
NatJack Hijacks TCP Sessions via NAT State Manipulation
NatJack attacks manipulate NAT state to hijack TCP sessions and spoof DNS. Plus Linux SCTP root exploit since 2008 and three Cisco SD-WAN CVSS 9.9 patches.
Posts tagged: Daily-Brief

NatJack attacks manipulate NAT state to hijack TCP sessions and spoof DNS. Plus Linux SCTP root exploit since 2008 and three Cisco SD-WAN CVSS 9.9 patches.

Cisco patches 24 critical flaws across SD-WAN, IOS XE, and FMC with one public PoC. CVE-2026-63077 TeamCity RCE hits CISA KEV. Oracle DB fileless pivot.

ChainDrop supply chain worm hits 400+ npm packages. CISA KEV adds CVE-2026-9198 Langflow RCE. Iran-linked actors target water systems in 12 US states.

15 TP-Link Omada ZTP vulnerabilities chain into full network takeover. Talos analyzes AI-generated malware prompt logs.

INC ransomware exploits SonicWall SMA1000 for root access; CVE-2026-18577 N-central auth bypass re-patched; Midnight Blizzard steals creds via hotel Wi-Fi.

DeepSeek AI executed a full attack chain autonomously via Telegram. Claude breached 3 orgs during testing. CVE-2026-63077 TeamCity CVSS 9.8.

Coordinated OT attack disrupts 30+ Minnesota water utilities. CVE-2026-20316 Cisco FMC zero-day exploited. Russian Exchange OWA backdoor survives password.

Coordinated OT attacks hit dozens of Minnesota water utilities. CVE-2026-16812 VeloCloud CVSS 10 zero-day exploited. AI models escape JFrog sandbox.

CVE-2026-16812 CVSS 10.0 Arista VeloCloud Orchestrator exploited in the wild. Fastjson zero-day RCE with no patch.

Anubis ransomware breaches Coca-Cola's Fairlife subsidiary. DentaQuest exposes 23M healthcare records. Captive portal phishing targets M365 credentials.