<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>OSec Threat Briefs</title><description>Weekly threat situation reports from OSec (OccamSec).</description><link>https://www.osec.com/</link><language>en-us</language><item><title>Weekly Situation Report — 8/3/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-8-3-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-8-3-26/</guid><description>Security researchers have released a proof-of-concept exploit for CVE-2026-54121, a critical privilege escalation vulnerability in Microsoft&apos;s Active Directory Certificate Services. The vulnerability enables attackers to manipulate directory lookup processes to impersonate domain controllers and…</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 7/27/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-27-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-27-26/</guid><description>Ernst &amp; Young (EY) disclosed a breach of a third-party IT support system holding client tax information. An unauthorized party accessed the system between March 28 and April 12, 2026, and downloaded multiple documents. So far, no misuse of the exposed files has been detected.</description><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 7/20/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-20-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-20-26/</guid><description>A phishing campaign leverages DocuSign lures to automatically download payloads, track user interactions, and install legitimate RMM tools for persistent access.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 7/13/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-13-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-13-26/</guid><description>A suspected Chinese espionage group used a Roundcube exploit chain to compromise university engineering departments in targeted attacks.; Researchers have demonstrated an offensive technique that recovers active ADFS signing keys using Machine DPAPI, after manual certificate rotation.; A newly…</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 7/6/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-6-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-6-26/</guid><description>A new Citrix NetScaler pre-authentication memory overread vulnerability, dubbed CitrixBleed To Infinity And Beyond (CVE-2026-8451), exposes affected appliances to remote attacks.; A security researcher has released an exploitarium repository containing proof-of-concept exploits for multiple…</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/29/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-29-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-29-26/</guid><description>An update to the FortiBleed incident details use of custom tooling used by threat actors in post compromise activities, alongside credential-centric exploitation.; Cisco Unified CM flaw CVE-2026-20230 claimed to be exploited in the wild. Attackers used known unverified and likely fake PoC, while…</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/22/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-22-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-22-26/</guid><description>A critical pre-authentication remote code execution vulnerability in Splunk Enterprise (CVE-2026-20253) has left more than 13,000 internet-exposed instances at risk.; A vulnerability in SimpleHelp allows attackers to create unauthorized accounts on affected systems.; The DragonForce ransomware…</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/15/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-15-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-15-26/</guid><description>A newly discovered Cisco SD-WAN zero-day vulnerability is actively exploited against enterprise networks; Verdant Panda (UNC5221) deploys multiple backdoors for sustained persistence in targeted intrusions; Nightmare Eclipse researchers unveiled RoguePlanet and greatXML exploits targeting fully…</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/8/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-8-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-8-26/</guid><description>A newly discovered CIFSwitch Linux local privilege escalation flaw enables attackers to gain root access across multiple distributions.; Attackers are exploiting a Palo Alto GlobalProtect authentication bypass vulnerability that allows forged cookies to grant unauthorized access.; A Chinese threat…</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/1/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-1-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-1-26/</guid><description>SQL injection in Ghost CMS powers large-scale ClickFix malware campaigns; Lazarus APT subgroup introduced fileless remote access trojan for evasion; Nimbus Manticore continues targeting aerospace and technology sectors; cPanel LiteSpeed plugin vulnerability (CVE-2026-48172) actively exploited…</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/25/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-25-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-25-26/</guid><description>Nightmare Eclipse disclosed MiniPlasma, a Windows local privilege escalation vulnerability; A public exploit emerged for the DirtyDecrypt Linux root escalation vulnerability; Microsoft warned of an actively exploited Exchange zero-day flaw; FlowerStorm malware uses KrakVM virtual machine framework…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/18/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-18-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-18-26/</guid><description>Two new Linux local privilege escalation flaws, Dirty Frag and Fragenesia, have been disclosed and may already be under active exploitation.; The Shai-Hulud campaign has compromised additional AI-related packages and released its source code publicly in a move framed as a competition.; A second…</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/11/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-11-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-11-26/</guid><description>A critical buffer overflow vulnerability in PAN-OS is being actively exploited to compromise affected firewall devices.; DAEMON Tools Lite was trojanized in a supply-chain attack to distribute a hidden backdoor to users.; The CloudZ remote access trojan may be stealing one-time passcodes by abusing…</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/4/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-4-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-4-26/</guid><description>SAP-related npm packages have been targeted in the Shai-Hulud supply chain attack to distribute malicious code.; A critical vulnerability in cPanel and WHM is being actively exploited in the wild, with a public proof-of-concept now available.; GlassWorm supply chain attacks have been linked to…</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/27/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-27-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-27-26/</guid><description>Threat actors deploy malicious document sharing and meeting invites as phishing lures to distribute ScreenConnect remote access tool; A Vercel security incident claimed by fake ShinyHunters group resulted in possible supply-chain compromise; CISA issued urgent warnings about critical SD-WAN…</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/20/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-20-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-20-26/</guid><description>Multiple vulnerabilities in Adobe Acrobat are being actively exploited in real-world attacks.; Hackers are conducting sophisticated remote access campaigns to infiltrate shipping systems and steal cargo.; An impersonator posing as a Linux Foundation leader is using Slack messages to phish…</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/13/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-13-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-13-26/</guid><description>Iranian-linked hackers are targeting critical infrastructure and exposed operational technology (OT) systems in ongoing campaigns.; Attackers are exploiting a vulnerability in the Ninja Forms plugin that leaves WordPress sites vulnerable to full takeover.; AI-driven Microsoft device code phishing…</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/6/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-6-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-6-26/</guid><description>A critical memory overread vulnerability in Citrix NetScaler is actively exploited in real-world attacks; Hackers target a critical F5 BIG-IP vulnerability for unauthorized system access; North Korean state-linked threat group attributed to axios supply chain attack; Cisco source code stolen…</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/30/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-30-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-30-26/</guid><description>A critical Oracle Identity Manager vulnerability (CVE-2026-21992) enables remote code execution on affected systems.; TEAMPCP supply chain attacks are escalating following the compromise of a security tool used in development environments.; Attackers are abusing Microsoft Azure Monitor alerts to…</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/23/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-23-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-23-26/</guid><description>A critical Telnet vulnerability affecting all versions has been disclosed, with no patch expected until April 1st.; The LeakNet ransomware group is using ClickFix techniques and the Deno runtime to conduct stealthy intrusions.; The ForceMemo campaign has compromised Python repositories in the…</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/16/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-16-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-16-26/</guid><description>Storm-2561 distributes trojanized software via SEO poisoning to deceive victims into downloading malware; A newly demonstrated Zombie ZIP technique is expected to be adopted by threat actors for evasion and detection bypass; The BlackSanta campaign uses an EDR-killer tool targeting HR departments…</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/9/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-9-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-9-26/</guid><description>VMware released patches for remote code execution vulnerabilities in Aria Operations allowing complete system compromise; Iranian-linked attacks targeted internet-connected IP cameras, likely involving state actors and affiliated groups; APT28 exploited MSHTML vulnerability CVE-2026-21513 as a…</description><pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/2/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-2-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-2-26/</guid><description>Critical vulnerabilities in SolarWinds Serv-U can grant attackers root-level access to affected servers; The &apos;Starkiller&apos; phishing service uses realistic login pages and MFA bypass techniques to steal credentials; VMware has released fixes for remote code execution vulnerabilities in Aria…</description><pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 2/23/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-2-23-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-2-23-26/</guid><description>Chinese state-sponsored actors have exploited a hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines since mid-2024, deploying two malware families (Brickstorm and its successor Grimbolt) to maintain persistent backdoors and pivot laterally through victim networks.</description><pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>