Urgent Threats & Advisories

Active and archived focus items for SOC teams and threat hunters

ACTIVE RIGHT NOW

CRITICALADVISORY10h ago

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

Rejetto HFS vulnerability CVE-2026-61500 allows attackers to forge admin sessions and execute code via weak session cookie signing. Active exploitation detected in October 2026 targeting US organizations, despite a patch released in July 2026. Any unpatched HFS instance is immediately compromised.

Action required
Identify and patch all Rejetto HFS instances to July 2026 patch level or later. Search logs for HFS access patterns and session manipulation attempts from October 2026 forward. Block HFS ports at perimeter if not actively required.
HTTP File Server (HFS)RejettoMythosAnthropic
CRITICALADVISORY10h ago

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persistence and can pivot to exploit additional router/DVR vulnerabilities, making it a serious risk for network compromise.

Action required
Immediately scan your network for exploitation attempts targeting CVE-2021-35394 and for STUN protocol anomalies on ports 3478-3479. Patch or isolate any Realtek-based routers and DVRs to the latest firmware version.
Realtek Jungle SDKRealtekNozomi Networks
HIGHADVISORY12h ago

Alleged dev of Ploutus ATM malware appears in US court after arrest

Ploutus ATM malware developer arrested after stealing $5.4M from ATMs between Feb 2024-Dec 2025 for Tren de Aragua gang. While the threat actor is in custody, variant samples and TTPs remain active in the wild. Organizations managing ATM networks or processing ATM transaction data need immediate visibility into potential compromise.

Action required
Hunt for Ploutus indicators: scan ATM systems and connected terminals for known malware signatures. Review ATM transaction logs for anomalous cash dispensing patterns, especially bulk withdrawals with minimal authentication. Block known C2 infrastructure and monitor for new variant activity.

ARCHIVE

Category:
Severity:
No focus items found.
Try a different filter.