#exploitation
9 articles
APT28 (Fancy Bear) and StrikeShark were the most frequently cited threat actors across ten articles published between April and June 2026, with high-severity exploits dominating the coverage. Critical vulnerabilities CVE-2026-42208 and CVE-2026-21643, alongside CVE-2026-34197, CVE-2021-26855, and CVE-2022-40684, were linked to attacks against government, defense, diplomatic, enterprise software, and software development sectors. Affected regions included Global, Colombia, Hong Kong, Indonesia, and Lebanon, with seven high-severity and two critical incidents noted.
HIGHStrikeShark Campaign Delivers Cobalt Strike Via SharkLoader Loader
Kaspersky uncovers StrikeShark, a global campaign using SharkLoader malware to deploy Cobalt Strike Beacon across 10+ countries via exploits for ProxyLogon, Openfire, and...
CRITICALLiteLLM CVE-2026-42208 Pre-Auth SQLi Exploited in Attacks
Attackers exploit CVE-2026-42208, a critical pre-authentication SQL injection in LiteLLM LLM gateway, to steal API keys and model data. CVSS 9.8. No patch yet.
HIGHAI-Powered Vulnerability Discovery Accelerates Exploit Timelines, Strains
Qualys warns that AI agents like Claude Mythos can cut vulnerability discovery time from months to hours, compressing the patch window and overwhelming security teams with a surge of new CVEs.
HIGHApache ActiveMQ Vulnerability Exploited, Added to CISA KEV Catalog
A high-severity flaw in Apache ActiveMQ Classic, CVE-2026-34197 (CVSS 8.8), is under active exploitation, prompting CISA to add it to its Known Exploited Vulnerabilities catalog and mandate patching for federal agencies.
HIGHCISA Flags Six Actively Exploited Flaws in Fortinet, Microsoft, Adobe
CISA added six vulnerabilities in Fortinet, Microsoft, and Adobe software to its Known Exploited Vulnerabilities catalog, warning of active in-the-wild attacks requiring urgent patching.
CRITICALAdobe Patches Acrobat Zero-Day Exploited via Malicious PDFs for Months
Adobe patches CVE-2024-34102, a critical zero-day vulnerability in Acrobat and Reader exploited via malicious PDFs for at least four months prior to discovery.
HIGHFancy Bear APT Exploits Unpatched Flaws in Global Espionage Campaign
Russia's APT28 (Fancy Bear) is conducting a global cyber espionage campaign, exploiting unpatched vulnerabilities in routers and network devices to infiltrate government and defense targets.
HIGHSANS Stormcast: Exploits Target Ivanti, Fortinet, and VMware Flaws
The SANS Internet Storm Center reports active exploitation of vulnerabilities in Ivanti, Fortinet, and VMware products, alongside a new phishing campaign using malicious OneNote attachments.
INFORMATIONALMetasploit Framework Expands with Cisco, osTicket Exploits and LDAP Enhancements
The latest Metasploit Framework release introduces exploit modules for Cisco Catalyst SD-WAN and osTicket, alongside significant improvements to LDAP/ADCS data collection and Windows persistence techniques.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.