CRITICALADVISORY10h ago
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.
Action required
Identify and patch all Rejetto HFS instances to July 2026 patch level or later. Search logs for HFS access patterns and session manipulation attempts from October 2026 forward. Block HFS ports at perimeter if not actively required.
HTTP File Server (HFS)RejettoMythosAnthropic
CRITICALADVISORY10h ago
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persistence and can pivot to exploit additional router/DVR vulnerabilities, making it a serious risk for network compromise.
Action required
Immediately scan your network for exploitation attempts targeting CVE-2021-35394 and for STUN protocol anomalies on ports 3478-3479. Patch or isolate any Realtek-based routers and DVRs to the latest firmware version.
Realtek Jungle SDKRealtekNozomi Networks
HIGHADVISORY12h ago
Alleged dev of Ploutus ATM malware appears in US court after arrest
Ploutus ATM malware developer arrested after stealing $5.4M from ATMs between Feb 2024-Dec 2025 for Tren de Aragua gang. While the threat actor is in custody, variant samples and TTPs remain active in the wild. Organizations managing ATM networks or processing ATM transaction data need immediate visibility into potential compromise.
Action required
Hunt for Ploutus indicators: scan ATM systems and connected terminals for known malware signatures. Review ATM transaction logs for anomalous cash dispensing patterns, especially bulk withdrawals with minimal authentication. Block known C2 infrastructure and monitor for new variant activity.