๐ CISA flags actively exploited MikroTik RouterOS privilege-escalation flaw
CISA added CVE-2026-86060 to the KEV catalog on 10 September, with remediation due by 13 September. The flaw affects MikroTik RouterOS, is tied to improper neutralization of argument delimiters in a command, and can let an attacker alter the trusted policy mask to gain elevated privileges. CISA marked the case for forensic triage.
For defenders, this moves beyond routine patching. A successful compromise of edge routers can enable rule changes, traffic redirection, unauthorized account creation, VPN tampering, persistence, and suppression of security controls on infrastructure that often sits at key network choke points.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
CISA added CVE-2026-86060 to the KEV catalog on 10 September, with remediation due by 13 September. The flaw affects MikroTik RouterOS, is tied to improper neutralization of argument delimiters in a command, and can let an attacker alter the trusted policy mask to gain elevated privileges. CISA marked the case for forensic triage.
For defenders, this moves beyond routine patching. A successful compromise of edge routers can enable rule changes, traffic redirection, unauthorized account creation, VPN tampering, persistence, and suppression of security controls on infrastructure that often sits at key network choke points.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Chrome-Windows exploit chain used in targeted intrusions
Volexity says UTA0560 and JungleBamboo used an identical three-stage chain combining Chrome V8 bug CVE-2026-85046, WebAssembly escape CVE-2026-87491, and Windows kernel LPE CVE-2026-85880. The attacks began with phishing links abusing reflected XSS on legitimate sites, then delivered GRIMWEDGE or the browser-focused LONGTALE via SUPERSTOMP.
The notable point is the patch-gap: code changes existed upstream in Chromium, but not yet in released Chrome builds. The chain also fingerprinted hosts before kernel exploitation and reused byte-identical exploit components across operators, indicating shared tooling and a mature post-browser compromise workflow.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Volexity says UTA0560 and JungleBamboo used an identical three-stage chain combining Chrome V8 bug CVE-2026-85046, WebAssembly escape CVE-2026-87491, and Windows kernel LPE CVE-2026-85880. The attacks began with phishing links abusing reflected XSS on legitimate sites, then delivered GRIMWEDGE or the browser-focused LONGTALE via SUPERSTOMP.
The notable point is the patch-gap: code changes existed upstream in Chromium, but not yet in released Chrome builds. The chain also fingerprinted hosts before kernel exploitation and reused byte-identical exploit components across operators, indicating shared tooling and a mature post-browser compromise workflow.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Dutch NCSC warns Check Point VPN exploitation is imminent
The Dutch NCSC has flagged two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103, as likely to face near-term exploitation. The issues can enable remote code execution on Security Gateways, and in one case Security Management Servers. Affected branches include R81.20, R82, R82.10, R81.10.x and R82.00.x; R82.20 is not affected. Relevant NCSC advisory guidance urges immediate patching.
This is a high-priority edge-device exposure set: internet-facing VPN infrastructure, RCE impact, broad enterprise deployment, and an official warning issued before public exploit code appears. Defenders should treat unpatched gateways as a short-window risk and restrict Site-to-Site VPN access to trusted IPs where applicable.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
The Dutch NCSC has flagged two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103, as likely to face near-term exploitation. The issues can enable remote code execution on Security Gateways, and in one case Security Management Servers. Affected branches include R81.20, R82, R82.10, R81.10.x and R82.00.x; R82.20 is not affected. Relevant NCSC advisory guidance urges immediate patching.
This is a high-priority edge-device exposure set: internet-facing VPN infrastructure, RCE impact, broad enterprise deployment, and an official warning issued before public exploit code appears. Defenders should treat unpatched gateways as a short-window risk and restrict Site-to-Site VPN access to trusted IPs where applicable.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ก CISA expands KEV with 5 exploited flaws
CISA has added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. The update formally places the bugs into the U.S. federal remediation workflow.
The combination is notable: software repository infrastructure, remote administration tooling, and edge networking gear. KEV inclusion signals confirmed in-the-wild abuse and raises patch urgency across enterprise build pipelines, IT management stacks, and perimeter devices.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
CISA has added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. The update formally places the bugs into the U.S. federal remediation workflow.
The combination is notable: software repository infrastructure, remote administration tooling, and edge networking gear. KEV inclusion signals confirmed in-the-wild abuse and raises patch urgency across enterprise build pipelines, IT management stacks, and perimeter devices.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ค Claude agents move from assistance to attack orchestration
Anthropic says it disrupted malicious use of Claude between Dec. 2025 and Aug. 2026, spanning espionage, cybercrime, and hacktivist activity. The threat-intelligence findings describe AI agents automating reconnaissance, phishing, credential theft, malware retooling, cloud compromise, and data exfiltration, including GTG-20006 activity linked to targets in Ukraine and Europe.
The key shift is operational scale. AI agents are reducing the manpower and skill needed for complex intrusions while accelerating iteration, parallel targeting, and evasion. AI API keys, session tokens, and agent integrations are also emerging as attack surfaces and usable loot.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Anthropic says it disrupted malicious use of Claude between Dec. 2025 and Aug. 2026, spanning espionage, cybercrime, and hacktivist activity. The threat-intelligence findings describe AI agents automating reconnaissance, phishing, credential theft, malware retooling, cloud compromise, and data exfiltration, including GTG-20006 activity linked to targets in Ukraine and Europe.
The key shift is operational scale. AI agents are reducing the manpower and skill needed for complex intrusions while accelerating iteration, parallel targeting, and evasion. AI API keys, session tokens, and agent integrations are also emerging as attack surfaces and usable loot.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ OpenAI-linked agents tied to RubyGems intrusion
A new report links OpenAI agents to a RubyGems campaign that obtained remote code execution on RubyDoc servers. The incident centers on abuse within the Ruby package ecosystem and resulted in code execution against infrastructure supporting Ruby documentation services.
The case is significant because it connects AI-agent activity to a live software supply chain compromise with downstream infrastructure impact. RCE on RubyDoc moves the event beyond package tampering alone, showing how ecosystem trust paths can be leveraged into operational access on adjacent services.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
A new report links OpenAI agents to a RubyGems campaign that obtained remote code execution on RubyDoc servers. The incident centers on abuse within the Ruby package ecosystem and resulted in code execution against infrastructure supporting Ruby documentation services.
The case is significant because it connects AI-agent activity to a live software supply chain compromise with downstream infrastructure impact. RCE on RubyDoc moves the event beyond package tampering alone, showing how ecosystem trust paths can be leveraged into operational access on adjacent services.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ค Hackers Used Claude to Hunt for Secrets in 1.8 Million Android Apps
Threat actors reportedly used Claude to scan 1.8 million Android applications for embedded secrets, indicating AI-assisted review at very large scale. The headline points to automated discovery of exposed credentials, tokens, or other sensitive data inside mobile software.
Operationally, this reflects how AI can compress time and labor for code triage and secret hunting, turning app ecosystems into broad attack surfaces. At this scale, defenders face a faster reconnaissance cycle and a lower barrier for mass exploitation.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Threat actors reportedly used Claude to scan 1.8 million Android applications for embedded secrets, indicating AI-assisted review at very large scale. The headline points to automated discovery of exposed credentials, tokens, or other sensitive data inside mobile software.
Operationally, this reflects how AI can compress time and labor for code triage and secret hunting, turning app ecosystems into broad attack surfaces. At this scale, defenders face a faster reconnaissance cycle and a lower barrier for mass exploitation.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Revolut confirms sensitive customer data breach after fake government requests
Revolut says sensitive customer information was disclosed to an unauthorized third party after staff responded to fraudulent requests sent from a legitimate government agency email domain. The incident points to successful abuse of trusted official channels rather than a direct technical intrusion.
Operationally, the case highlights a persistent weak point in compliance and data-release workflows: trust in sender identity. For defenders, it underscores the need for independent verification of government and law-enforcement requests, even when they arrive through authentic domains.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Revolut says sensitive customer information was disclosed to an unauthorized third party after staff responded to fraudulent requests sent from a legitimate government agency email domain. The incident points to successful abuse of trusted official channels rather than a direct technical intrusion.
Operationally, the case highlights a persistent weak point in compliance and data-release workflows: trust in sender identity. For defenders, it underscores the need for independent verification of government and law-enforcement requests, even when they arrive through authentic domains.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ The blurred line between drone and missile
Ukraine's success against the old propeller Shaheds pushed Moscow toward what analyst Konrad Muzyka calls the "cruise-missilisation" of its drone fleet. The new Gerans fly at speeds and altitudes that erase the distinction between a loitering munition and a cruise missile, the Financial Times reports.
Muzyka expects the trend to continue. "Soon we will probably see these drones acquire stealth capabilities, which means producing, procuring and using them will become more expensive, but destroying them will also cost more." The new models are already harder and costlier to launch than their predecessors, while remaining far below the price of a Kalibr or Kh-101.
That is the mechanism worth watching. Each defensive success drives the attacker upmarket, and each upgrade shifts more of the financial burden onto the side doing the intercepting.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Ukraine's success against the old propeller Shaheds pushed Moscow toward what analyst Konrad Muzyka calls the "cruise-missilisation" of its drone fleet. The new Gerans fly at speeds and altitudes that erase the distinction between a loitering munition and a cruise missile, the Financial Times reports.
Muzyka expects the trend to continue. "Soon we will probably see these drones acquire stealth capabilities, which means producing, procuring and using them will become more expensive, but destroying them will also cost more." The new models are already harder and costlier to launch than their predecessors, while remaining far below the price of a Kalibr or Kh-101.
That is the mechanism worth watching. Each defensive success drives the attacker upmarket, and each upgrade shifts more of the financial burden onto the side doing the intercepting.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ค AI adoption is reshaping SOC workload
A new security operations report argues that enterprise-wide AI use changes the volume, speed, and character of security events reaching the SOC. As AI tools spread across business units, defenders face expanded monitoring demands tied to new workflows, identities, and attack surfaces.
Operationally, this shifts the SOC from guarding a defined perimeter to tracking fast-moving, distributed AI-enabled activity inside routine business processes. The core issue is not just more alerts, but reduced analyst visibility as organizational AI adoption outpaces established detection and response models.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
A new security operations report argues that enterprise-wide AI use changes the volume, speed, and character of security events reaching the SOC. As AI tools spread across business units, defenders face expanded monitoring demands tied to new workflows, identities, and attack surfaces.
Operationally, this shifts the SOC from guarding a defined perimeter to tracking fast-moving, distributed AI-enabled activity inside routine business processes. The core issue is not just more alerts, but reduced analyst visibility as organizational AI adoption outpaces established detection and response models.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Mshta.exe Used to Deliver HTA Malware in Spanish-Language Phishing
Researchers tracking an active campaign since June report phishing emails using invoice and judicial-notice lures to push malicious HTA files executed via mshta.exe. The chain uses shortened URLs, redirects to a delivery page, off-screen HTA execution, reconnaissance via WMI and PowerShell, then HTML smuggling to download a 7-Zip self-extracting payload disguised as a Firefox installer.
The operation combines a signed Windows binary, hidden execution, browser-side payload reconstruction, and frequently recompiled malware to reduce signature-based detection. Reported SCL:-1 handling on some phishing emails also points to a delivery-stage control gap before endpoint defenses engage.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Researchers tracking an active campaign since June report phishing emails using invoice and judicial-notice lures to push malicious HTA files executed via mshta.exe. The chain uses shortened URLs, redirects to a delivery page, off-screen HTA execution, reconnaissance via WMI and PowerShell, then HTML smuggling to download a 7-Zip self-extracting payload disguised as a Firefox installer.
The operation combines a signed Windows binary, hidden execution, browser-side payload reconstruction, and frequently recompiled malware to reduce signature-based detection. Reported SCL:-1 handling on some phishing emails also points to a delivery-stage control gap before endpoint defenses engage.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
๐ Hidden crypto farm in Mexican mountains puts spotlight on cartel funding
A clandestine cryptocurrency mining site discovered in central Mexico is drawing attention to how criminal groups may use remote infrastructure and low-visibility locations to generate revenue. The reported crypto farm was concealed in mountainous terrain, away from regular traffic and public scrutiny.
Operationally, the case highlights a financing model that blends illicit territorial control with energy-intensive digital activity. For OSINT tracking, it underscores the value of monitoring isolated industrial signatures, power anomalies, and logistics footprints linked to nontraditional cartel income streams.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
A clandestine cryptocurrency mining site discovered in central Mexico is drawing attention to how criminal groups may use remote infrastructure and low-visibility locations to generate revenue. The reported crypto farm was concealed in mountainous terrain, away from regular traffic and public scrutiny.
Operationally, the case highlights a financing model that blends illicit territorial control with energy-intensive digital activity. For OSINT tracking, it underscores the value of monitoring isolated industrial signatures, power anomalies, and logistics footprints linked to nontraditional cartel income streams.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
Forwarded from DD Geopolitics
๐ฎ๐ท๐ธ ๐ท๐บ IRAN ASKS RUSSIA FOR ITS ADVANCED GERAN DRONES, TECHNOLOGY TRANSFER COMES FULL CIRCLE
Iran has asked Moscow to supply its newest Russian-developed Geran attack drones for use against Israel and the United States, according to the Financial Times, citing Western security officials and a person close to the Kremlin. It remains unclear whether Russia has agreed to the latest request.
Iran originally supplied Russia with the Shahed technology. Russia then spent four years combat-testing, modifying and mass-producing the platform in Ukraine and Tehran now reportedly wants Russiaโs evolved versions back.
The latest jet-powered Geran variants are faster, carry larger warheads and incorporate improved targeting, communications and resistance to electronic warfare. Russiaโs adaptation of the Iranian design has become so extensive that CSIS recently concluded that Russia has effectively mastered the platform through continuous battlefield-driven development.
๐ด @DDGeopolitics
Iran has asked Moscow to supply its newest Russian-developed Geran attack drones for use against Israel and the United States, according to the Financial Times, citing Western security officials and a person close to the Kremlin. It remains unclear whether Russia has agreed to the latest request.
Iran originally supplied Russia with the Shahed technology. Russia then spent four years combat-testing, modifying and mass-producing the platform in Ukraine and Tehran now reportedly wants Russiaโs evolved versions back.
The latest jet-powered Geran variants are faster, carry larger warheads and incorporate improved targeting, communications and resistance to electronic warfare. Russiaโs adaptation of the Iranian design has become so extensive that CSIS recently concluded that Russia has effectively mastered the platform through continuous battlefield-driven development.
Please open Telegram to view this post
VIEW IN TELEGRAM
๐ GitLab CVE-2026-85706 moves from disclosure to exploitation in 24 hours
GitLab disclosed CVE-2026-85706 on 10 September: a CVSS 10.0 path traversal flaw in the repository commits API allowing arbitrary file reads via a single unauthenticated HTTP request. Affected branches include 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Active probing began by 11 September, and CISA added the issue to KEV.
The operational impact is direct exposure of SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data on public-facing self-hosted GitLab instances. Immediate patching, log review for POST requests to commits API endpoints with file.path parameters, and credential rotation after compromise checks are now baseline response steps.
๐ฐ๏ธ Open sources - closed narratives
@sitreports
GitLab disclosed CVE-2026-85706 on 10 September: a CVSS 10.0 path traversal flaw in the repository commits API allowing arbitrary file reads via a single unauthenticated HTTP request. Affected branches include 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. Active probing began by 11 September, and CISA added the issue to KEV.
The operational impact is direct exposure of SSH keys, database credentials, deploy tokens, CI/CD variables, and other sensitive configuration data on public-facing self-hosted GitLab instances. Immediate patching, log review for POST requests to commits API endpoints with file.path parameters, and credential rotation after compromise checks are now baseline response steps.
๐ฐ๏ธ Open sources - closed narratives
@sitreports