CNN
Ukraine racing to develop new interceptors as Russian drones and missiles ravage the country
Ukraine is urgently trying to develop interceptors capable of countering a new generation of Russian jet-powered drones that have wreaked havoc across the country in recent months.
🔍 Ukraine develops interceptor drones against jet-powered Gerans
Ukraine is expanding work on interceptor UAVs designed to counter newer Russian jet-powered Geran drones, CNN reports. The effort reflects a growing problem for conventional air defense, where faster targets and larger raid sizes can force defenders to commit expensive missiles, radar coverage, mobile groups, and fighter aircraft.
The wider implication is not limited to Ukraine. A large drone campaign does not need to defeat an air-defense network outright to create strategic pressure. It can force a defending country to spread limited assets between energy facilities, transport routes, airfields, command sites, and industrial infrastructure.
Myanmar offers one example of this risk. The country’s prolonged civil conflict has already shown how air power and attacks on civilian infrastructure can deepen displacement and disrupt essential services. The wider availability of long-range, low-cost strike UAVs could make such conflicts harder to contain and more dangerous for civilians.
🛰️ Open sources - closed narratives
@sitreports
Ukraine is expanding work on interceptor UAVs designed to counter newer Russian jet-powered Geran drones, CNN reports. The effort reflects a growing problem for conventional air defense, where faster targets and larger raid sizes can force defenders to commit expensive missiles, radar coverage, mobile groups, and fighter aircraft.
The wider implication is not limited to Ukraine. A large drone campaign does not need to defeat an air-defense network outright to create strategic pressure. It can force a defending country to spread limited assets between energy facilities, transport routes, airfields, command sites, and industrial infrastructure.
Myanmar offers one example of this risk. The country’s prolonged civil conflict has already shown how air power and attacks on civilian infrastructure can deepen displacement and disrupt essential services. The wider availability of long-range, low-cost strike UAVs could make such conflicts harder to contain and more dangerous for civilians.
🛰️ Open sources - closed narratives
@sitreports
📡 Navy starts carrier-based CCA prototype push
The U.S. Navy has issued an request for information for two autonomous carrier-capable Collaborative Combat Aircraft prototypes. NAVAIR wants systems able to operate from Ford- and Nimitz-class carriers, achieve first flight within two years of award, and complete shore-based carrier certification within three years. The target unit cost is $30 million, with compatibility required for catapult launch, arrested recovery, and the MD-5 control system.
The notice shows the Navy is skipping early concept work and asking for relatively mature air vehicles with a defined certification path. That compresses development risk into carrier suitability, autonomy integration, and weapons carriage while aligning naval CCA timelines more closely with parallel Air Force and Marine Corps efforts.
🛰️ Open sources - closed narratives
@sitreports
The U.S. Navy has issued an request for information for two autonomous carrier-capable Collaborative Combat Aircraft prototypes. NAVAIR wants systems able to operate from Ford- and Nimitz-class carriers, achieve first flight within two years of award, and complete shore-based carrier certification within three years. The target unit cost is $30 million, with compatibility required for catapult launch, arrested recovery, and the MD-5 control system.
The notice shows the Navy is skipping early concept work and asking for relatively mature air vehicles with a defined certification path. That compresses development risk into carrier suitability, autonomy integration, and weapons carriage while aligning naval CCA timelines more closely with parallel Air Force and Marine Corps efforts.
🛰️ Open sources - closed narratives
@sitreports
📡 Army moves TITAN into production with $192M award
The U.S. Army has issued $192 million in delivery orders for the TITAN program, marking its shift from prototyping to production. Palantir received $127 million and Anduril $65 million for eight additional systems over 18 months: four advanced and four basic variants. The Army says 10 prototypes have already been delivered across medium tactical trucks, JLTVs, and two ISV-U platforms.
The award formalizes TITAN as a fielded AI-enabled targeting node for long-range fires, built to fuse geospatial and signals intelligence from multiple sensors into target recommendations. Recent testing also highlighted a push toward vehicle-agnostic deployment and integration into wider command-and-control data meshes rather than a single fixed platform.
🛰️ Open sources - closed narratives
@sitreports
The U.S. Army has issued $192 million in delivery orders for the TITAN program, marking its shift from prototyping to production. Palantir received $127 million and Anduril $65 million for eight additional systems over 18 months: four advanced and four basic variants. The Army says 10 prototypes have already been delivered across medium tactical trucks, JLTVs, and two ISV-U platforms.
The award formalizes TITAN as a fielded AI-enabled targeting node for long-range fires, built to fuse geospatial and signals intelligence from multiple sensors into target recommendations. Recent testing also highlighted a push toward vehicle-agnostic deployment and integration into wider command-and-control data meshes rather than a single fixed platform.
🛰️ Open sources - closed narratives
@sitreports
⚖️ Judge Finds DOD Retaliation Against Anthropic Unlawful
A federal judge ruled that the Department of Defense unlawfully retaliated against Anthropic by labeling the company a “supply chain risk” after it refused to allow its AI tools to be used for mass surveillance of U.S. persons. The court held the designation violated the First Amendment; the court’s decision leaves broader questions about whether such product-use restrictions are protected speech unresolved.
The ruling narrows the government’s room to use procurement and security designations as punishment for protected corporate speech. It does not resolve the larger policy gap: federal privacy safeguards still depend heavily on private firms setting their own limits.
🛰️ Open sources - closed narratives
@sitreports
A federal judge ruled that the Department of Defense unlawfully retaliated against Anthropic by labeling the company a “supply chain risk” after it refused to allow its AI tools to be used for mass surveillance of U.S. persons. The court held the designation violated the First Amendment; the court’s decision leaves broader questions about whether such product-use restrictions are protected speech unresolved.
The ruling narrows the government’s room to use procurement and security designations as punishment for protected corporate speech. It does not resolve the larger policy gap: federal privacy safeguards still depend heavily on private firms setting their own limits.
🛰️ Open sources - closed narratives
@sitreports
🔍 Malicious Virtualizor update delivered via BGP hijack
Softaculous says attackers hijacked BGP routes for part of its Hetzner-hosted infrastructure between 20:57 UTC on August 28 and 06:10 UTC on August 30, diverting traffic for Virtualizor updates and the client portal. A small number of installations received a malicious package during the window, and admins are being told to check for java-jre-update.service, rotate API credentials, and audit SSH keys, accounts, tasks, and outbound connections.
The incident shows how route hijacking can bypass normal trust in update channels without directly breaching the vendor. Softaculous says routing was restored, a fraudulent certificate was reported for revocation, and version 3.2.9.9 now includes a Security Analyzer.
🛰️ Open sources - closed narratives
@sitreports
Softaculous says attackers hijacked BGP routes for part of its Hetzner-hosted infrastructure between 20:57 UTC on August 28 and 06:10 UTC on August 30, diverting traffic for Virtualizor updates and the client portal. A small number of installations received a malicious package during the window, and admins are being told to check for java-jre-update.service, rotate API credentials, and audit SSH keys, accounts, tasks, and outbound connections.
The incident shows how route hijacking can bypass normal trust in update channels without directly breaching the vendor. Softaculous says routing was restored, a fraudulent certificate was reported for revocation, and version 3.2.9.9 now includes a Security Analyzer.
🛰️ Open sources - closed narratives
@sitreports
🔍 Attackers move on critical JFrog Artifactory flaw within days
Active exploitation has been observed against a critical JFrog Artifactory vulnerability disclosed only days earlier, with intruders using it to mint administrator tokens and gain privileged access. The issue affects a platform widely used to host and manage software packages across development and CI/CD environments, as detailed in JFrog Artifactory reporting.
The operational significance is direct: token minting bypasses normal trust boundaries and can hand attackers durable control over artifact repositories, pipelines, and downstream software delivery. Fast weaponization after disclosure also underlines how quickly exposed supply chain infrastructure becomes a high-priority target.
🛰️ Open sources - closed narratives
@sitreports
Active exploitation has been observed against a critical JFrog Artifactory vulnerability disclosed only days earlier, with intruders using it to mint administrator tokens and gain privileged access. The issue affects a platform widely used to host and manage software packages across development and CI/CD environments, as detailed in JFrog Artifactory reporting.
The operational significance is direct: token minting bypasses normal trust boundaries and can hand attackers durable control over artifact repositories, pipelines, and downstream software delivery. Fast weaponization after disclosure also underlines how quickly exposed supply chain infrastructure becomes a high-priority target.
🛰️ Open sources - closed narratives
@sitreports
🔍 Critical Langflow flaw used to harvest AI and cloud secrets
Attackers are actively exploiting CVE-2026-0768, an unauthenticated RCE in Langflow’s custom component validator affecting versions 1.4.2 and earlier. VulnCheck observed at least 360 attacks after an initial 50 over the weekend, with requests targeting environment variables, Langflow superuser keys, OpenAI API keys, AWS credentials, SSH access, and shell history.
The activity shows direct credential-theft objectives rather than simple disruption. For exposed Langflow instances, compromise can extend beyond the app layer into cloud access, model billing abuse, and persistence through recovered secrets. Langflow 1.11.6 is presented as the patched release.
🛰️ Open sources - closed narratives
@sitreports
Attackers are actively exploiting CVE-2026-0768, an unauthenticated RCE in Langflow’s custom component validator affecting versions 1.4.2 and earlier. VulnCheck observed at least 360 attacks after an initial 50 over the weekend, with requests targeting environment variables, Langflow superuser keys, OpenAI API keys, AWS credentials, SSH access, and shell history.
The activity shows direct credential-theft objectives rather than simple disruption. For exposed Langflow instances, compromise can extend beyond the app layer into cloud access, model billing abuse, and persistence through recovered secrets. Langflow 1.11.6 is presented as the patched release.
🛰️ Open sources - closed narratives
@sitreports
🔍 Nearly 22,000 Exchange servers still exposed to mailbox takeover flaw
Shadowserver identified 21,899 internet-exposed Microsoft Exchange servers still unpatched for CVE-2026-62911, an authentication bypass affecting Exchange 2016, 2019, and Subscription Edition. Microsoft patched the flaw in August 2026; exploit code is already reported online. The bug can let an authorized attacker seize all user mailboxes, read mail, send messages, and pull attachments.
The exposure is notable because affected on-prem Exchange versions are already in extended support, narrowing the patching window and leaving externally reachable mail infrastructure at elevated risk. With large concentrations in the US and Germany, the issue remains a broad enterprise attack surface rather than an isolated lag in update adoption.
🛰️ Open sources - closed narratives
@sitreports
Shadowserver identified 21,899 internet-exposed Microsoft Exchange servers still unpatched for CVE-2026-62911, an authentication bypass affecting Exchange 2016, 2019, and Subscription Edition. Microsoft patched the flaw in August 2026; exploit code is already reported online. The bug can let an authorized attacker seize all user mailboxes, read mail, send messages, and pull attachments.
The exposure is notable because affected on-prem Exchange versions are already in extended support, narrowing the patching window and leaving externally reachable mail infrastructure at elevated risk. With large concentrations in the US and Germany, the issue remains a broad enterprise attack surface rather than an isolated lag in update adoption.
🛰️ Open sources - closed narratives
@sitreports
🎭 Iranian operators used fake recruiter personas to deliver cross-platform RATs
Researchers detailed an Iranian social-engineering campaign targeting developers with bogus job outreach and coding tests. The lures delivered remote access trojans for multiple operating systems, using interview-style tasking to move malware into a trusted workflow. The reported chain is outlined in coding tests sent to prospective targets.
The tradecraft blends HR pretexting with developer tooling, reducing suspicion and widening target access across Windows, macOS, and Linux environments. For defenders, the key signal is execution of unsolicited assessment code during recruitment rather than the payload family alone.
🛰️ Open sources - closed narratives
@sitreports
Researchers detailed an Iranian social-engineering campaign targeting developers with bogus job outreach and coding tests. The lures delivered remote access trojans for multiple operating systems, using interview-style tasking to move malware into a trusted workflow. The reported chain is outlined in coding tests sent to prospective targets.
The tradecraft blends HR pretexting with developer tooling, reducing suspicion and widening target access across Windows, macOS, and Linux environments. For defenders, the key signal is execution of unsolicited assessment code during recruitment rather than the payload family alone.
🛰️ Open sources - closed narratives
@sitreports
📡 Russian cybercrime operation being dismantled after two decades
US officials and CrowdStrike say a long-running Russian cybercrime operation known as Sality is being dismantled after roughly 20 years of activity. The case points to coordinated action between law enforcement and private-sector cybersecurity tracking.
For OSINT watchers, the significance lies in disruption of an entrenched criminal network rather than a routine takedown claim. A two-decade lifespan indicates durable infrastructure, broad victim exposure, and sustained adaptation, making any verified rollback operationally notable.
🛰️ Open sources - closed narratives
@sitreports
US officials and CrowdStrike say a long-running Russian cybercrime operation known as Sality is being dismantled after roughly 20 years of activity. The case points to coordinated action between law enforcement and private-sector cybersecurity tracking.
For OSINT watchers, the significance lies in disruption of an entrenched criminal network rather than a routine takedown claim. A two-decade lifespan indicates durable infrastructure, broad victim exposure, and sustained adaptation, making any verified rollback operationally notable.
🛰️ Open sources - closed narratives
@sitreports
🔍 13 Packagist packages used iPhone-targeting chain to steal wallet seeds
A set of 13 malicious PHP packages on Packagist was identified delivering code aimed at unpatched iPhones and harvesting cryptocurrency wallet seed phrases. The campaign linked software supply chain abuse with mobile device exploitation, using developer package repositories as the initial access vector.
The case highlights cross-platform threat design: compromise begins in the development ecosystem, then pivots to end-user devices holding high-value crypto assets. It also reinforces the exposure created by delayed iPhone patching, where a repository-level infection can translate into direct wallet credential theft.
🛰️ Open sources - closed narratives
@sitreports
A set of 13 malicious PHP packages on Packagist was identified delivering code aimed at unpatched iPhones and harvesting cryptocurrency wallet seed phrases. The campaign linked software supply chain abuse with mobile device exploitation, using developer package repositories as the initial access vector.
The case highlights cross-platform threat design: compromise begins in the development ecosystem, then pivots to end-user devices holding high-value crypto assets. It also reinforces the exposure created by delayed iPhone patching, where a repository-level infection can translate into direct wallet credential theft.
🛰️ Open sources - closed narratives
@sitreports
🤖 OpenAI flags Astra at critical cyber risk level
OpenAI says Astra is its first model to reach the company’s “Critical” cybersecurity threshold, with autonomous zero-day discovery and exploit development across hardened systems. The model reportedly scored 100% on ExploitBench, found two previously unknown flaws during testing, and built full attack chains including browser-to-host compromise and privilege escalation to root.
The significance is not branding but capability: OpenAI’s own framework places Astra beyond assisted exploitation into end-to-end offensive autonomy. The company says release was delayed, safeguards tightened, and access restricted to a small alpha group, indicating internal concern over operational misuse.
🛰️ Open sources - closed narratives
@sitreports
OpenAI says Astra is its first model to reach the company’s “Critical” cybersecurity threshold, with autonomous zero-day discovery and exploit development across hardened systems. The model reportedly scored 100% on ExploitBench, found two previously unknown flaws during testing, and built full attack chains including browser-to-host compromise and privilege escalation to root.
The significance is not branding but capability: OpenAI’s own framework places Astra beyond assisted exploitation into end-to-end offensive autonomy. The company says release was delayed, safeguards tightened, and access restricted to a small alpha group, indicating internal concern over operational misuse.
🛰️ Open sources - closed narratives
@sitreports
🤖 Google, Anthropic, and OpenAI roll out cyber AI programs
Google, Anthropic, and OpenAI have unveiled new cyber-focused AI models, safeguard frameworks, and access programs aimed at security use cases. The measures package model capabilities with controlled access and defensive guardrails, signaling a coordinated push to position frontier AI systems inside cybersecurity workflows. Details were outlined in the rollout published on 2 September.
The move matters because it pairs capability expansion with explicit governance at the point of deployment. For defenders, that means faster institutional uptake of AI-assisted cyber tooling; for OSINT tracking, it marks a clearer baseline for how major vendors are framing safety, access control, and intended operational boundaries.
🛰️ Open sources - closed narratives
@sitreports
Google, Anthropic, and OpenAI have unveiled new cyber-focused AI models, safeguard frameworks, and access programs aimed at security use cases. The measures package model capabilities with controlled access and defensive guardrails, signaling a coordinated push to position frontier AI systems inside cybersecurity workflows. Details were outlined in the rollout published on 2 September.
The move matters because it pairs capability expansion with explicit governance at the point of deployment. For defenders, that means faster institutional uptake of AI-assisted cyber tooling; for OSINT tracking, it marks a clearer baseline for how major vendors are framing safety, access control, and intended operational boundaries.
🛰️ Open sources - closed narratives
@sitreports
🤖 Claude Mythos tops AI cyber weapon test
Booz Allen’s Cyber Weapon Index evaluated 18 US and Chinese models under identical conditions for autonomous vulnerability discovery and end-to-end intrusion. Claude Mythos was the only model to complete the full cyber kill chain without human assistance, including full domain compromise with and without stolen credentials. Grok-4.5, Muse Spark 1.1, and GLM-5.2 reached full domain access and control.
The main signal is less the leaderboard than the narrowing gap: all but one model gained initial network access, and Booz Allen assesses mainstream AI-enabled attacks as imminent. The report also found attack harnesses can sharply amplify weaker models, making tooling and orchestration as critical as the base model itself.
🛰️ Open sources - closed narratives
@sitreports
Booz Allen’s Cyber Weapon Index evaluated 18 US and Chinese models under identical conditions for autonomous vulnerability discovery and end-to-end intrusion. Claude Mythos was the only model to complete the full cyber kill chain without human assistance, including full domain compromise with and without stolen credentials. Grok-4.5, Muse Spark 1.1, and GLM-5.2 reached full domain access and control.
The main signal is less the leaderboard than the narrowing gap: all but one model gained initial network access, and Booz Allen assesses mainstream AI-enabled attacks as imminent. The report also found attack harnesses can sharply amplify weaker models, making tooling and orchestration as critical as the base model itself.
🛰️ Open sources - closed narratives
@sitreports
📡 BGP hijack used to push malicious Virtualizor update
A newly detailed supply-chain incident used a BGP hijack to redirect traffic and deliver a trojanized Virtualizor update. The tampered package reportedly established persistent root access on affected systems, turning a routine software update path into the initial intrusion vector.
The case highlights how network-layer interference can be paired with trusted update mechanisms to bypass normal admin expectations. For defenders, the key issue is not only package integrity but also route security, update validation, and post-install monitoring for persistence at root level.
🛰️ Open sources - closed narratives
@sitreports
A newly detailed supply-chain incident used a BGP hijack to redirect traffic and deliver a trojanized Virtualizor update. The tampered package reportedly established persistent root access on affected systems, turning a routine software update path into the initial intrusion vector.
The case highlights how network-layer interference can be paired with trusted update mechanisms to bypass normal admin expectations. For defenders, the key issue is not only package integrity but also route security, update validation, and post-install monitoring for persistence at root level.
🛰️ Open sources - closed narratives
@sitreports
🔍 JFrog Artifactory flaw exploited to mint admin tokens
CVE-2026-82329, a critical authentication bypass in the default configuration of self-managed JFrog Artifactory, is being exploited to forge administrative access tokens. watchTowr observed attackers creating their own admin tokens, while JFrog Artifactory patched the issue on 28 August across multiple 7.x releases. JFrog Cloud is stated to have been protected.
The access path matters more than the initial bug: admin tokens can survive a binary upgrade and provide direct control over artifacts, users, groups, and security settings. In environments where build and deployment systems automatically trust Artifactory content, that creates a supply-chain exposure with immediate downstream risk.
🛰️ Open sources - closed narratives
@sitreports
CVE-2026-82329, a critical authentication bypass in the default configuration of self-managed JFrog Artifactory, is being exploited to forge administrative access tokens. watchTowr observed attackers creating their own admin tokens, while JFrog Artifactory patched the issue on 28 August across multiple 7.x releases. JFrog Cloud is stated to have been protected.
The access path matters more than the initial bug: admin tokens can survive a binary upgrade and provide direct control over artifacts, users, groups, and security settings. In environments where build and deployment systems automatically trust Artifactory content, that creates a supply-chain exposure with immediate downstream risk.
🛰️ Open sources - closed narratives
@sitreports
🔍 SonicWall patches two exploited SMA 1000 zero-days
SonicWall released hotfixes for two actively exploited SMA 1000 VPN flaws: CVE-2026-83548, a pre-auth SSRF (CVSS 10.0), and CVE-2026-83549, a post-auth command injection bug (CVSS 7.8). The company said attackers may chain them for arbitrary command execution. Affected versions include 12.4.3-03453 and earlier, and 12.5.0-02835 and earlier; fixes are in the SMA 1000 advisory.
This is a high-priority edge-device patch. SonicWall also recommends compromise checks, reimaging if needed, and credential resets.
🛰️ Open sources - closed narratives
@sitreports
SonicWall released hotfixes for two actively exploited SMA 1000 VPN flaws: CVE-2026-83548, a pre-auth SSRF (CVSS 10.0), and CVE-2026-83549, a post-auth command injection bug (CVSS 7.8). The company said attackers may chain them for arbitrary command execution. Affected versions include 12.4.3-03453 and earlier, and 12.5.0-02835 and earlier; fixes are in the SMA 1000 advisory.
This is a high-priority edge-device patch. SonicWall also recommends compromise checks, reimaging if needed, and credential resets.
🛰️ Open sources - closed narratives
@sitreports
🔍 Malicious .git configs can trigger code execution in AI coding agents
A newly disclosed issue shows that crafted Git repository configuration can cause AI coding tools including Claude, Codex, and Cursor to execute attacker-controlled code during normal repository interaction. The exposed attack surface centers on repository-level .git configs, turning trusted development workflows into an execution path.
Operationally, this shifts risk from prompt abuse to supply-chain level repository handling. Any agent that reads, initializes, or acts on local Git context may inherit hostile behavior before a user reviews code, making repo provenance and config inspection a primary defensive control.
🛰️ Open sources - closed narratives
@sitreports
A newly disclosed issue shows that crafted Git repository configuration can cause AI coding tools including Claude, Codex, and Cursor to execute attacker-controlled code during normal repository interaction. The exposed attack surface centers on repository-level .git configs, turning trusted development workflows into an execution path.
Operationally, this shifts risk from prompt abuse to supply-chain level repository handling. Any agent that reads, initializes, or acts on local Git context may inherit hostile behavior before a user reviews code, making repo provenance and config inspection a primary defensive control.
🛰️ Open sources - closed narratives
@sitreports
🔍 Linux rootkit targets Elastic trusted_pids path
Research on the Singularity Linux rootkit shows a loader can abuse Elastic Defend’s trusted_pids eBPF map to suppress module_load telemetry during malicious kernel module insertion. Testing cited Elastic Defend 9.5.2 on Ubuntu 6.8.0-138, where the BPF program exits early if the loading process is marked trusted, preventing module metadata collection and event creation.
The significance is narrow but serious: the technique does not disable the agent, it blinds one kernel-module detection path. It highlights how trusted-process logic and eBPF map integrity become critical inspection points, especially when taint-based analytics depend on telemetry generated inside the same kernel space an attacker already controls.
🛰️ Open sources - closed narratives
@sitreports
Research on the Singularity Linux rootkit shows a loader can abuse Elastic Defend’s trusted_pids eBPF map to suppress module_load telemetry during malicious kernel module insertion. Testing cited Elastic Defend 9.5.2 on Ubuntu 6.8.0-138, where the BPF program exits early if the loading process is marked trusted, preventing module metadata collection and event creation.
The significance is narrow but serious: the technique does not disable the agent, it blinds one kernel-module detection path. It highlights how trusted-process logic and eBPF map integrity become critical inspection points, especially when taint-based analytics depend on telemetry generated inside the same kernel space an attacker already controls.
🛰️ Open sources - closed narratives
@sitreports
🔍 More than a dozen Serbians targeted with mercenary spyware, digital rights group finds
At least 14 people in Serbia’s civil society were targeted with advanced spyware ahead of local elections in March, the SHARE Foundation said. The headline points to a coordinated digital intrusion campaign aimed at non-state actors in a politically sensitive period.
Operationally, this places commercial surveillance tools back at the center of election-period security monitoring. Targeting civil society with mercenary spyware indicates both access to sophisticated intrusion capability and an interest in intelligence collection beyond formal state institutions.
🛰️ Open sources - closed narratives
@sitreports
At least 14 people in Serbia’s civil society were targeted with advanced spyware ahead of local elections in March, the SHARE Foundation said. The headline points to a coordinated digital intrusion campaign aimed at non-state actors in a politically sensitive period.
Operationally, this places commercial surveillance tools back at the center of election-period security monitoring. Targeting civil society with mercenary spyware indicates both access to sophisticated intrusion capability and an interest in intelligence collection beyond formal state institutions.
🛰️ Open sources - closed narratives
@sitreports
🔍 Sangoma Switchvox flaw hit in active RCE exploitation
Attackers are exploiting CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox that enables remote code execution via the /pa endpoint. Horizon3 observed rapid attacks from 176.65.148.184 on August 30, including reverse shell deployment, process enumeration, and base64-encoded data exfiltration. Sangoma patched the issue in Switchvox 8.4.0.2 on July 14.
This is a direct edge-service compromise path against internet-exposed enterprise VoIP infrastructure. With roughly 4,000 exposed devices cited and signs of compromise logged in db-quirks.log plus outbound traffic on port 39323, unpatched systems should be treated as high-priority incident response cases.
🛰️ Open sources - closed narratives
@sitreports
Attackers are exploiting CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox that enables remote code execution via the /pa endpoint. Horizon3 observed rapid attacks from 176.65.148.184 on August 30, including reverse shell deployment, process enumeration, and base64-encoded data exfiltration. Sangoma patched the issue in Switchvox 8.4.0.2 on July 14.
This is a direct edge-service compromise path against internet-exposed enterprise VoIP infrastructure. With roughly 4,000 exposed devices cited and signs of compromise logged in db-quirks.log plus outbound traffic on port 39323, unpatched systems should be treated as high-priority incident response cases.
🛰️ Open sources - closed narratives
@sitreports