⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
ID: 2b1ef405-1fda-5a0b-a41b-4479831629c8
STIX ID: report--2b1ef405-1fda-5a0b-a41b-4479831629c8
Feed Name: The Hacker News
Weekly threat roundup: Multiple high-risk incidents and trends are reported — an on‑prem Microsoft Exchange XSS/spoofing vulnerability is under active exploitation, Cisco Catalyst SD‑WAN controllers are being exploited by a tracked actor (UAT-8616) for persistent access, and TeamPCP has expanded supply‑chain package poisoning to distribute stealers and harvest keys. Additional notable items include a malicious Hugging Face model delivering a Rust stealer, a ransomware/data-extortion case with Instructure, numerous high-severity CVEs cited for urgent patching, and commentary on AI accelerating vulnerability discovery and attacker speed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
