NGINX RCE, Windows crypto-stealer, Salesforce breaches, INC ransomware surge
ID: bcfac4ea-23d3-5e42-bfe8-e3e1f8878ca6
STIX ID: report--bcfac4ea-23d3-5e42-bfe8-e3e1f8878ca6
Feed Name: defend.network – Daily Threat Briefings
F5 released patches for a critical NGINX RCE (CVE-2026-42530); Microsoft disclosed an active Windows clipboard‑stealing campaign that spreads via USB LNK worms and uses Tor-based C2; INC ransomware claims 830+ victims while Gentlemen develops EDR-evasion tools; and a Klue OAuth compromise enabled Salesforce data theft—urgent actions include applying patches, rotating/revoking OAuth tokens, strengthening EDR and remote access controls, and monitoring/blocking Tor C2 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
