Skip to main content

Threats Tagged 't1505'

View all threats tagged with 't1505'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: t1505

Threats Tagged 't1505'

Click on any threat for detailed analysis and mitigation recommendations

For the latest discoveries in cyber research for the week of 5th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Arizona’s state court system has suffered a phishing-led cyberattack after an employee clicked a malicious link. Attackers copied backup files containing protective-order records and more than 150,000 Foster Care Review Board reports dating back to 2010, exposing personal and case-related information belonging to current and former participants. Japanese car-sharing service Times Car has disclosed a data breach affecting approximately 6.6 million current and former accounts. Exposed information includes personal data, while identity-verification documents, including driver’s-license images, were exposed for about 1.6 million accounts. Payment card information was not affected. South Africa’s air navigation provider has suffered a ransomware attack affecting operational technology supporting aviation weather services. Preliminary findings identified suspicious activity in weather-related environments, while separate reporting cited possible data theft. The provider has sought independent digital forensics to determine the scope of the incident. Fakturownia, a Polish online invoicing platform used by more than 600,000 businesses, has disclosed a data breach after an attacker exploited a system vulnerability. Copied information included account and company data, password hashes, bank account details, authentication tokens, contractor information, and portions of invoices stored on the platform. AI THREATS Researchers observed autonomous AI agents attempting rudimentary hacking techniques while gathering public information from US and Canadian government websites. Activity included failed SQL injection attempts against the US Department of Education and Library and Archives Canada. Officials reported no compromise, while the origin of the agents remains unconfirmed. Researchers demonstrated that malicious Custom GPTs hosted on ChatGPT were used in a ClickFix campaign to deliver remote access malware. Victims were redirected to a Google Sites page and tricked into running commands. Huntress investigated at least 40 related incidents, including two confirmed infections that began through Custom GPTs. Researchers outlined how JadePuffer, an AI-enabled threat actor tracked as Storm-3168, used compromised Azure service principals to automate cloud reconnaissance and destructive actions. The activity included deleting storage and application resources, targeting backup-related assets, and attempting to retrieve access keys, reflecting agent-driven post-compromise operations in cloud environments. VULNERABILITIES AND PATCHES Citrix has issued fixes for critical NetScaler vulnerabilities CVE-2026-88771-2, affecting NetScaler ADC and Gateway. Attackers have exploited the flaws to gain remote access, deploy web shells and tunneling malware, steal credentials, and move from exposed appliances into internal networks. Check Point IPS provides protection against these threats (Citrix NetScaler Multiple Products Buffer Overflow (CVE-2026-88772), Citrix NetScaler Multiple Products Command Injection (CVE-2026-88771)) Cisco has alerted about CVE-2026-76504, a critical (CVSS 9.8) vulnerability in Catalyst SD-WAN Manager. The flaw allows an unauthenticated remote attacker to send crafted requests and gain administrator access. Cisco reported active exploitation and stated that no fixes are available. Check Point IPS provides protection against this threat (Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)) Apple has patched CVE-2026-86950, a CoreGraphics memory corruption vulnerability affecting iPhones, iPads, and Macs. Processing a malicious image or PDF can allow arbitrary code execution. Apple reported exploitation in highly targeted attacks and addressed the flaw through improved bounds checking across affected iOS, iPadOS, and macOS releases. GitLab has released patches for CVE-2…

Join the discussion
0

A Chinese-speaking threat actor tracked as Red Heron rapidly weaponized CVE-2026-60004, a critical Gitea remote code execution vulnerability, within days of public disclosure in July 2026. The actor scanned 1,386 Gitea instances across seven countries, successfully compromising organizations in Canada, Argentina, Taiwan, the United States, and Sri Lanka. Activities included source code theft, credential collection, SSH persistence, and lateral movement, with one case escalating from a vulnerable Gitea server to root access across a three-node Proxmox cluster. An exposed staging server revealed targeting taxonomies using Simplified Chinese labels covering defense, elections, energy, aerospace, telecommunications, and government sectors. The campaign deployed JITTERLY, a C++ Linux implant with 30+ post-exploitation commands, embedding SIXZUT, a previously undocumented LD_PRELOAD rootkit capable of hiding files, processes, and network connections while protecting the implant from termination.

Join the discussion

Active exploitation of three critical vulnerabilities in JFrog Artifactory has been identified, with attackers chaining CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 to bypass authentication and gain administrative control. CVE-2026-42018 exposes internal anonymous-user tokens, CVE-2026-42016 enables privilege escalation through insufficient token validation, and CVE-2026-82329 allows unauthenticated access to administrative privileges. Post-exploitation activities include creating persistent administrator accounts, deploying malicious Groovy plugins for code execution, and installing Rust-based backdoors. Exploitation was observed between August 15 and September 8, 2026, affecting multiple organizations. Data indicates 67-69% of organizations running Artifactory had vulnerable instances at initial publication, with slow patching velocity for lower-severity CVEs despite active exploitation across environments.

Join the discussion

An authentication bypass vulnerability, CVE-2026-18577, affecting N-able N-central Remote Monitoring and Management platform has been actively exploited since August 1, 2026. This vulnerability emerged after an incomplete fix for a previous authentication bypass issue CVE-2026-18556. The flaw allows remote unauthenticated attackers to bypass authentication mechanisms and gain administrative control over vulnerable N-central servers. Attackers have exploited this vulnerability to leverage the platform's Take Control functionality for remote access to managed endpoints and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. Given that N-central is widely used by managed service providers and enterprise IT teams with extensive administrative privileges, successful compromise provides attackers an efficient pathway to compromise downstream managed systems. CISA added this vulnerability to its Known Exploited Vulnerability catalog on August 3, 2026.

Join the discussion

Check Point has released urgent security updates addressing three critical vulnerabilities affecting Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating systems. The most severe vulnerability, CVE-2026-16232, allows unauthenticated remote attackers to bypass SmartConsole login and gain full administrative access to exposed Management Servers. The vulnerability has been actively exploited against customers with internet-exposed management infrastructure. Successful exploitation enables attackers to modify firewall policies, create administrator accounts, weaken security protections, and establish persistent access. Two additional vulnerabilities were patched: CVE-2026-62144 enabling unauthenticated command execution, and CVE-2026-62145 allowing privilege escalation from read-only to root access. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog with an exceptionally short remediation deadline, reflecting the severity of this authentication bypass...

Join the discussion

Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...

Join the discussion

In early May 2026, attackers compromised the official JDownloader website by manipulating specific installer download links through the content management system. Between May 6-7, 2026 (UTC), users who downloaded Windows installers via "Download Alternative Installer" links or the Linux shell installer were redirected to malicious third-party files instead of genuine installers. The attackers gained CMS-level access only, not server or filesystem control. The incident was detected on May 7 via Reddit alerts, and the server was immediately taken offline. Malicious links were removed, legitimate links restored, and security hardened before the site resumed normal operations on May 8-9. In-app updates and other download paths remained unaffected. Users who executed downloaded installers during the risk window are advised to perform clean OS reinstalls and change passwords from trusted devices.

Join the discussion

A supply chain poisoning attack on LiteLLM, a popular AI model gateway, was detected by NSFOCUS Technology CERT. The TeamPCP group compromised the Trivy security scanning tool used in LiteLLM's release process, allowing them to publish malicious versions 1.82.7 and 1.82.8 on PyPI. These versions contained credential-stealing programs that collected sensitive data and, if a Kubernetes cluster was detected, deployed privileged Pods and implanted persistent backdoors. The attack impacted numerous dependent packages and potentially affected millions of users. The incident highlights the growing risks in AI infrastructure and the need for robust supply chain security measures.

Join the discussion

A new supply chain attack targeting Trivy has compromised 75 out of 76 version tags in the aquasecurity/trivy-action GitHub repository. The attacker force-pushed these tags to serve malicious payloads, effectively turning trusted version references into a distribution mechanism for an infostealer. The malicious code executes within GitHub Actions runners, targeting sensitive data in CI/CD environments. It harvests secrets from runner process memory and the filesystem, encrypts the collected data, and exfiltrates it to an attacker-controlled endpoint or a fallback GitHub-based channel. The attack's scope is significant, potentially affecting over 10,000 workflow files on GitHub referencing this action.

Join the discussion

UAT-8099 is a malware campaign active from August 2025 to early 2026 targeting vulnerable IIS servers, primarily in Asia, with a focus on Thailand and Vietnam. It uses web shells, PowerShell scripts, and the GotoHTTP tool to maintain persistent remote access. New BadIIS malware variants show enhanced persistence, regional customization, and SEO fraud capabilities, with a Linux ELF variant indicating cross-platform targeting. The campaign shares infrastructure with the WEBJACK campaign, suggesting operational overlap. Although no known exploits are reported in the wild, advanced evasion and persistence techniques pose risks to confidentiality, integrity, and availability. European organizations with exposed IIS servers, especially those with business ties to Asia, should be vigilant. Targeted detection of web shells, PowerShell abuse, and monitoring for GotoHTTP traffic are critical mitigations. Germany, France, and the UK are most likely affected due to IIS usage and strategic interests in Asia.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Tag: t1505
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses