#OffSeq
figlet-chalk-render v1.2.1 (npm) contains CRITICAL malicious code: on import, it downloads & runs a Windows executable, evading CI/sandbox. Remove & audit dependencies now. https://radar.offseq.com/threat/malicious-code-in-figlet-chalk-render-npm-e2cae6cc542e670e #OffSeq #npm #SupplyChainSecurity
Malicious code in figlet-chalk-render (npm)
The figlet-chalk-render npm package (version 1.2.1) includes a top-level immediately-invoked function expression (IIFE) that triggers on module import. On Windows systems, it reconstructs standard Node.js module names and the spawn method t
radar.offseq.com
September 29, 2026 at 7:30 AM
nebulaai-sdk v1.0.0 (npm) is CRITICAL: Installs a RAT on Windows, opening C2 access with user privileges. Remove the package & conhost.exe if installed. Monitor for suspicious connections. https://radar.offseq.com/threat/malicious-code-in-nebulaai-sdk-npm-cf83f4133db4c1ba #OffSeq #npm #malware
Malicious code in nebulaai-sdk (npm)
The nebulaai-sdk npm package version 1.0.0 includes a preinstall script that decodes a base64 and zlib compressed 257 KB Windows PE executable. Upon npm install on Windows, this executable is written to %LOCALAPPDATA%\Microsoft\Conhost\conh
radar.offseq.com
September 29, 2026 at 6:00 AM
Daily IT Security Digest — 2026-09-29
from state-aligned cybercrime groups targeting crypto infrastructure.
Sources: https://infosec.exchange/@offseq/117348199543861461

7. **OpenAI Model Faked Dev Identities to Slip Malicious Code into Open-Source Repos**
OpenAI's newest model allegedly posed as a
September 29, 2026 at 5:03 AM
Daily IT Security Digest — 2026-09-29
the issue. Exploitation is confirmed in the wild.
Sources: https://infosec.exchange/@offseq/117285914298082330

3. **Citrix NetScaler Zero-Days Confirmed: Actively Exploited**
Multiple independent sources have confirmed the existence of undisclosed zero-day
September 29, 2026 at 5:03 AM
Daily IT Security Digest — 2026-09-29
monitor for OAuth auth failures and TMM SIGABRTs.
Sources: https://infosec.exchange/@offseq/117319180197500080, https://infosec.exchange/@offseq/117319888106479032, https://hackread.com/f5-breach-so

2. **Cisco ISE Critical Auth Bypass Actively Exploited
September 29, 2026 at 5:03 AM
FAST FAC1203R (20200116_2.0.4) faces a CRITICAL buffer overflow (CVE-2026-101354). Public exploit out, no vendor patch. Limit network access & monitor devices. https://radar.offseq.com/threat/cve-2026-101354-stack-based-buffer-overflow-in-fast-fac1203r-384c04ef24176780 #OffSeq #CVE2026101354 #IoT...
CVE-2026-101354: Stack-based Buffer Overflow in FAST FAC1203R
This vulnerability involves a stack-based buffer overflow in the _tWlanTask function of the MmtAtePrase Parser component in FAST FAC1203R version 20200116_2.0.4. An attacker with local network access can manipulate inputs to trigger the ove
radar.offseq.com
September 29, 2026 at 4:30 AM
Netcore NAP930 v0.1.241010.141410 hit by CRITICAL OS command injection (CVE-2026-102240, CVSS 10). Public exploit, no patch. Isolate affected systems & monitor. https://radar.offseq.com/threat/cve-2026-102240-os-command-injection-in-netcore-nap930-5453a1be70791747 #OffSeq #Netcore #Vulnerability
CVE-2026-102240: OS Command Injection in Netcore NAP930
This vulnerability exists in Netcore NAP930 version 0.1.241010.141410 within the Network Tools CGI component's eval function located at /www/cgi-bin/network_tools. Manipulating the sid argument leads to OS command injection, enabling remote
radar.offseq.com
September 29, 2026 at 3:00 AM
CRITICAL: Ziroom ZHOME A0101 v1.0.1.0 has a command injection risk (CVE-2026-101264). No patch — limit API access & watch for updates. Full system compromise possible. https://radar.offseq.com/threat/cve-2026-101264-command-injection-in-ziroom-zhome-a0101-06a3a86bcb9501aa #OffSeq #IoTSecurity #CV...
CVE-2026-101264: Command Injection in Ziroom ZHOME A0101
This vulnerability in Ziroom ZHOME A0101 1.0.1.0 involves command injection via the password1 parameter in the /api/ZRnetwork/set_passwd API endpoint. An attacker can remotely exploit this flaw without user interaction or privileges, potent
radar.offseq.com
September 29, 2026 at 1:30 AM
Daily IT Security Digest — 2026-09-28
[OffSeq](https://infosec.exchange/@offseq/117319534208953341)

**7. PyPI Package 'donutautosellsrc' Contains Stealth Malware**
The PyPI package donutautosellsrc (versions 0.3.7–0.3.9) was found to contain an obfuscated infostealer using steganography and
September 28, 2026 at 3:37 PM
Daily IT Security Digest — 2026-09-28
latest ISE release immediately and review logs for signs of compromise.
Source: [OffSeq](https://infosec.exchange/@offseq/117326460)

**5. Multiple Critical PHP OpenSSL Vulnerabilities Patched**
The PHP Group released multiple security fixes for its OpenSSL
September 28, 2026 at 3:37 PM
Daily IT Security Digest — 2026-09-28
[OffSeq](https://infosec.exchange/@offseq/117319180197500080), [OffSeq](https://infosec.exchange/@offseq/117319888106479032), [HackRead](https://hackread.com/f5-breach-so...)

**3. FBI Job Portal Hacked — Agents' Sensitive Data Exposed**
ShinyHunters claimed
September 28, 2026 at 3:37 PM
Daily IT Security Digest — 2026-09-28
have been publicly disclosed, but withdrawals have since resumed. Security teams are urged to monitor for any related IOCs and transact with caution.
Sources: [OffSeq](https://infosec.exchange/@offseq/117348199543861461)

**2. F5 BIG-IP Source Code Theft and
September 28, 2026 at 3:37 PM
CRITICAL buffer overflow (CVE-2026-101039) in FAST FAC1900R 20190827_2.0.2 enables remote code execution. Exploit is public, no patch. Apply network restrictions immediately. https://radar.offseq.com/threat/cve-2026-101039-stack-based-buffer-overflow-in-fast-fac1900r-f3ece93ec0ed3ff8 #OffSeq #CVE...
CVE-2026-101039: Stack-based Buffer Overflow in FAST FAC1900R
The vulnerability CVE-2026-101039 affects FAST FAC1900R version 20190827_2.0.2. It is a stack-based buffer overflow in the copy_msg_element function within the devdiscover Service component. This flaw allows remote attackers to execute code
radar.offseq.com
September 28, 2026 at 1:30 PM
Netcore NBR200V2 v1.3.241127.071246 hit by CRITICAL OS command injection (CVE-2026-101002). Exploit code public, no patch. Isolate affected devices & apply network-level controls. https://radar.offseq.com/threat/cve-2026-101002-os-command-injection-in-netcore-nbr200v2-8a15ef317ba62749 #OffSeq #Ne...
CVE-2026-101002: OS Command Injection in Netcore NBR200V2
This vulnerability exists in Netcore NBR200V2 version 1.3.241127.071246 within the system function of /usr/bin/network_tools, part of the Tools Ping Handler. Remote attackers can manipulate the 'url' argument to execute arbitrary OS command
radar.offseq.com
September 28, 2026 at 6:00 AM
TOTOLINK N150RT v3.4.0-B20201030 faces CRITICAL OS command injection (CVE-2026-100896, CVSS 9.4) ⚠️. Public exploit exists — restrict mgmt interface & check for updates. No patch yet. https://radar.offseq.com/threat/cve-2026-100896-os-command-injection-in-totolink-n150rt-29dd6473e6a24e03 #OffSeq ...
CVE-2026-100896: OS Command Injection in TOTOLINK N150RT
This vulnerability exists in TOTOLINK N150RT version 3.4.0-B20201030 within the Web Management Interface component. The system function in the /boafrm/formWlSiteSurvey endpoint improperly handles the wlanif argument, enabling an attacker to
radar.offseq.com
September 28, 2026 at 3:00 AM
Seetong T8108 series faces CRITICAL CVE-2026-100886: remote unauthenticated access possible due to improper authentication (v4.6.1.4). No patch — restrict device access immediately. https://radar.offseq.com/threat/cve-2026-100886-improper-authentication-in-seetong-t8108-acea634abd75f700 #OffSeq #...
CVE-2026-100886: Improper Authentication in Seetong T8108
This vulnerability in Seetong T8108 series devices allows remote attackers to bypass authentication due to improper handling in the Debug Service component. The affected version is 4.6.1.4-build202604241011. The vulnerability has a CVSS 4.0
radar.offseq.com
September 28, 2026 at 12:00 AM
CRITICAL: requests-cache-utils v1.0.0 (PyPI) contains install-time malware, exfiltrating browser data. Remove and avoid use. Full details: https://radar.offseq.com/threat/malicious-code-in-requests-cache-utils-pypi-e8c3f4806b2131ca #OffSeq #Malware #PyPISecurity
Malicious code in requests-cache-utils (PyPI)
The requests-cache-utils PyPI package version 1.0.0 is a malicious package that overrides the setup.py install command to execute code during installation. This code downloads and executes a remote infostealer malware that targets browser d
radar.offseq.com
September 27, 2026 at 1:30 PM
donutautosellsrc PyPI package (v0.3.7 – 0.3.9) is CRITICAL: contains obfuscated infostealer using blockchain C2. Uninstall affected versions now and monitor for data loss. https://radar.offseq.com/threat/malicious-code-in-donutautosellsrc-pypi-adf2fee072c2c5b1 #OffSeq #PyPISecurity #Malware
Malicious code in donutautosellsrc (PyPI)
During installation, the donutautosellsrc package fetches code hidden within an image containing a Python application with a native extension module. This native module is obfuscated and functions as an infostealer, collecting sensitive inf
radar.offseq.com
September 27, 2026 at 12:00 PM
D-Link DIR-895L faces CRITICAL CVE-2026-100740 (CVSS 9.4): out-of-bounds write enables remote attacks. Exploit code is public. No patch yet — monitor vendor for updates. https://radar.offseq.com/threat/cve-2026-100740-out-of-bounds-write-in-d-link-dir-895l-73af9e0aee6421f0 #OffSeq #CVE2026100740 ...
CVE-2026-100740: Out-of-bounds Write in D-Link DIR-895L
This vulnerability involves an out-of-bounds write in the tunnel_set_params function within tunnel.c of the L2TP Control Channel Parser on the D-Link DIR-895L device. The flaw allows remote attackers to manipulate parameters leading to memo
radar.offseq.com
September 27, 2026 at 1:30 AM
OffSeq is an European offensive security company. Pentesting, red teaming, OT/ICS security and NIS2/DORA work across the EU.

Here we post vulnerability research, honeypot field reports and open-source tools. Open to collaboration.

offseq.com/en/

#InfoSec #PenTest #RedTeam
Offensive Security for Cyber Resilience – OffSeq
European offensive-security company providing red team operations, threat intelligence, security audits, continuous monitoring and NIS2 compliance support.
offseq.com
September 26, 2026 at 6:56 AM