#activeExploitation
📰 Check Point Peringatkan Zero-Day Security Management Server yang Aktif Dieksploitasi

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/23/check-point-cve-2026-93616-security-management-server-zero-day/

#activeExploitation #checkPoint #checkPointSoftware #cisa #cve-2026-93616 #c
September 23, 2026 at 5:44 AM
📰 F5 Rilis Patch untuk Zero-Day BIG-IP APM yang Dieksploitasi dalam Serangan RCE

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/24/f5-big-ip-apm-cve-2026-94127-zero-day-rce/

#accessPolicyManager #activeExploitation #big-ipApm #cisa #cisaKev #cve #cve-2026-94127 #cyberAttack #c
September 24, 2026 at 3:56 AM
📰 CISA Perintahkan Pemerintah AS Patch Celah Zyxel GS1900 yang Aktif Dieksploitasi

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/22/cisa-zyxel-gs1900-cve-2026-7273-dieksploitasi/

#activeExploitation #cisa #cve-2026-7273 #cybersecurity #dataExfiltration #dataTheft #exploit #fi
September 22, 2026 at 1:27 PM
Hackers moved from scanning WordPress sites to creating files that could run commands, just hours after a fix was released.

The flaw only affects spe…

https://en.hacks.gr/wordpress-chaker-ekmetalleyontai-krisimo-provlima-liges-ores-meta-ti-diorthosi-toy/

#WordPress #Patchstack #ActiveExploitation
September 23, 2026 at 7:52 PM
Fastjson 1.x Zero-Day RCE Under Active Exploitation — No Patch Available

https://blindthoughts.com/fastjson-1x-rce-active-exploitation-no-patch

#rce #java #fastjson #zeroday #activeexploitation
July 25, 2026 at 2:16 PM
Magento and Adobe Commerce stores are being attacked through a flaw affecting all versions.

Latest updates didn’t prevent the first reported incident; Ado…

https://en.hacks.gr/oles-oi-ekdoseis-magento-kai-adobe-commerce-epireazontai-apo-sovaro-provlima/

#Magento #AdobeCommerce #ActiveExploitation
September 8, 2026 at 12:24 AM
August 29, 2026 at 5:17 AM
August 28, 2026 at 12:17 PM
August 27, 2026 at 9:17 AM
August 25, 2026 at 4:17 AM
Microsoft Entra ID RCE Flaw (CVSS 10.0) Exploited in the Wild — Patch Is Automatic, But Check Your Logs

https://blindthoughts.com/microsoft-entra-id-cve-2026-69836-rce-exploited

#microsoftentraid #remotecodeexecution #activeexploitation #vulnerability #identitysecurity
August 21, 2026 at 7:17 AM
August 15, 2026 at 5:17 AM
August 13, 2026 at 8:17 AM
Critical Adobe Commerce Flaw Under Active Exploit — Patch Now to Stop Account Hijacking

https://blindthoughts.com/adobe-commerce-cve-2026-71362-active-exploitation

#adobecommerce #magento #cve #activeexploitation #ecommercesecurity
August 13, 2026 at 5:17 AM
N-able Issues Emergency N-central Hotfixes as Attackers Pivot to Managed Systems

https://blindthoughts.com/n-able-n-central-hotfix-active-exploitation

#rmm #nable #ncentral #activeexploitation #mspsecurity
August 8, 2026 at 12:18 PM
July 28, 2026 at 12:16 PM
July 28, 2026 at 4:16 AM
July 6, 2026 at 8:16 PM
July 1, 2026 at 2:16 PM
Hackers Exploit cPanel Flaw to Gain Control of Thousands of Websites #activeexploitation #cPanel #SSHKeys
Hackers Exploit cPanel Flaw to Gain Control of Thousands of Websites
 Hackers are still aggressively exploiting a critical bug in cPanel and WHM, the widely used web hosting control software that powers countless websites across the internet. The flaw, tracked as CVE-2026-41940, lets attackers bypass the login screen and seize administrative access to affected servers without a password. Because cPanel is deeply embedded in shared hosting environments, a single compromised server can expose many unrelated websites at once.  The scale of the problem is large. Security researchers say more than 550,000 cPanel servers may be vulnerable, while roughly 2,000 instances were believed to be compromised at the time of reporting, down from about 44,000 last week. That drop suggests some hosting providers and administrators have already begun cleaning up or blocking attacks, but the threat remains active and widespread.  What makes the issue especially dangerous is how much control the bug gives to attackers. Once inside, criminals can manage website files, databases, SSL certificates, and other critical settings tied to every site hosted on the server. In practice, that means they can deface websites, install backdoors, steal data, or redirect visitors to malicious pages, all from the control panel intended for legitimate administrators. The vulnerability has also shown signs of being abused before the public disclosure. One hosting provider reported seeing exploitation attempts as early as late February, well before the issue was officially disclosed and patched. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog, confirming that it is being used in real-world attacks and should be treated as an urgent patching priority.  For site owners, the response needs to be immediate and practical. Systems should be patched to the latest cPanel and WHM releases, exposed login panels should be restricted where possible, and administrators should check for unauthorized users, modified files, suspicious SSH keys, and unexpected database changes. Hosting providers such as Namecheap, HostGator, and KnownHost have already taken emergency steps, including temporarily blocking access while they applied fixes. The wider lesson is that a single authentication-bypass flaw in a core admin tool can become a large-scale internet incident almost overnight.
dlvr.it
May 16, 2026 at 1:56 AM
CrossCurve Bridge Hit by $3 Million Exploit after Smart Contract Flaw #activeexploitation #BugExploit #CrossCurve
CrossCurve Bridge Hit by $3 Million Exploit after Smart Contract Flaw
CrossCurve, a cross-chain bridge formerly known as EYWA, has suffered a major cyberattack after hackers exploited a vulnerability in its smart contract infrastructure, draining about $3 million across multiple blockchain networks. The CrossCurve team confirmed the incident on Sunday, saying its bridge infrastructure was under active attack and urging users to immediately stop interacting with the protocol. “Our bridge is currently under attack, involving the exploitation of a vulnerability in one of the smart contracts used,” CrossCurve said in a post on X.  “Please pause all interactions with CrossCurve while the investigation is ongoing.” Blockchain security account Defimon Alerts said the exploit stemmed from a gateway validation bypass in CrossCurve’s ReceiverAxelar contract. According to the analysis, the contract was missing a critical validation check, allowing attackers to call the expressExecute function using spoofed cross-chain messages.  By abusing this flaw, the attackers were able to bypass the intended gateway validation logic and trigger unauthorized token unlocks on the PortalV2 contract, resulting in the loss of funds. The exploit affected CrossCurve deployments across several blockchain networks.  Data from Arkham Intelligence, shared by Defimon Alerts, shows that the PortalV2 contract balance fell from roughly $3 million to nearly zero around Jan. 31. Transaction records indicate the attack unfolded across multiple chains rather than a single network.  CrossCurve operates a cross-chain decentralized exchange and liquidity protocol built in partnership with Curve Finance. The system relies on what it describes as a Consensus Bridge, which routes transactions through multiple validation layers, including Axelar, LayerZero, and the EYWA Oracle Network. In its documentation, CrossCurve had described this architecture as a security advantage, stating that “the probability of several crosschain protocols getting hacked at the same time is near zero.”  The incident, however, showed that a single smart contract flaw can still compromise a broader system. The project has backing from prominent figures in decentralized finance. Michael Egorov invested in the protocol in September 2023, and CrossCurve later said it had raised $7 million from venture capital firms. Following the exploit, Curve Finance warned users with exposure to EYWA-related pools to reassess their positions.  “Users who have allocated votes to Eywa-related pools may wish to review their positions and consider removing those votes,” Curve Finance said on X.  Security researchers said the attack echoes earlier bridge exploits, drawing comparisons to the 2022 Nomad bridge hack, in which about $190 million was drained after attackers discovered a faulty validation mechanism.
dlvr.it
February 3, 2026 at 5:20 PM