Asutorufaのブログ

こんにちは

Threat Intelligence

Threat Intelligence

Daily security intelligence collected from public sources.

Latest

Threat Intelligence Daily · 2026-10-02

October 2 centered on three distinct risks: GitLab patched a CVSS 9.9 AI Gateway sandbox escape that can lead to command execution, Dell disclosed multiple critical Container Storage Modules flaws including two CVSS 10.0 authentication failures, and Frontline Education began notifying school districts after a third-party software vulnerability exposed employee data.

Critical2High1Medium0Low0Exploited13 threats

Threat Intelligence Daily · 2026-10-02

October 2 centered on three distinct risks: GitLab patched a CVSS 9.9 AI Gateway sandbox escape that can lead to command execution, Dell disclosed multiple critical Container Storage Modules flaws including two CVSS 10.0 authentication failures, and Frontline Education began notifying school districts after a third-party software vulnerability exposed employee data.

Critical2High1Medium0Low0Exploited13 threats

Threat Intelligence Daily · 2026-10-01

October 1 combined an actively exploited FortiMail zero-day with two targeted campaigns and a firmware security note: Fortinet disclosed CVE-2026-104286 and attack IOCs, Proofpoint detailed TA419 credential phishing against AI-policy experts, Symantec described Longlegs/Warlock attacks on critical infrastructure, and CERT/CC published InsydeH2O IHISI SMM memory-write findings.

Critical1High2Medium1Low0Exploited34 threats

Threat Intelligence Daily · 2026-09-30

September 30 brought two newly documented actively exploited edge/server flaws and a deeper NetScaler follow-up: Microsoft traced exploitation of Zimbra CVE-2026-73570, Cisco confirmed active exploitation of Catalyst SD-WAN Manager CVE-2026-76504, Unit 42 expanded NetScaler post-exploitation findings, and JVN published a path-traversal issue affecting FUJIFILM/Sharp multifunction printers.

Critical3High0Medium1Low0Exploited34 threats

Threat Intelligence Daily · 2026-09-29

September 29 combined two active threat-research disclosures with two library/server vulnerability sets: Microsoft described phishing that abuses MSP360 and ScreenConnect plus Star Blizzard's RedFlick delivery technique, while JVN published seven Pgpool-II CVEs and CERT/CC disclosed an Authlib JWS signature-verification bypass.

Critical0High4Medium0Low0Exploited24 threats

Threat Intelligence Daily · 2026-09-28

September 28 added context rather than another flood of CVEs: Unit 42 counted more than 50,000 potentially vulnerable NetScaler instances after zero-day exploitation, Microsoft documented the NeedyMantis post-compromise framework, Kiteworks restored systems after identifying and fixing a previously unknown critical issue, and JVN published BUFFALO Wi-Fi fixes.

Critical1High3Medium0Low0Exploited24 threats

Threat Intelligence Daily · 2026-09-27

Two developments defined September 27: Citrix disclosed two NetScaler zero-days already exploited against unmitigated appliances, while Kiteworks lifted its precautionary shutdown recommendation and still reported no evidence of customer compromise.

Critical1High0Medium1Low0Exploited12 threats

Threat Intelligence Daily · 2026-09-26

September 26 was quieter but still produced three operationally relevant events: Keio Plaza Hotel confirmed a ransomware-caused system outage, the Mini Shai-Hulud GitHub Actions incident reached a containment update, and Kiteworks asked customers to perform a precautionary nine-hour shutdown after federal threat intelligence.

Critical0High3Medium0Low0Exploited23 threats

Threat Intelligence Daily · 2026-09-25

September 25 added four actionable exploitation updates and one Japanese CMS disclosure set: SharePoint CVE-2026-65660 and MikroTik CVE-2026-67279 entered the exploited-vulnerability queue, WordPress CVE-2026-87902 reached CISA KEV, Microsoft detailed Storm-3168 destructive Azure activity, and JVN published baserCMS fixes.

Critical1High3Medium1Low0Exploited45 threats

Threat Intelligence Daily · 2026-09-24

Six events were retained for September 24. CISA added exploited WSO2 and Adobe Commerce flaws to KEV; WordPress and Roundcube exploitation required rapid patching; Microsoft documented Storm-2570 ransomware affiliate activity; and SolarWinds fixed two unauthenticated RCE paths in Observability Self-Hosted.

Critical4High2Medium0Low0Exploited56 threats

Threat Intelligence Daily · 2026-09-23

Four threat events require action: Check Point confirmed exploitation of two pre-authentication flaws, F5 disclosed an exploited BIG-IP APM zero-day, Arista reported active exploitation of a VeloCloud Orchestrator flaw, and compromised MemTensor npm/PyPI releases shipped the sckit credential-stealing worm.

Critical3High1Medium0Low0Exploited44 threats

Threat Intelligence Daily · 2026-09-22

CISA added an actively exploited Zyxel GS1900 command-execution flaw to KEV after a campaign compromised 996 switches. Microsoft disrupted EvilTokens after more than 12,000 inbox compromises. Volexity linked a third China-aligned actor to a shared Chrome/Windows zero-day chain, while Arctic Wolf reports active exploitation of a Veeam Agent local privilege-escalation flaw.

Critical0High4Medium0Low0Exploited44 threats

Threat Intelligence Daily · 2026-09-21

Fortinet telemetry confirms active exploitation of an unauthenticated Orkes Conductor RCE. Kaspersky documented a manufacturing intrusion where attackers used Group Policy for encryptionless extortion, while Securonix decoded TASK#STOMP as a persistent PowerShell backdoor for document theft and remote command execution.

Critical1High2Medium0Low0Exploited33 threats

Threat Intelligence Daily · 2026-09-20

ConoHa WING disclosed unauthorized access to customer web-server areas affecting 426 accounts. Checkmarx documented an npm malware campaign that moves execution from install scripts into normal library runtime, while working exploits are now public for four patched Linux kernel local-root flaws.

Critical0High3Medium0Low0Exploited23 threats

Threat Intelligence Daily · 2026-09-19

CISA added three actively exploited Linux kernel flaws to KEV with a September 21 remediation target. WordPress 7.1.1 fixes a crafted-URL theme-install path later demonstrated as Click2Shell, Chrome 153 fixes critical Dawn and WebGL memory-safety bugs, and vm2 3.11.7 closes multiple sandbox-boundary failures including host-process RCE and TLS trust-store manipulation.

Critical3High1Medium0Low0Exploited14 threats

Threat Intelligence Daily · 2026-09-18

Japan and international partners attributed the WaterPlum fake-recruitment campaign to North Korea and documented more than 30,000 infected devices. AIR disclosed Plugin4Shell across major AI coding agents, Check Point patched an unauthenticated root RCE in management servers, Microsoft disclosed a server-side-mitigated Azure AI Foundry flaw rated CVSS 10.0, and Zscaler detailed APT36's RapidRust espionage tooling.

Critical2High3Medium0Low0Exploited25 threats

Threat Intelligence Daily · 2026-09-17

Cisco disclosed an actively exploited, unauthenticated ISE authentication bypass with a CVSS score of 10.0. ESET documented FamousSparrow's new SparroWocky backdoor against Latin American governments, while CrowdStrike described PhantomRaven malware distributed through npm. Malwarebytes also tracked a large T-Mobile-themed SMS phishing campaign, and JVN published a fixed hard-coded-key flaw in Tohoku Electric Power's Yorisou e Net app.

Critical1High2Medium1Low1Exploited35 threats

Threat Intelligence Daily · 2026-09-16

Google's September Pixel bulletin confirms limited targeted exploitation of CVE-2026-58704. UK, US and Dutch agencies published technical details for Iran-linked CHOSEN BRICK spyware, while Kaspersky documented NightEagle intrusions using stolen VPN credentials, GhostContainer, RDP tunneling and BlueKeep. OPSWAT also published details for two patched TP-Link Tapo C200 flaws requiring network access.

Critical0High4Medium0Low0Exploited34 threats

Threat Intelligence Daily · 2026-09-15

September 15 brought a high-confidence ransomware-prepositioning update around N-able N-central, fresh FreeRDP 3.31.0 security fixes, new JFrog analysis of 3,022 GemStuffer-linked RubyGems packages, and coordinated disclosure of the DDRop physical attack against confidential-computing memory integrity. Linux RPC/RDMA and SUNRPC fixes also warrant review where the affected transports are enabled.

Critical2High3Medium0Low0Exploited25 threats

Threat Intelligence Daily · 2026-09-14

The most urgent new threat on September 14 was Cisco Secure Email Gateway CVE-2026-76461: an unauthenticated remote attacker can trigger root-level command execution through a crafted email. Cisco confirmed active exploitation and CISA added it to KEV the same day. Other notable items include the Mathspace breach via Metabase CVE-2026-72898, follow-up on the IDScan.net identity-data incident, and new JVN disclosures affecting FLEXLAN, YAMAP and ExLlamaV3.

Critical1High3Medium2Low0Exploited26 threats

Threat Intelligence Daily · 2026-09-13

As of 2026-09-13, the most urgent threats center on actively exploited DevOps, remote-management and edge-device vulnerabilities, plus the BlueMoon browser/Windows zero-day chain rapidly adopted by multiple state-aligned clusters. CISA added five KEVs, PaperCut and GitLab saw real-world attack activity, while Check Point disclosed two critical VPN RCEs and the Brevo incident enabled targeted phishing against Trezor users.

Critical7High1Medium0Low0Exploited78 threats
©2026Asutorufa