr & OPEN)) { BYTE_ALIGN(bs); if (nf_h323_error_boundary(bs, len, 0)) /* len is 0 here */ return H32 CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43232 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43232

In the Linux kernel, the following vulnerability has been resolved: net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accessed in fst_process_tx_work_q() or fst_process_int_work_q(). A typical race conditi CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43215 — Linux: In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43215

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix locking usage for tcon fields We used to use the cifs_tcp_ses_lock to protect a lot of objects that are not just the server, ses or tcon lists. We later introduced srv_lock, ses_lock and tc_lock to protect fields within the corresponding structs. This was done to provide a more granular protection and avoid unnecessary serialization. There were still a couple of uses of cifs_tcp_ses_lock to provi CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
CRIT

CVE-2026-43208 — Linux: In the Linux kernel, the following vulnerability has been resolved: net: do not pass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43208

In the Linux kernel, the following vulnerability has been resolved: net: do not pass flow_id to set_rps_cpu() Blamed commit made the assumption that the RPS table for each receive queue would have the same size, and that it would not change. Compute flow_id in set_rps_cpu(), do not assume we can use the value computed by get_rps_cpu(). Otherwise we risk out-of-bound access and/or crashes. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 12:16Z
CRIT

CVE-2026-43198 — Linux: This allows the removal of one tcp_sync_mss(), since tcp_v4_syn_recv_sock() will call it with the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43198

In the Linux kernel, the following vulnerability has been resolved: tcp: fix potential race in tcp_v6_syn_recv_sock() Code in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock() is done too late. After tcp_v4_syn_recv_sock(), the child socket is already visible from TCP ehash table and other cpus might use it. Since newinet->pinet6 is still pointing to the listener ipv6_pinfo bad things can happen as syzbot found. Move the problematic code in tcp_v6_mapped_ch CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 12:16Z
CRIT

CVE-2026-43197 — Linux: Now we see: printk: console [netcon_ext0] enabled BUG: KASAN: slab-out-of-bounds in string+0x1f7/0x240 Read of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43197

In the Linux kernel, the following vulnerability has been resolved: netconsole: avoid OOB reads, msg is not nul-terminated msg passed to netconsole from the console subsystem is not guaranteed to be nul-terminated. Before recent commit 7eab73b18630 ("netconsole: convert to NBCON console infrastructure") the message would be placed in printk_shared_pbufs, a static global buffer, so KASAN had harder time catching OOB accesses. Now we see: printk: console [netcon_ext0] en CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43190 — Linux: In the case where i + 1 == optlen, this causes an out-of-bounds read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43190

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_tcpmss: check remaining length before reading optlen Quoting reporter: In net/netfilter/xt_tcpmss.c (lines 53-68), the TCP option parser reads op[i+1] directly without validating the remaining option length. If the last byte of the option field is not EOL/NOP (0/1), the code attempts to index op[i+1]. In the case where i + 1 == optlen, this causes an out-of-bounds read, accessing mem CVSSv3.1 8.2 (HIGH)

TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43187 — Linux: That can result in the freemap containing two entries with the same base but

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43187

In the Linux kernel, the following vulnerability has been resolved: xfs: delete attr leaf freemap entries when empty Back in commit 2a2b5932db6758 ("xfs: fix attr leaf header freemap.size underflow"), Brian Foster observed that it's possible for a small freemap at the end of the end of the xattr entries array to experience a size underflow when subtracting the space consumed by an expansion of the entries array. There are only three freemap entries, which means that it is CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
CRIT

CVE-2026-43186 — Linux: In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43186

In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts this field as-is from the incoming packet, with no consistency check against trace->type (the 24-bit field that tells which data items are present). A crafted packet can set nodelen=0 while setting type bits 0-21, causi CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 12:16Z
CRIT

CVE-2026-43185 — Linux: By sending a second message with a large value (>1420 bytes) the attacker can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43185

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() smb_direct_prepare_negotiation() casts an unsigned __u32 value from sp->max_recv_size and req->preferred_send_size to a signed int before computing min_t(int, ...). A maliciously provided preferred_send_size of 0x80000000 will return as smaller than max_recv_size, and then be used to set the maximum allowed alowed receive size for the next mess CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43176 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43176

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: validate release report content before using for RTL8922DE The commit 957eda596c76 ("wifi: rtw89: pci: validate sequence number of TX release report") does validation on existing chips, which somehow a release report of SKB becomes malformed. As no clear cause found, add rules ahead for RTL8922DE to avoid crash if it happens. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43172 — Linux: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43172

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix 22000 series SMEM parsing If the firmware were to report three LMACs (which doesn't exist in hardware) then using "fwrt->smem_cfg.lmac[2]" is an overrun of the array. Reject such and use IWL_FW_CHECK instead of WARN_ON in this function. CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43158 — Linux: This results in an entry size of 80 bytes.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43158

In the Linux kernel, the following vulnerability has been resolved: xfs: fix freemap adjustments when adding xattrs to leaf blocks xfs/592 and xfs/794 both trip this assertion in the leaf block freemap adjustment code after ~20 minutes of running on my test VMs: ASSERT(ichdr->firstused >= ichdr->count * sizeof(xfs_attr_leaf_entry_t) + xfs_attr3_leaf_hdr_size(leaf)); Upon enabling quite a lot more debugging code, I narrowed this down to fsstress trying to set a local CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43139 — Linux: In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43139

In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() xfrm6_get_saddr() does not check the return value of ipv6_dev_get_saddr(). When ipv6_dev_get_saddr() fails to find a suitable source address (returns -EADDRNOTAVAIL), saddr->in6 is left uninitialized, but xfrm6_get_saddr() still returns 0 (success). This causes the caller xfrm_tmpl_resolve_one() to use the uninitialized address in xfrm_state_find(), trigg CVSSv3.1 8.6 (HIGH)

TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2026-43134 — Linux: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43134

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption key size upon receiving L2CAP_LE_CONN_REQ which is required by L2CAP/LE/CFC/BV-15-C which expects L2CAP_CR_LE_BAD_KEY_SIZE. CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-06
2026-05-06 12:16Z
CRIT

CVE-2026-43125 — Linux: When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43125

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree(). Add length validation to prevent potential buffer overflow. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-06
2026-05-06 12:16Z
HIGH

CVE-2025-31951 — HCL: A flaw in a component's input handling was identified that could permit unauthorized command

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-31951

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution. CVSSv3.1 8.8 (HIGH)

CWECWE 77CWECWE 451CWECWE 351VNDHclTYPVulnerability
8.8
CVSS v3.1
94
Edit Score