Asutorufaのブログ

こんにちは

Threat Intelligence

Threat Intelligence

Daily security intelligence collected from public sources.

Latest

Threat Intelligence Daily · 2026-09-20

ConoHa WING disclosed unauthorized access to customer web-server areas affecting 426 accounts. Checkmarx documented an npm malware campaign that moves execution from install scripts into normal library runtime, while working exploits are now public for four patched Linux kernel local-root flaws.

Critical0High3Medium0Low0Exploited23 threats

Threat Intelligence Daily · 2026-09-20

ConoHa WING disclosed unauthorized access to customer web-server areas affecting 426 accounts. Checkmarx documented an npm malware campaign that moves execution from install scripts into normal library runtime, while working exploits are now public for four patched Linux kernel local-root flaws.

Critical0High3Medium0Low0Exploited23 threats

Threat Intelligence Daily · 2026-09-19

CISA added three actively exploited Linux kernel flaws to KEV with a September 21 remediation target. WordPress 7.1.1 fixes a crafted-URL theme-install path later demonstrated as Click2Shell, Chrome 153 fixes critical Dawn and WebGL memory-safety bugs, and vm2 3.11.7 closes multiple sandbox-boundary failures including host-process RCE and TLS trust-store manipulation.

Critical3High1Medium0Low0Exploited14 threats

Threat Intelligence Daily · 2026-09-18

Japan and international partners attributed the WaterPlum fake-recruitment campaign to North Korea and documented more than 30,000 infected devices. AIR disclosed Plugin4Shell across major AI coding agents, Check Point patched an unauthenticated root RCE in management servers, Microsoft disclosed a server-side-mitigated Azure AI Foundry flaw rated CVSS 10.0, and Zscaler detailed APT36's RapidRust espionage tooling.

Critical2High3Medium0Low0Exploited25 threats

Threat Intelligence Daily · 2026-09-17

Cisco disclosed an actively exploited, unauthenticated ISE authentication bypass with a CVSS score of 10.0. ESET documented FamousSparrow's new SparroWocky backdoor against Latin American governments, while CrowdStrike described PhantomRaven malware distributed through npm. Malwarebytes also tracked a large T-Mobile-themed SMS phishing campaign, and JVN published a fixed hard-coded-key flaw in Tohoku Electric Power's Yorisou e Net app.

Critical1High2Medium1Low1Exploited35 threats

Threat Intelligence Daily · 2026-09-16

Google's September Pixel bulletin confirms limited targeted exploitation of CVE-2026-58704. UK, US and Dutch agencies published technical details for Iran-linked CHOSEN BRICK spyware, while Kaspersky documented NightEagle intrusions using stolen VPN credentials, GhostContainer, RDP tunneling and BlueKeep. OPSWAT also published details for two patched TP-Link Tapo C200 flaws requiring network access.

Critical0High4Medium0Low0Exploited34 threats

Threat Intelligence Daily · 2026-09-15

September 15 brought a high-confidence ransomware-prepositioning update around N-able N-central, fresh FreeRDP 3.31.0 security fixes, new JFrog analysis of 3,022 GemStuffer-linked RubyGems packages, and coordinated disclosure of the DDRop physical attack against confidential-computing memory integrity. Linux RPC/RDMA and SUNRPC fixes also warrant review where the affected transports are enabled.

Critical2High3Medium0Low0Exploited25 threats

Threat Intelligence Daily · 2026-09-14

The most urgent new threat on September 14 was Cisco Secure Email Gateway CVE-2026-76461: an unauthenticated remote attacker can trigger root-level command execution through a crafted email. Cisco confirmed active exploitation and CISA added it to KEV the same day. Other notable items include the Mathspace breach via Metabase CVE-2026-72898, follow-up on the IDScan.net identity-data incident, and new JVN disclosures affecting FLEXLAN, YAMAP and ExLlamaV3.

Critical1High3Medium2Low0Exploited26 threats

Threat Intelligence Daily · 2026-09-13

As of 2026-09-13, the most urgent threats center on actively exploited DevOps, remote-management and edge-device vulnerabilities, plus the BlueMoon browser/Windows zero-day chain rapidly adopted by multiple state-aligned clusters. CISA added five KEVs, PaperCut and GitLab saw real-world attack activity, while Check Point disclosed two critical VPN RCEs and the Brevo incident enabled targeted phishing against Trezor users.

Critical7High1Medium0Low0Exploited78 threats
©2026Asutorufa