#exploitation
10 articles
APT28 (Fancy Bear) and StrikeShark were the most frequently cited threat actors across 11 articles published between April and August 2026, with exploitation activity spanning government, defense, diplomatic, enterprise software, and research sectors. Key vulnerabilities included CVE-2023-49105, CVE-2026-42208, both rated 9.8, alongside CVE-2026-21643, CVE-2026-34197, and CVE-2021-26855. Coverage documented three critical and seven high-severity incidents, affecting regions including Colombia, Hong Kong, Indonesia, Lebanon, and globally, with one informational report.
CRITICALCVE-2023-49105: ownCloud Flaw Exploited to Steal Nuclear Research Data
CVE-2023-49105 (CVSS 9.8) added to CISA KEV after Chinese-speaking actor exploited it to steal nuclear research records from a Philippine agency. Patch now.
HIGHStrikeShark Campaign Delivers Cobalt Strike Via SharkLoader Loader
Kaspersky uncovers StrikeShark, a global campaign using SharkLoader malware to deploy Cobalt Strike Beacon across 10+ countries via exploits for ProxyLogon, Openfire, and...
CRITICALLiteLLM CVE-2026-42208 Pre-Auth SQLi Exploited in Attacks
Attackers exploit CVE-2026-42208, a critical pre-authentication SQL injection in LiteLLM LLM gateway, to steal API keys and model data. CVSS 9.8. No patch yet.
HIGHAI-Powered Vulnerability Discovery Accelerates Exploit Timelines, Strains
Qualys warns that AI agents like Claude Mythos can cut vulnerability discovery time from months to hours, compressing the patch window and overwhelming security teams with a surge of new CVEs.
HIGHApache ActiveMQ Vulnerability Exploited, Added to CISA KEV Catalog
A high-severity flaw in Apache ActiveMQ Classic, CVE-2026-34197 (CVSS 8.8), is under active exploitation, prompting CISA to add it to its Known Exploited Vulnerabilities catalog and mandate patching for federal agencies.
HIGHCISA Flags Six Actively Exploited Flaws in Fortinet, Microsoft, Adobe
CISA added six vulnerabilities in Fortinet, Microsoft, and Adobe software to its Known Exploited Vulnerabilities catalog, warning of active in-the-wild attacks requiring urgent patching.
CRITICALAdobe Patches Acrobat Zero-Day Exploited via Malicious PDFs for Months
Adobe patches CVE-2024-34102, a critical zero-day vulnerability in Acrobat and Reader exploited via malicious PDFs for at least four months prior to discovery.
HIGHFancy Bear APT Exploits Unpatched Flaws in Global Espionage Campaign
Russia's APT28 (Fancy Bear) is conducting a global cyber espionage campaign, exploiting unpatched vulnerabilities in routers and network devices to infiltrate government and defense targets.
HIGHSANS Stormcast: Exploits Target Ivanti, Fortinet, and VMware Flaws
The SANS Internet Storm Center reports active exploitation of vulnerabilities in Ivanti, Fortinet, and VMware products, alongside a new phishing campaign using malicious OneNote attachments.
INFORMATIONALMetasploit Framework Expands with Cisco, osTicket Exploits and LDAP Enhancements
The latest Metasploit Framework release introduces exploit modules for Cisco Catalyst SD-WAN and osTicket, alongside significant improvements to LDAP/ADCS data collection and Windows persistence techniques.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.