7 critical threats detected in the last 24 hours. Active threat actors: Midnight Blizzard, Conti, LockBit. Immediate review of affected systems recommended.
Critical
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
NVD CRITICAL: CVE-2026-69085 — SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree...
NVD CRITICAL: CVE-2026-69084 — SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, whic...
NVD CRITICAL: CVE-2026-69083 — SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullT...
NVD CRITICAL: CVE-2026-64827 — Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x...
NVD CRITICAL: CVE-2026-18601 — A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun...
CFTC fines UBS $8 million for AML failures
The Commodity Futures Trading Commission today announced an order filing and settling charges against UBS Financial Services Inc., a registered futures commission merchant, for failing to diligently supervise the configuration and operation of its anti-money laundering transaction monitoring systems for wire transfers denominated in foreign currencies (FX).
Mastercard closes acquisition of BVNK
Mastercard (NYSE: MA) today completed its acquisition of BVNK, expanding the company’s strategy to support greater choice in how people and businesses exchange value by enabling interoperability across fiat and digital currencies.
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
Inside the Underground Business of BTMOB RAT
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
Infinios goes live with Mastercard on stablecoin settlement
INFINIOS, the Bahrain‑based digital financial infrastructure company, today announced that it is officially live with Mastercard on stablecoin settlement, marking a major milestone in the evolution of regulated digital payments in the Middle East.
NVD CRITICAL: CVE-2026-69085 — SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree...
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter binding. The endpoint is reachable by a publish RoleReader token, or unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. Because the statement exec
NVD CRITICAL: CVE-2026-69084 — SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, whic...
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin restrictions. The endpoint is gated only by CheckAuth, making it reachable by the publish RoleReader token and by anonymous users when publish authentication is disabled. Because the u
NVD CRITICAL: CVE-2026-69083 — SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullT...
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the read-write asset-content database via unescaped method parameters and REGEXP clauses to read, modify, or delete cross-notebook data.
NVD CRITICAL: CVE-2026-64827 — Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x...
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP s
NVD CRITICAL: CVE-2026-18601 — A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the fun...
A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from
Is There Really a Fix for CISO Fatigue?
Accountability without any real authority is driving CISO burnout, and organizations need to take notice.
Live Activity
Threat Alerts
Real-time alerts for the threats that matter to you. Choose your severity levels and threat categories.