Rescana Blog
1243 posts | Page 8 of 52

Active Exploitation Alert
Oracle PeopleSoft PeopleTools Zero-Day (CVE-2026-35273) Actively Exploited: Urgent Patch Required to Prevent Ransomware and Data Breaches

Technology
OnyxC2 Stealer: Advanced Malware-as-a-Service Threatens Enterprise Security and Supply Chain Integrity in 2026

Cybersecurity Incident Analysis
OceanLotus (APT32) Supply Chain Attack: SPECTRALVIPER Backdoor Targets FireAnt Platform and Vietnamese Infrastructure

Technology
GitHub Disables npm Install Scripts by Default in v12 to Prevent JavaScript Supply Chain Attacks

Active Exploitation Alert
Gentlemen Ransomware Actively Exploiting Fortinet FortiGate Vulnerabilities: 478 Victims Hit by Rapid Worm-Like Attacks

Compliance
CISA BOD 26-04: Risk-Based Vulnerability Management and Patch Prioritization Requirements for Federal Agencies and Third-Party Systems

Cybersecurity Incident Analysis
ServiceNow API Security Incident Exposes Customer Data: Analysis of Unauthenticated Access Vulnerability (June 2026)

Cybersecurity Incident Analysis
SoFi Hong Kong Third-Party Data Breach Exposes Customer Information: Cybersecurity Incident Analysis and Lessons Learned

Cybersecurity Incident Analysis
Silent Ransom Group (Luna Moth) Extortion Attacks Target US Law Firms via Remote Access Tools and Social Engineering

Cybersecurity Incident Analysis
Nitrogen Ransomware Attack on Foxconn: Malvertising Threats, ESXi Vulnerability, and Supply Chain Risks in Manufacturing

Cybersecurity Incident Analysis
France Titres (ANTS) Identity Portal Breach: Massive IDOR Vulnerability Exposes Millions of French Citizen Records in 2026 Cyberattack

Active Exploitation Alert
CISA Issues 3-Day Emergency Directive to Patch Check Point VPN Zero-Day (CVE-2024-24919) Amid Active Qilin Ransomware Exploitation

Active Exploitation Alert
Active Exploitation of WinRAR CVE-2025-8088 by Russia-Aligned APTs Targets Ukrainian Government with Advanced Stealer Malware

Active Exploitation Alert
Active Exploitation Alert: Shai-Hulud Supply Chain Attack Compromises 100+ NPM and PyPI Packages with Self-Spreading Malware

Active Exploitation Alert
Active Exploitation Alert: Google Chrome Zero-Day CVE-2026-5281 Actively Exploited via Dawn WebGPU – Urgent Patch Required

Active Exploitation Alert
Active Exploitation Alert: CVE-2026-42271 and CVE-2026-48710—Unauthenticated RCE in LiteLLM AI Gateway via Starlette Host Header Bypass

Cybersecurity Incident Analysis
Miasma Worm Supply Chain Attack: 73 Microsoft GitHub Repositories Compromised via AI Coding Tools

CVE Analysis Center
Google Chrome 149 Security Update: Analysis of Record 429 Vulnerabilities Patched Across Windows, macOS, and Linux

Cybersecurity Incident Analysis
DentaQuest Data Breach Analysis: ShinyHunters Leak Exposes PII and PHI of 2.6 Million Members in 2026

Active Exploitation Alert
Active Exploitation of Critical CVE-2026-3300 Vulnerability in Everest Forms Pro Plugin Threatens WordPress Sites Globally

Active Exploitation Alert
Active Exploitation of Dover Fueling Solutions and OPW Automatic Tank Gauge Systems Exposes US Fuel Infrastructure to Iranian APT Attacks

Active Exploitation Alert
Active Exploitation Alert: FIFA World Cup 2026 Targeted by Fake Ticket Sites, Banking Malware, and Credential Theft

Active Exploitation Alert
Active Exploitation Alert: Cisco Catalyst SD-WAN Manager CVE-2026-20245 Zero-Day Under Attack With No Patch Available

Email Security