Threat Intelligence

The latest vulnerabilities, exploits, and threat actor activity — curated by the Lost Edges Security research team.

50 items · sorted by date

Severity: Critical High Medium Low
Informational
Policy

US and China prepare for mid-September AI safety talks.

On Friday, the US and China agreed to discuss various AI safety risks during a planned September meeting. These will be the first official bilateral talks between the two countries since the second Trump administration began, and the talks will be led by US Treasury Secretary Sco

policy
CyberWire
Informational
Breach

Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed servi

breach vpn
Bleeping Computer
High
Malware

MantaxOtax Android Malware Combines Ransomware With Spyware

MantaxOtax Android malware has combined file encryption with extensive surveillance, letting attackers steal messages, credentials and device data while restricting access to infected phones. In a technical write up published on September 9, Zimperium's zLabs team linked the malw

ransomware malware
Infosecurity Magazine
High
Malware

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with ph

ransomware phishing malware telecom
Bleeping Computer
Informational
Policy

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

The FBI has published its first ever Cyber Strategy, providing guidance on how the agency investigates and disrupts cyber threat actors. The new document, published on September 9, highlights the need for strategic response to escalating cyber-attacks perpetrated by financially-m

policy nation-state
Infosecurity Magazine
Medium
Vulnerability

Multiple vulnerabilities in SolarView Compact

SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities. The affected products include SolarView Compact, SV-CPT-MC310 versions prior to 9.00, and SV-CPT-MC310F versions prior to 9.00.

vulnerability
Jvn
Informational
Law Enforcement

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The U.S. Department of Justice (DOJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and depl

law-enforcement
The Hacker News
Informational
Research

New N0va Phishkit Targets North America and EU - A Growing Identity Risk for SOCs

Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology, consulting, and healthcare. What makes N0va especially relevant for SOC leaders is how it spreads the attack across different la

research cloud
Cyber Security News
High
Vulnerability

Once Bluemoon Multiple State Aligned Threat Actors Rapidly Adopt Novel Exploit

Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities. Proofpoint is tracking the exploit kit used in this activity as BlueMoon. The first observed cluster using the BlueM

vulnerability windows
Proofpoint Threat Insight
High
Breach

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. DAVID is the "Driver and Vehicle Information Database" platform operated by the

breach
Bleeping Computer
Informational
Breach

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017

breach
Security Affairs
Critical
Malware CVE-2025-53521

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. The malware shows signs of being a second-stage payload that was likely deployed

rce malware linux
Bleeping Computer
Informational
Policy

Grindr Settles UK Data Privacy Claims for £26m

Grindr has agreed to pay £26m ($35.2m) to settle a UK group action over allegations that it unlawfully processed users' personal data and misused private information before 2020. The settlement was reached on September 2 and disclosed to investors two days later in a filing with

policy
Infosecurity Magazine
Critical
Policy

The EU CRA's Real Question - What Shipped, and When Did You Know?

Last year, someone submitted a vulnerability report to a security address for a free software project I help to review. It contained 95 vulnerabilities, purportedly. Two or three of the 95 turned out to be real. Then came the second email: pay $100,000, or the report would go pub

policy
Bleeping Computer
High
Breach

Mathspace discloses data breach affecting over 1 million people

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attacke

breach
Bleeping Computer
Informational
Breach

Welsh environment regulator's FoI blunder exposes diversity data of 2,000 staff

Natural Resources Wales (NRW) says diversity data belonging to around 2,000 current and former employees who worked at the environmental regulator between April 2013 and March 2018 was exposed in a classic Freedom of Information (FoI) blunder. The Welsh government-sponsored body

breach policy
The Register Security
High
Malware

JSCeal Hides Crypto Malware in V8 Bytecode

JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. JSCeal uses a clever trick. Instead of deliveri

malware
Security Affairs
Informational
Vulnerability

Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys

Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sund

vulnerability
The Register Security
Informational
Vulnerability

LG TV flaws could let attackers listen in, even in standby mode

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family's phones, laptops, printers, and smart-home devices. Now, a new investigation by Gamers Nexus, carried out with Level1Techs and i

vulnerability
Malwarebytes Labs
Informational
Malware

Node.js - Old Technique Makes a Comeback

Abuse of Node.js has undergone a revival. The Symantec Threat Hunter Team has observed the technique being used by multiple actors since February 2026, with victims including government departments, technology companies, and hotels. The technique's appeal is that node.exe (the bi

malware
Symantec Threat Intelligence
Medium
Policy

Nonprofit sues Trump admin for details on AI safety reviews.

Huntress is tracking a worm-like attack campaign that's installing rogue ScreenConnect clients on unrelated endpoints at various organizations. The attacks begin with social engineering, but the payload can then spread itself within an organization. The reserachers explain, "This

policy
CyberWire
Informational
Vulnerability CVE-2026-28323

Signature Optional - Analysis of CVE-2026-28323

The SamlConsumer.getAuthenticatedUserFromSamlResponse() method was where the authentication decision happened. This method processed SAMLResponse values. The signature verification call was gated behind a null check on the certificate data. If an administrator configured SAML aut

vulnerability
Bishop Fox
Informational
Vulnerability

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

A member of Serbia's student protest movement has been infected with NSO Group's Pegasus spyware through an iMessage zero-click exploit, according to a forensic investigation by the Citizen Lab and the SHARE Foundation. The Citizen Lab said it found high-confidence indicators of

vulnerability
Infosecurity Magazine
High
Malware

Breaking the Seal - Static Deobfuscation of JSCeal's Compiled V8 Bytecode

JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications. Its campaign activity dates back to March 2024. Unlike ordinary JavaScript malware, JSCeal reaches the analyst after two transformations

malware
Check Point Research
Informational
Malware

Security Incident – BGP Hijacking

The Virtualizor platform, for those unfamiliar, is a VPS management platform used by many hosting providers to deploy and manage virtual servers on KVM, Xen, LXC, OpenVZ, Proxmox and other virtualization platforms. It is not some tiny admin panel either. Virtualizor publicly list

malware
Virtualizor
Informational
Vulnerability

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. The glitch, which Microsoft says it working to fix, creates an attacke

vulnerability windows
CSO Online
Informational
Vulnerability

Microsoft Exchange Online outage causes email failures, auth issues

Microsoft is investigating a widespread service issue causing authentication issues, connection problems, email delays and failures, and various other issues for Microsoft 365 customers. It first acknowledged this incident (tracked under EX1464935 in the admin center) at 5:30 PM

vulnerability cloud
Bleeping Computer
Informational
Vulnerability

Cronos blockchain restarts after $74 million Tectonic exploit

The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. According to current information, the threat actor artificially inflated the price of Tectonic's

vulnerability
Bleeping Computer
Medium
Vulnerability

Traefik | Version Through 3.7.11

Bishop Fox staff identified one vulnerability in Traefik, an open-source reverse proxy and ingress controller widely deployed in container and Kubernetes environments. This vulnerability, described as "Request Read Timeout Not Applied to HTTP/3" and tracked as GHSA-7ghq-v6jf-g56c

vulnerability kubernetes
Bishop Fox
High
Malware

Caught in 4K - The Aurora Files

An exposed open directory revealed months of activity from belonging to a Russian speaking Aurora ransomware affiliate, active against more than twenty organisations between April and July 2026. The directory included the operator's own toolkit and shell history alongside the Aur

malware ransomware
Cloudsek
Informational
Breach

Hackers steal data from millions of UK airport customers

Three major UK airports have been hit by a "cyber security incident" in which criminal hackers accessed the data of almost nine million people and demanded a ransom. Manchester Airports Group (MAG), which owns Manchester, East Midlands and London Stansted airports, said customers

breach
BBC news
High
Breach

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it's responding to a "major" cybersecurity incident shortly after the Qilin ransomware gang posted the US federal law enforcement agency on its leak site. An ATF spokesperson told The Register the intruders access

breach ransomware
The Register Security
High
Malware

JavaScript obfuscation - From party trick to phishing kit

We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. Obfuscated JavaScript is still code, but it is code with the useful context stripped out, the names ruined, the strings hi

phishing malware
Cisco Talos Intelligence
Medium
Research

A polymorphic phishing page (that occasionally breaks itself)

But even something that seems to be "run-of-the-mill" at first glance can sometimes turn out to be quite interesting. One such message led to a URL which, instead of displaying a phishing page, caused the browser to remain effectively stuck for about 30 seconds, while utilization

research phishing
SANS Internet Storm Center
Low
Tips

Version Control DFIR - a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps

As threat actors increasingly target Version Control Systems (VCS) to execute both targeted attacks and broad supply chain compromises (such as the campaigns attributed to TeamPCP), it is essential to understand available telemetry, recommended configurations, and available audit

tips supply-chain cloud
Wiz Research
Informational
Vulnerability

AI girlfriend review site's secrets were exposed to the world for three weeks

Our story comes courtesy of Mia Morin, Editor & AI Quality Analyst at Intimeros, a site that rates, reviews, and evaluates AI companions. The trouble started during a redesign when one of Morin's colleagues was working on a test version of the site. The test site was supposed to

vulnerability
The Register Security
Informational
Mobile

Beware of fake Indeed interview apps used to install spyware

From several independent reports, we've seen evidence of scammers using fake Android "interview" apps to target job seekers on the Indeed platform. Indeed is one of the world's largest employment websites, giving scammers access to a huge pool of potential victims, especially in

mobile
Malwarebytes Labs
Critical
Research

New GPUThor attack defeats NVIDIA ECC protection for root access

A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. In a paper published by the University of Toronto, researchers say that GPUThor achieves far

research privilege-escalation cloud
Bleeping Computer
Informational
Research

Your Expired Visa Card Could Be 'Zombified' to Make Contactless Payments

Less expected is that an expired Visa card, too, could serve as an errant key into their bank account if it's left unattended or discarded intact, discovered by a fraudster, and "zombified" using a new technique researchers recently revealed. At the Usenix Cybersecurity Conferenc

research
Wired Security
Informational
Tools

Kubernetes 1.37 - New security features

Kubernetes 1.37 has just been released, bringing 67 enhancements. In terms of security, we've identified 19 changes with security implications spanning new security features to mount volumes, improvements on snapshots, authentication by default on webhooks, and more.

tools kubernetes
Sysdig
Critical
Vulnerability CVE-2026-58073 CVSS 9.5

A GUID is Not a Credential - Unauthenticated RCE in Veeam Service Provider Console

CVE-2026-58073 (CVSS 9.5) and CVE-2026-58072 (CVSS 9.0) are critical vulnerabilities in Veeam Service Provider Console, the multi-tenant console that managed service providers use to run backups across all of their customers. The first lets an unauthenticated network peer claim a

vulnerability rce cloud
Bishop Fox