June 2026 (30)
OpenMed RCE via Malicious Hugging Face Model Loading (CVE-2026-47117)
2 rules 1 TTPOpenMed before 1.5.2 is vulnerable to remote code execution (CVE-2026-47117) due to broad substring matching in the PII privacy-filter model loading path, allowing an unauthenticated attacker to execute arbitrary code by supplying a malicious Hugging Face model repository containing custom Transformers code.
HP Security Advisory for Poly Voice Vulnerability
2 rulesHP released a security advisory addressing a critical vulnerability in Poly VVX, Trio 8300, Trio 8500, and Trio 8800 devices, potentially allowing remote control.
Iran's MOIS Expands Handala Brand to Physical Threat Operations
1 rule 1 TTPIran's MOIS has broadened the Handala brand to encompass physical threat operations, recruiting proxies to conduct attacks, espionage, and sabotage against US and Israeli interests, amplifying both cyber and physical threats.
Multiple Vulnerabilities in X.Org X11 and Xwayland
2 rules 5 TTPsMultiple vulnerabilities exist in X.Org X11 and Xwayland, allowing attackers to disclose information, escalate privileges, conduct denial-of-service attacks, and perform unspecified attacks.
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
3 rules 1 TTP 8 IOCsOperation FlutterBridge is a malvertising campaign targeting macOS users with the new FlutterShell backdoor, which uses malicious desktop applications for adware distribution and provides backdoor capabilities such as command execution and file system manipulation, with some variants using AI summarization for data exfiltration.
FreePBX Hardcoded Credentials Vulnerability (CVE-2026-46376)
2 rules 1 TTP 1 CVEA critical vulnerability, CVE-2026-46376, exists in FreePBX due to the use of hard-coded credentials in the User Control Panel (UCP) generic template setup process, allowing an unauthenticated, remote attacker to gain unauthorized access to user accounts and manipulate user settings if default template credentials are not immediately changed by the administrator after enabling UCP.
CVE-2026-25276: Qualcomm Strongbox Memory Corruption Vulnerability
2 rules 1 CVECVE-2026-25276 describes a memory corruption vulnerability in Qualcomm's Strongbox due to a missing bounds check, potentially leading to arbitrary code execution.
CVE-2026-24092: Memory Corruption in Qualcomm Fastboot Display Mode Setting
2 rules 1 CVECVE-2026-24092 is a memory corruption vulnerability in Qualcomm products arising from improper validation when processing fastboot commands to set the display mode, potentially leading to arbitrary code execution.
CVE-2026-24091: Memory Corruption in Fastboot Command Processing
2 rules 2 TTPs 1 CVECVE-2026-24091 is a memory corruption vulnerability in Qualcomm devices that occurs when processing fastboot commands with improperly formatted input, potentially leading to code execution.
CVE-2026-24090 - Qualcomm Cryptographic Issue in Partition Table Processing
2 rules 2 TTPs 1 CVECVE-2026-24090 is a cryptographic issue in Qualcomm chipsets while processing partition table entries, allowing unauthorized modification of the boot flow due to missing authentication for critical functions.
CVE-2026-24089 Memory Corruption Vulnerability in Fastboot Command Processing
2 rules 1 TTP 1 CVECVE-2026-24089 describes a memory corruption vulnerability in processing fastboot commands with invalid input, potentially leading to arbitrary code execution on affected devices and requiring physical access to trigger.
CVE-2026-24087: Memory Corruption in Fastboot OEM Command Processing
2 rules 1 CVECVE-2026-24087 is a high-severity memory corruption vulnerability in Qualcomm components that occurs while processing fastboot OEM commands, potentially leading to code execution.
CVE-2026-24085 Memory Corruption Vulnerability in Display Command Line Processing
2 rules 1 TTP 1 CVECVE-2026-24085 is a memory corruption vulnerability due to improper initialization of a variable when processing display command line information, potentially leading to a stack-based buffer overflow (CWE-121) and allowing a privileged attacker to achieve code execution.
CVE-2025-59605: Qualcomm Device Identifier String Memory Corruption
2 rules 2 TTPs 1 CVECVE-2025-59605 is a memory corruption vulnerability in Qualcomm products where processing overly long device identifier strings leads to an out-of-bounds write, potentially allowing for information disclosure, code execution, or denial of service.
CVE-2025-59604 Memory Corruption Vulnerability Due to Null Pointer Dereference
2 rules 1 CVECVE-2025-59604 is a memory corruption vulnerability due to invalid writes caused by a null pointer when running a memory copy operation, potentially leading to arbitrary code execution, as reported by Qualcomm.
CVE-2019-25718: Dräger Infinity Explorer C700 Kiosk Escape Vulnerability
2 rules 1 TTP 1 CVEDräger Infinity Explorer C700 contains a privilege escalation vulnerability (CVE-2019-25718) that allows attackers to break out of kiosk mode, access the underlying operating system, and potentially cause the device to display incorrect patient monitor information.
Red Hat Cloud Services npm Packages Hijacked
2 rulesMultiple npm packages within the legitimate @redhat-cloud-services namespace have been hijacked with malicious code, posing a supply chain risk.
UTT HiPER 1200GW Stack-Based Buffer Overflow Vulnerability (CVE-2026-10292)
1 rule 1 TTP 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-10292) exists in the strcpy function of /goform/formTaskEdit in UTT HiPER 1200GW up to version 2.5.3-170306, allowing for remote code execution.
Pixa Bank 2.0 Unauthenticated SQL Injection Vulnerability
2 rules 1 TTP 1 CVEPixa Bank 2.0 is vulnerable to SQL injection, allowing unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter via POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads, potentially leading to the retrieval of user information such as names, email addresses, and phone numbers from the database.
UTT HiPER 1200GW Stack-Based Buffer Overflow Vulnerability (CVE-2026-10293)
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-10293) exists in UTT HiPER 1200GW up to version 2.5.3-170306 due to the strcpy function in /goform/formFireWall, allowing remote exploitation via manipulation of the Profile argument.
CVE-2026-10290: Hotel and Tourism Reservation System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation System version 1.0 due to improper sanitization of the 'tour' GET parameter in the tour.php file, potentially allowing remote attackers to execute arbitrary SQL queries.
WP AutoSuggest 0.24 SQL Injection Vulnerability (CVE-2018-25434)
2 rules 1 TTP 1 CVEWP AutoSuggest version 0.24 contains an SQL injection vulnerability that allows an unauthenticated attacker to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter via GET requests to autosuggest.php, potentially extracting sensitive database information.
CVE-2018-25433 - Joomla JE Photo Gallery SQL Injection
1 rule 1 TTP 1 CVEJoomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability, tracked as CVE-2018-25433, allowing unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter.
CVE-2018-25432: Arm Whois 3.11 Buffer Overflow Vulnerability
2 rules 2 TTPs 1 CVEArm Whois 3.11 contains a buffer overflow vulnerability (CVE-2018-25432) that allows local attackers to execute arbitrary code by overwriting the structured exception handler via a crafted input file.
No-CMS 1.0 SQL Injection Vulnerability (CVE-2018-25431)
2 rules 1 TTP 1 CVENo-Cms 1.0 is vulnerable to SQL injection (CVE-2018-25431) in the order_by parameter of the manage_privilege export endpoint, allowing authenticated attackers to manipulate database queries and potentially extract sensitive information.
CVE-2018-25430: Paroiciel 11.20 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEParoiciel 11.20 contains an SQL injection vulnerability (CVE-2018-25430) that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the eGeqIdEquipe parameter, potentially leading to sensitive data extraction.
CVE-2018-25429: Paroiciel 11.20 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEParoiciel 11.20 is vulnerable to SQL injection, allowing authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the zProIdPro parameter, potentially extracting sensitive database information.
CVE-2018-25428: Paroiciel 11.20 SQL Injection Vulnerability
1 rule 1 TTP 1 CVEParoiciel 11.20 is vulnerable to SQL injection, allowing unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter via GET requests to the trec.php endpoint, enabling attackers to extract sensitive database information.
Arm Whois 3.11 Stack-Based Buffer Overflow Vulnerability (CVE-2018-25427)
2 rules 1 TTP 1 CVEArm Whois 3.11 is vulnerable to a stack-based buffer overflow (CVE-2018-25427) allowing remote attackers to execute arbitrary code by providing oversized input to the IP address or domain field.
Red Hat npm Packages Compromised by Miasma Malware
2 rules 2 TTPsA supply chain attack compromised over 30 npm packages under Red Hat's '@redhat-cloud-services' namespace, distributing a credential-stealing malware variant named 'Miasma' that targets sensitive developer information.