Armored Likho expands its cyber-espionage toolkit
The campaign uses fundraising and Starlink lures as bait and delivers a new toolkit generation that steals Telegram data and eavesdrops on victims.
Comparing 12 September 2026 with the previous day 11 September 2026.
The campaign uses fundraising and Starlink lures as bait and delivers a new toolkit generation that steals Telegram data and eavesdrops on victims.
The flaw allows local attackers to escalate privileges in the Linux kernel and affects unpatched Ubuntu systems.
Bundling several already-patched zero-days into a circulating exploit kit lets even less skilled espionage-motivated actors exploit them, making the window between patch availability and patch deployment the decisive risk factor.
The report provides a quarterly overview of the threat landscape for industrial automation systems and documents new APT malware attributed to Mirage Kitten, which is strategically relevant for production environments.
The report summarizes multiple vulnerabilities in Google Chrome without specific CVEs or exploit details; timely patch management remains necessary.
The vulnerability requires user interaction and affects widely used compression software installed in many corporate environments; a CVE ID is not yet available.
This BSI advisory lists multiple Edge vulnerabilities without CVE references and without indication of active exploitation.
The report describes a novel attack technique (Benchmaxxing) that goes beyond pure patch information and provides new TTPs for defense.
The advisory summarises multiple Linux kernel vulnerabilities without providing specific CVEs or evidence of active exploitation.
No changes in this category.
No changes in this category.
The alert provides no details on active exploitation, affected versions, or patch urgency , it is a generic patch announcement without context on threat activity or deployment timeline.
Sensitive information hardcoded in source code allows unauthorized access to FortiMonitor instances; vague attack vector details suggest incomplete CVE documentation.
No additional strategic information beyond patch announcement available; merely technical CVE classification without context of active exploits or campaigns.
The vulnerability requires user interaction to upload a malicious driver and is not documented in active attack scenarios to date.
APT29 leverages generative AI systems to automate malware regeneration after detection, undermining static detection mechanisms, and compromises supply-chain infrastructure (hospitality vendors) for network manipulation.
Russian state-linked actors are weaponizing commercial AI tools like Claude for targeted cyber-espionage against Western government and defense organizations, signaling strategic escalation of hybrid warfare with DACH implications.
Russian state-sponsored hacker groups directly targeted AI vendor infrastructure and leveraged Claude to automate malware evasion techniques, signaling a new attack model against cloud service providers and their customers.
Pure vulnerability report with no indication of active exploitation, PoC, or attacker TTPs.
The flaw is only exploitable on systems with the WDS role enabled, so the effective attack surface depends heavily on role configuration, and no patch is yet confirmed.
The flaw was demonstrated at Pwn2Own; it allows bypassing the existing authentication mechanism and thereby escalating privileges on Exchange servers, despite authentication being nominally required.
The vulnerability was demonstrated as a zero-day at Pwn2Own and allows unauthenticated bypass of Exchange authentication , an indication that patches may only become available with a delay.
This is a kernel LPE in win32kfull demonstrated at Pwn2Own, with no patch status communicated yet, which combined with an initial-access vector enables full system compromise.
The advisory highlights ICC color profiles as an attack vector for remote code execution on Windows; exploitation requires interaction with the color management library.
The flaw was demonstrated at Pwn2Own and allows an attacker who already has local code execution to escalate privileges on Windows systems; public exploit code is therefore fundamentally likely.
The vulnerability was demonstrated at Pwn2Own, indicating an available exploit; a local attacker with low privileges can gain system privileges.
The Pwn2Own finding demonstrates exploitability of the local privilege escalation in ipt.sys; active exploitation is not known.
The BSI has documented critical and zero-day vulnerabilities in Microsoft SharePoint without providing specific CVE identifiers or details on active exploitation , indicating a general security advisory without active-campaign context.
BSI warns of critical code execution vulnerability in multiple Microsoft Office versions triggered by Use-After-Free, requiring immediate patches.
Attackers use invisible Unicode characters to split financial lure words and bypass modern email filters,representing an evolution of AI-era evasion techniques into large-scale traditional phishing campaigns.
Heise reports on SAP patch day with multiple critical vulnerabilities but does not name active attacks or exploit code; typical patch reminder reporting without evidence of wild exploitation.
A Russian threat actor group is using AI-generated exploits to automate and scale attacks against hundreds of PaperCut instances worldwide, combined with active post-exploitation for remote code execution and credential harvesting.
The BSI warns of multiple vulnerabilities in Adobe Acrobat/Reader enabling a broad range of attack scenarios, though specific CVE numbers or version details are not provided in this alert.
BSI warning regarding multiple Chrome vulnerabilities without specific CVE identification or patch-status details; typically an aggregated update advisory.
The Bluemoon exploit kit is actively used by Chinese hackers against Windows users and poses an immediate threat to manufacturing environments.
The vulnerability enables authentication bypass in PLC systems through incorrect implementation of authentication algorithms, which is particularly critical for legacy or lower application levels.
The BSI advisory describes multiple vulnerabilities in GNU libc without specific CVE numbers, which may indicate coordinated disclosure or an incompletely documented vulnerability series.
BSI advisory on systemd vulnerabilities without specification of individual CVE IDs; patch status and active exploitation remain unclear.
BSI warns of multiple Chrome vulnerabilities without full technical details; patches should be applied promptly once available.
BSI warns of multiple Intel processor vulnerabilities with high risk for local privilege escalation and data loss; specific CVE details are missing from this generic advisory.
Adobe Lightroom Classic contains multiple critical vulnerabilities (path traversal, unsafe deserialization, integer overflow, buffer overflows, authorization flaws) that can be combined to enable remote code execution.
BSI warns of multiple, partly critical vulnerabilities in Microsoft Edge with potential for code execution and data leaks; exploitation requires user interaction in some cases but remains practical.
The BSI report summarises several vulnerabilities in Ubiquiti UniFi but provides no CVE IDs or affected versions, so the vendor advisories are needed for specifics.
Attackers exploit passkey-themed phishing lures to trick users into revealing Microsoft 365 authentication credentials,a tactic that exploits modern security expectations.
There is no evidence of active exploitation, threat actors, or strategic implications; the report describes only a single kernel vulnerability with an available patch.
Pure patch information with no indication of active exploitation or strategic relevance.
The vulnerability is a local out-of-bounds write in the AppArmor parser that can be triggered via /proc/self/attr/apparmor/current, but requires loaded AppArmor profiles and has not been actively exploited so far.
The report contains no information beyond the patch details regarding active exploitation, attackers, or affected sectors.
The report contains no insights beyond patch information, as it is a pure NVD entry with no indication of active exploitation.