<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>OSec Threat Briefs</title><description>Weekly threat situation reports from OSec (OccamSec).</description><link>https://www.osec.com/</link><language>en-us</language><item><title>Weekly Situation Report — 7/13/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-13-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-13-26/</guid><description>A suspected Chinese espionage group used a Roundcube exploit chain to compromise university engineering departments in targeted attacks.; Researchers have demonstrated an offensive technique that recovers active ADFS signing keys using Machine DPAPI, after manual certificate rotation.; A newly…</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 7/6/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-6-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-7-6-26/</guid><description>A new Citrix NetScaler pre-authentication memory overread vulnerability, dubbed CitrixBleed To Infinity And Beyond (CVE-2026-8451), exposes affected appliances to remote attacks.; A security researcher has released an exploitarium repository containing proof-of-concept exploits for multiple…</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/29/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-29-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-29-26/</guid><description>An update to the FortiBleed incident details use of custom tooling used by threat actors in post compromise activities, alongside credential-centric exploitation.; Cisco Unified CM flaw CVE-2026-20230 claimed to be exploited in the wild. Attackers used known unverified and likely fake PoC, while…</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/22/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-22-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-22-26/</guid><description>A critical pre-authentication remote code execution vulnerability in Splunk Enterprise (CVE-2026-20253) has left more than 13,000 internet-exposed instances at risk.; A vulnerability in SimpleHelp allows attackers to create unauthorized accounts on affected systems.; The DragonForce ransomware…</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/15/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-15-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-15-26/</guid><description>A newly discovered Cisco SD-WAN zero-day vulnerability is actively exploited against enterprise networks; Verdant Panda (UNC5221) deploys multiple backdoors for sustained persistence in targeted intrusions; Nightmare Eclipse researchers unveiled RoguePlanet and greatXML exploits targeting fully…</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/8/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-8-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-8-26/</guid><description>A newly discovered CIFSwitch Linux local privilege escalation flaw enables attackers to gain root access across multiple distributions.; Attackers are exploiting a Palo Alto GlobalProtect authentication bypass vulnerability that allows forged cookies to grant unauthorized access.; A Chinese threat…</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 6/1/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-1-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-6-1-26/</guid><description>SQL injection in Ghost CMS powers large-scale ClickFix malware campaigns; Lazarus APT subgroup introduced fileless remote access trojan for evasion; Nimbus Manticore continues targeting aerospace and technology sectors; cPanel LiteSpeed plugin vulnerability (CVE-2026-48172) actively exploited…</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/25/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-25-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-25-26/</guid><description>Nightmare Eclipse disclosed MiniPlasma, a Windows local privilege escalation vulnerability; A public exploit emerged for the DirtyDecrypt Linux root escalation vulnerability; Microsoft warned of an actively exploited Exchange zero-day flaw; FlowerStorm malware uses KrakVM virtual machine framework…</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/18/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-18-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-18-26/</guid><description>Two new Linux local privilege escalation flaws, Dirty Frag and Fragenesia, have been disclosed and may already be under active exploitation.; The Shai-Hulud campaign has compromised additional AI-related packages and released its source code publicly in a move framed as a competition.; A second…</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/11/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-11-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-11-26/</guid><description>A critical buffer overflow vulnerability in PAN-OS is being actively exploited to compromise affected firewall devices.; DAEMON Tools Lite was trojanized in a supply-chain attack to distribute a hidden backdoor to users.; The CloudZ remote access trojan may be stealing one-time passcodes by abusing…</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 5/4/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-4-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-5-4-26/</guid><description>SAP-related npm packages have been targeted in the Shai-Hulud supply chain attack to distribute malicious code.; A critical vulnerability in cPanel and WHM is being actively exploited in the wild, with a public proof-of-concept now available.; GlassWorm supply chain attacks have been linked to…</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/27/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-27-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-27-26/</guid><description>Threat actors deploy malicious document sharing and meeting invites as phishing lures to distribute ScreenConnect remote access tool; A Vercel security incident claimed by fake ShinyHunters group resulted in possible supply-chain compromise; CISA issued urgent warnings about critical SD-WAN…</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/20/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-20-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-20-26/</guid><description>Multiple vulnerabilities in Adobe Acrobat are being actively exploited in real-world attacks.; Hackers are conducting sophisticated remote access campaigns to infiltrate shipping systems and steal cargo.; An impersonator posing as a Linux Foundation leader is using Slack messages to phish…</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/13/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-13-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-13-26/</guid><description>Iranian-linked hackers are targeting critical infrastructure and exposed operational technology (OT) systems in ongoing campaigns.; Attackers are exploiting a vulnerability in the Ninja Forms plugin that leaves WordPress sites vulnerable to full takeover.; AI-driven Microsoft device code phishing…</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 4/6/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-6-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-4-6-26/</guid><description>A critical memory overread vulnerability in Citrix NetScaler is actively exploited in real-world attacks; Hackers target a critical F5 BIG-IP vulnerability for unauthorized system access; North Korean state-linked threat group attributed to axios supply chain attack; Cisco source code stolen…</description><pubDate>Thu, 09 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/30/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-30-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-30-26/</guid><description>A critical Oracle Identity Manager vulnerability (CVE-2026-21992) enables remote code execution on affected systems.; TEAMPCP supply chain attacks are escalating following the compromise of a security tool used in development environments.; Attackers are abusing Microsoft Azure Monitor alerts to…</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/23/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-23-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-23-26/</guid><description>A critical Telnet vulnerability affecting all versions has been disclosed, with no patch expected until April 1st.; The LeakNet ransomware group is using ClickFix techniques and the Deno runtime to conduct stealthy intrusions.; The ForceMemo campaign has compromised Python repositories in the…</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/16/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-16-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-16-26/</guid><description>Storm-2561 distributes trojanized software via SEO poisoning to deceive victims into downloading malware; A newly demonstrated Zombie ZIP technique is expected to be adopted by threat actors for evasion and detection bypass; The BlackSanta campaign uses an EDR-killer tool targeting HR departments…</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/9/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-9-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-9-26/</guid><description>VMware released patches for remote code execution vulnerabilities in Aria Operations allowing complete system compromise; Iranian-linked attacks targeted internet-connected IP cameras, likely involving state actors and affiliated groups; APT28 exploited MSHTML vulnerability CVE-2026-21513 as a…</description><pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 3/2/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-2-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-3-2-26/</guid><description>Critical vulnerabilities in SolarWinds Serv-U can grant attackers root-level access to affected servers; The &apos;Starkiller&apos; phishing service uses realistic login pages and MFA bypass techniques to steal credentials; VMware has released fixes for remote code execution vulnerabilities in Aria…</description><pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Weekly Situation Report — 2/23/26</title><link>https://www.osec.com/resources/threat-briefs/weekly-situation-report-2-23-26/</link><guid isPermaLink="true">https://www.osec.com/resources/threat-briefs/weekly-situation-report-2-23-26/</guid><description>Chinese state-sponsored actors have exploited a hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines since mid-2024, deploying two malware families (Brickstorm and its successor Grimbolt) to maintain persistent backdoors and pivot laterally through victim networks.</description><pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>