Critical Gitea RCE CVE-2026-60004 Actively Exploited in Cryptojacking Campaign
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
HOSTKEY, a hosting provider, alerted a customer to excessive CPU usage on their virtual server, leading to the discovery of a cryptojacking…
A critical authentication bypass vulnerability in Apple macOS Screen Sharing, tracked as CVE-2026-65400 (CVSS 9.8), is being actively exploited in the wild…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
Threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow (CVSS 9.3), to deploy a Monero cryptocurrency…
Kinsing is a threat group known for cryptojacking operations, often deploying cryptocurrency miners on compromised systems. In this campaign, the Lambsys malware…
WatchDog is a threat group involved in cryptojacking, deploying miners on vulnerable systems. The Lambsys malware actively terminates WatchDog processes to maintain…
Rocke is a threat group associated with cryptocurrency mining malware. The Lambsys malware kills Rocke miner processes as part of its anti-competition…
Outlaw is a threat group known for cryptojacking activities. The Lambsys malware terminates Outlaw miner processes to eliminate rival operations.
Lambsys is a Go-based ELF executable used in cryptojacking campaigns targeting Langflow vulnerabilities. It terminates rival miners, disables security controls, establishes persistence,…