Overview
- OISF
- Suricata
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
RE: https://infosec.exchange/@suricata/117309241594395404
https://nvd.nist.gov/vuln/detail/cve-2026-94083
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
https://nvd.nist.gov/vuln/detail/cve-2026-94084
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Overview
- OISF
- Suricata
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
RE: https://infosec.exchange/@suricata/117309241594395404
https://nvd.nist.gov/vuln/detail/cve-2026-94083
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
https://nvd.nist.gov/vuln/detail/cve-2026-94084
sev:CRIT 9.4 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Overview
- Docker
- Docker Sandboxes
Description
Statistics
- 1 Post
Fediverse
Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 #devopsish https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994
Overview
- Docker
- Docker Sandboxes
Description
Statistics
- 1 Post
Fediverse
Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 #devopsish https://docs.docker.com/security/security-announcements/#docker-sandboxes-0420-security-update-cve-2026-77179-and-cve-2026-79994
Overview
Description
Statistics
- 1 Post
Fediverse
Following @volexity’s September 9 blog post on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity discovered another threat actor, UTA0565, had been using the same exploits on Sept 3-4, 2026, while they were still unpatched.
UTA0565 used multiple fake websites, posing as media organizations and an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening.
Full details and IOCs can be found here: https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/
#DFIR #threatintel
Description
Statistics
- 1 Post
Fediverse
Following @volexity’s September 9 blog post on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity discovered another threat actor, UTA0565, had been using the same exploits on Sept 3-4, 2026, while they were still unpatched.
UTA0565 used multiple fake websites, posing as media organizations and an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening.
Full details and IOCs can be found here: https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/
#DFIR #threatintel
Overview
Description
Statistics
- 1 Post
Description
Statistics
- 1 Post
Fediverse
Following @volexity’s September 9 blog post on two Chinese APT actors chaining 0-days in Chrome (CVE-2026-85046, CVE-2026-87491) & Windows (CVE-2026-85880), Volexity discovered another threat actor, UTA0565, had been using the same exploits on Sept 3-4, 2026, while they were still unpatched.
UTA0565 used multiple fake websites, posing as media organizations and an NGO, to run a more customized version of the exploit framework than previously documented instances. The payload delivered was a new custom malware family, CLEANGULP, obfuscated using control flow flattening.
Full details and IOCs can be found here: https://www.volexity.com/blog/2026/09/21/mind-the-patch-gap-part-2-fake-websites-used-to-deploy-chrome-windows-0-day-exploits/
#DFIR #threatintel