Rescana Blog
1206 posts | Page 7 of 51

Active Exploitation Alert
Active Exploitation of WinRAR CVE-2025-8088 by Russia-Aligned APTs Targets Ukrainian Government with Advanced Stealer Malware

Active Exploitation Alert
Active Exploitation Alert: Shai-Hulud Supply Chain Attack Compromises 100+ NPM and PyPI Packages with Self-Spreading Malware

Active Exploitation Alert
Active Exploitation Alert: CVE-2026-42271 and CVE-2026-48710—Unauthenticated RCE in LiteLLM AI Gateway via Starlette Host Header Bypass

Cybersecurity Incident Analysis
Miasma Worm Supply Chain Attack: 73 Microsoft GitHub Repositories Compromised via AI Coding Tools

CVE Analysis Center
Google Chrome 149 Security Update: Analysis of Record 429 Vulnerabilities Patched Across Windows, macOS, and Linux

Cybersecurity Incident Analysis
DentaQuest Data Breach Analysis: ShinyHunters Leak Exposes PII and PHI of 2.6 Million Members in 2026

Active Exploitation Alert
Active Exploitation of Dover Fueling Solutions and OPW Automatic Tank Gauge Systems Exposes US Fuel Infrastructure to Iranian APT Attacks

Active Exploitation Alert
Active Exploitation of Critical CVE-2026-3300 Vulnerability in Everest Forms Pro Plugin Threatens WordPress Sites Globally

Active Exploitation Alert
Active Exploitation Alert: FIFA World Cup 2026 Targeted by Fake Ticket Sites, Banking Malware, and Credential Theft

Active Exploitation Alert
Active Exploitation Alert: Cisco Catalyst SD-WAN Manager CVE-2026-20245 Zero-Day Under Attack With No Patch Available

Email Security
Cyber Espionage Attack: Five-Month Compromise of Stock Exchange Executive’s Outlook Mailbox via Covert Cloud Exfiltration

Active Exploitation Alert
Active Exploitation Alert: Fake Open-Source Software Sites Dominate Google Search to Distribute Malware via Advanced TDS

Active Exploitation Alert
Active Exploitation Alert: Critical VS Code Zero-Day Enables One-Click GitHub Token Theft and Massive Internal Repository Breach

Cybersecurity Incident Analysis
Miasma Supply Chain Attack Compromises Red Hat @redhat-cloud-services npm Packages With Credential-Stealing Worm: Cybersecurity Incident Analysis and Mitigation

Cybersecurity Incident Analysis
Critical Supply Chain Attack Compromises 32 Red Hat @redhat-cloud-services NPM Packages with Credential-Stealing Malware

Active Exploitation Alert
Active Exploitation Alert: Palo Alto Networks PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)

Active Exploitation Alert
Active Exploitation Alert: Microsoft Windows and Defender Zero-Day Vulnerabilities Trigger Global Backlash Amid Legal Threats to Security Researchers

Service Disruption Analysis
GlassWorm Malware Takedown: Disruption of Developer Supply Chain Attacks Targeting VSCode, npm, Python, and GitHub

CVE Analysis Center
CVE-2026-41241: Critical Stored XSS in Pretalx Conference Platform Allows Attackers 100% Talk Acceptance (Patched in 2026.1.0)

CVE Analysis Center
CVE-2026-27771: Critical Gitea Container Registry Vulnerability Exposes Private Images to Unauthenticated Attackers

Active Exploitation Alert
Active Exploitation Alert: Grandoreiro Banking Trojan and BTMOB RAT Targeting Windows and Android Users in Global Financial Malware Campaigns

Active Exploitation Alert
Active Exploitation Alert: GPU Mining Malware Targeting Windows Systems via SEO Poisoning and AI Chatbot Recommendations

Active Exploitation Alert
Active Exploitation Alert: AI-Assisted Zero-Day Targeting Erlang SSH Library (CVE-2025-32433) Outpaces Vulnerability Scanners

Cybersecurity Incident Analysis