{"source":"ctiaze.tech","description":"Azərbaycan dilində avtomatlaşdırılmış CTI feed. Son 100 dərc olunmuş xəbər.","generated_at":"2026-07-28T21:18:13.822Z","count":100,"items":[{"id":"url:efae5f08188a2723","title_az":"Hugging Face Diffusers-də 3 CVE: zərərli model repo kod icra edə bilir","title_en":"Bugs in Hugging Face Diffusers Bypass Custom Code Safeguard","url":"https://ctiaze.tech/xeber/efae5f08188a-hugging-face-diffusers-də-3-cve-zərərli-model-repo-kod-icra","source_url":"https://www.infosecurity-magazine.com/news/hugging-face-diffusers-trust/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T21:05:13.440Z"},{"id":"url:cfcaafc694e224a8","title_az":"Flying Eagle Android RAT: 170 server Hong Kong ASN-lərində aşkarlanıb","title_en":"Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs","url":"https://ctiaze.tech/xeber/cfcaafc694e2-flying-eagle-android-rat-170-server-hong-kong-asn-lərində-aş","source_url":"https://www.reddit.com/r/netsec/comments/1v95msb/flying_eagle_android_rat_tls_certificate_pivots/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T21:05:10.106Z"},{"id":"url:a2ecc15302d67fac","title_az":"24,000-dən çox internetə açıq server BMC-si 20 illik zəiflik ilə password hash sızdırır","title_en":"Over 24,000 exposed server BMCs leak password hash via decades-old flaw","url":"https://ctiaze.tech/xeber/a2ecc15302d6-24000-dən-çox-internetə-açıq-server-bmc-si-20-illik-zəiflik","source_url":"https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs-leak-password-hash-via-decades-old-flaw/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T21:05:06.796Z"},{"id":"url:baa66cf30cf55288","title_az":"Wordfence PRISM backdoor-lu WordPress plugin-ini 2 saata aşkarladı","title_en":"Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced","url":"https://ctiaze.tech/xeber/baa66cf30cf5-wordfence-prism-backdoor-lu-wordpress-plugin-ini-2-saata-aşk","source_url":"https://www.wordfence.com/blog/2026/07/wordfence-prism-detected-backdoored-wordpress-plugin-within-two-hours-of-it-being-introduced/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T21:05:03.433Z"},{"id":"url:7942bdf3bfc6aabf","title_az":"24,650 BMC interfeysi login-dən əvvəl IPMI password hash-larını açıq göstərir","title_en":"24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login","url":"https://ctiaze.tech/xeber/7942bdf3bfc6-24650-bmc-interfeysi-login-dən-əvvəl-ipmi-password-hash-ları","source_url":"https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T21:05:00.130Z"},{"id":"url:444f0bed861e7401","title_az":"Tengu botnet: proses öldürüləndə cihazı özü yenidən işə salır","title_en":"Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process","url":"https://ctiaze.tech/xeber/444f0bed861e-tengu-botnet-proses-öldürüləndə-cihazı-özü-yenidən-işə-salır","source_url":"https://thehackernews.com/2026/07/tengu-botnet-reboots-compromised-linux.html","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T21:04:56.763Z"},{"id":"url:282e58443f9213e0","title_az":"vBulletin-də kritik pre-auth RCE zəiflik aşkarlanıb, exploit artıq açıqdır","title_en":"vBulletin fixes critical pre-auth RCE flaw with public exploit","url":"https://ctiaze.tech/xeber/282e58443f92-vbulletin-də-kritik-pre-auth-rce-zəiflik-aşkarlanıb-exploit","source_url":"https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-flaw-with-public-exploit/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T19:18:57.579Z"},{"id":"cve:CVE-2024-1813","title_az":"CVE-2024-1813: Simple Job Board plagininde unauthenticated RCE","title_en":"Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)","url":"https://ctiaze.tech/xeber/CVE-2024-181-cve-2024-1813-simple-job-board-plagininde-unauthenticated-rc","source_url":"https://www.reddit.com/r/netsec/comments/1v8zh25/simple_job_board_2110_unauthenticated_rce/","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2024-1813"],"region_relevant":false,"published_at":"2026-07-28T19:18:54.220Z"},{"id":"url:3a4b6aa04cf7ef46","title_az":"AI köməyi ilə Linux kernel-in net/sched modulunda zero-day tapıldı","title_en":"AI-Assisted Bug Hunt Uncovers Linux Kernel 0-Day in net/sched","url":"https://ctiaze.tech/xeber/3a4b6aa04cf7-ai-köməyi-ilə-linux-kernel-in-netsched-modulunda-zero-day-ta","source_url":"https://www.infosecurity-magazine.com/news/ai-linux-kernel-zero-day-net-sched/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T19:18:50.680Z"},{"id":"url:8f0336f9fe6a6409","title_az":"24,650 BMC login-dan əvvəl IPMI hash-larını sızdırır","title_en":"‼️ 24,650 internet-exposed BMCs are leaking IPMI authentication hashes before login, giving attackers what they need to crack passwords offline. More than 30% matched recoverable passwords, including factory-issued credentials. Read what exposed servers need to lock down: https://thehackernews.com/2026/07/24650-internet-exposed-bmcs-disclose.html","url":"https://ctiaze.tech/xeber/8f0336f9fe6a-24650-bmc-login-dan-əvvəl-ipmi-hash-larını-sızdırır","source_url":"https://nitter.net/TheHackersNews/status/2082114402564898987#m","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T19:18:47.022Z"},{"id":"url:f131a7e2727f2da3","title_az":"⚠️ OpenWrt-də kritik pre-auth DHCPv6 zəifliyi router-i root hüquqları ilə ələ keçirməyə imkan verir","title_en":"⚠️ ALERT - OpenWrt users, this one needs attention. A critical pre-auth DHCPv6 flaw could let an attacker who can reach the service send a crafted request and run code as root on the router. A separate audit also found 7 more flaws, including three pre-auth paths to device compromise. What users need to update now: https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html","url":"https://ctiaze.tech/xeber/f131a7e2727f-openwrt-də-kritik-pre-auth-dhcpv6-zəifliyi-router-i-root-hüq","source_url":"https://nitter.net/TheHackersNews/status/2082088014805881307#m","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T19:18:43.508Z"},{"id":"url:fd252e1c9fae37bb","title_az":"BMC-lərdə köhnə IPMI 2.0 protokolu login-dən əvvəl password hash ötürür","title_en":"Exposed BMCs hand out password hashes before login","url":"https://ctiaze.tech/xeber/fd252e1c9fae-bmc-lərdə-köhnə-ipmi-20-protokolu-login-dən-əvvəl-password-h","source_url":"https://www.helpnetsecurity.com/2026/07/28/exposed-bmc-ipmi-vulnerability-research/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T19:18:40.142Z"},{"id":"url:19b30075d9385d62","title_az":"🚨 İran dövlət dəstəkli Nimbus Manticore ələ keçirilmiş sistemləri gizli relay-ə çevirir","title_en":"🚨 Iranian state-backed Nimbus Manticore is turning compromised systems into covert network relays. NightLedger executes commands, uploads files, and captures screenshots, while BridgeHead and ArcBridge tunnel traffic through victim networks. Read more: https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html","url":"https://ctiaze.tech/xeber/19b30075d938-iran-dövlət-dəstəkli-nimbus-manticore-ələ-keçirilmiş-sisteml","source_url":"https://nitter.net/TheHackersNews/status/2082073818005479899#m","category":"apt","severity":null,"kev":false,"cve_ids":[],"region_relevant":true,"published_at":"2026-07-28T16:05:43.045Z"},{"id":"url:b05aca282570c3a8","title_az":"Tibbi billing şirkəti MCBS-də data breach: 1.26 milyon nəfərin məlumatı sızıb","title_en":"Data breach at medical billing firm MCBS affects 1.26 million people","url":"https://ctiaze.tech/xeber/b05aca282570-tibbi-billing-şirkəti-mcbs-də-data-breach-126-milyon-nəfərin","source_url":"https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billing-firm-mcbs-affects-126-million-people/","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T16:05:39.611Z"},{"id":"url:5cf12354efd78a16","title_az":"Apple-dan iyul yeniləməsi: iPhone, iPad və Mac-ınızı indi update edin","title_en":"Update your iPhone, iPad and Mac to fix Apple security holes","url":"https://ctiaze.tech/xeber/5cf12354efd7-apple-dan-iyul-yeniləməsi-iphone-ipad-və-mac-ınızı-indi-upda","source_url":"https://www.malwarebytes.com/blog/news/2026/07/july-apple-updates-are-especially-important-if-you-receive-images","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T16:05:36.196Z"},{"id":"url:4f076dd92988f10c","title_az":"Microsoft AI-based təhdidlərə qarşı yeni təhlükəsizlik alətləri təqdim etdi","title_en":"Microsoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled Threats","url":"https://ctiaze.tech/xeber/4f076dd92988-microsoft-ai-based-təhdidlərə-qarşı-yeni-təhlükəsizlik-alətl","source_url":"https://www.infosecurity-magazine.com/news/microsoft-ai-security-initiatives/","category":"other","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T16:05:32.726Z"},{"id":"url:2093e327ec400c04","title_az":"Cisco Talos: phishing hələ də ən çox istifadə olunan ilkin giriş üsuludur","title_en":"Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques","url":"https://ctiaze.tech/xeber/2093e327ec40-cisco-talos-phishing-hələ-də-ən-çox-istifadə-olunan-ilkin-gi","source_url":"https://www.infosecurity-magazine.com/news/phishing-dominates-initial-entry/","category":"research","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T16:05:29.215Z"},{"id":"url:e2225af3b0449f38","title_az":"İran-bağlı Nimbus Manticore qrupu yeni NightLedger backdoor ilə hücum edir","title_en":"Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays","url":"https://ctiaze.tech/xeber/e2225af3b044-iran-bağlı-nimbus-manticore-qrupu-yeni-nightledger-backdoor","source_url":"https://thehackernews.com/2026/07/nimbus-manticore-deploys-nightledger.html","category":"apt","severity":null,"kev":false,"cve_ids":[],"region_relevant":true,"published_at":"2026-07-28T16:05:25.729Z"},{"id":"url:74a454e1f7fe3424","title_az":"JFrog: OpenAI modelləri Artifactory-dən sonra Hugging Face-i də hədəf alıb","title_en":"🔥 JFrog confirms OpenAI models exploited a zero-day in self-hosted \"Artifactory,\" escalated privileges, and moved laterally until they reached the open internet. From there, the models targeted #HuggingFace and obtained ExploitGym solutions from its production database via a separate attack path. Here's how it happened: https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html","url":"https://ctiaze.tech/xeber/74a454e1f7fe-jfrog-openai-modelləri-artifactory-dən-sonra-hugging-face-i","source_url":"https://nitter.net/TheHackersNews/status/2082098948777607622#m","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T13:57:28.471Z"},{"id":"cve:CVE-2026-53921","title_az":"⚠️ OpenWrt-də kritik DHCPv6 zəifliyi — root səviyyəsində RCE mümkündür","title_en":"Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root","url":"https://ctiaze.tech/xeber/CVE-2026-539-openwrt-də-kritik-dhcpv6-zəifliyi-root-səviyyəsində-rce-mümk","source_url":"https://thehackernews.com/2026/07/critical-openwrt-dhcpv6-flaw-could-let.html","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2026-53921"],"region_relevant":false,"published_at":"2026-07-28T13:57:25.019Z"},{"id":"cve:CVE-2013-4786","title_az":"20 illik CVE-2013-4786 zəifliyi minlərlə data mərkəzini bir neçə dəqiqəyə ələ keçirməyə imkan verib","title_en":"How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability","url":"https://ctiaze.tech/xeber/CVE-2013-478-20-illik-cve-2013-4786-zəifliyi-minlərlə-data-mərkəzini-bir","source_url":"https://www.reddit.com/r/netsec/comments/1v8ylt4/how_we_hacked_thousands_of_data_centers_in/","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2013-4786"],"region_relevant":false,"published_at":"2026-07-28T13:57:21.688Z"},{"id":"url:d22d44038d4f0fe5","title_az":"JFrog: OpenAI modelləri Artifactory-də zero-day istismar edib","title_en":"JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach","url":"https://ctiaze.tech/xeber/d22d44038d4f-jfrog-openai-modelləri-artifactory-də-zero-day-istismar-edib","source_url":"https://thehackernews.com/2026/07/jfrog-confirms-openai-models-exploited.html","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T13:57:18.144Z"},{"id":"url:36c773cd80adbaa7","title_az":"AWS Shield Advanced-də L7 avtomatik mitigation 1 yanvar 2027-də dayandırılır","title_en":"AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027","url":"https://ctiaze.tech/xeber/36c773cd80ad-aws-shield-advanced-də-l7-avtomatik-mitigation-1-yanvar-2027","source_url":"https://www.helpnetsecurity.com/2026/07/28/aws-waf-anti-ddos-rule-group/","category":"policy","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T13:57:14.807Z"},{"id":"cve:CVE-2026-53264","title_az":"⚠️ CVE-2026-53264: AI köməyi ilə Linux-da root exploit hazırlanıb","title_en":"🛑 A researcher says AI helped turn a #Linux traffic-control race into a root exploit. CVE-2026-53264 lets a local user gain root on the tested CentOS Stream 9 build, but needs user namespaces, specific kernel options, and build-specific ROP offsets. Read how the exploit works: https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html","url":"https://ctiaze.tech/xeber/CVE-2026-532-cve-2026-53264-ai-köməyi-ilə-linux-da-root-exploit-hazırlanı","source_url":"https://nitter.net/TheHackersNews/status/2082014830664597667#m","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2026-53264"],"region_relevant":false,"published_at":"2026-07-28T13:57:11.443Z"},{"id":"url:a82ac1eafa4cae07","title_az":"AutoIT: malware müəlliflərinin sevimli aləti","title_en":"AutoIT Payload Injector , (Tue, Jul 28th)","url":"https://ctiaze.tech/xeber/a82ac1eafa4c-autoit-malware-müəlliflərinin-sevimli-aləti","source_url":"https://isc.sans.edu/diary/rss/33192","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T10:32:18.947Z"},{"id":"url:03fe9294fdaca6c9","title_az":"Talos: 2026-cı ilin Q2-də phishing və RMM alətlərinin silaha çevrilməsi artıb","title_en":"IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains","url":"https://ctiaze.tech/xeber/03fe9294fdac-talos-2026-cı-ilin-q2-də-phishing-və-rmm-alətlərinin-silaha","source_url":"https://blog.talosintelligence.com/ir-trends-q2-2026/","category":"research","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T10:32:15.513Z"},{"id":"url:ad3a44de6ff63414","title_az":"Cruciferra: antivirusdan yayınmaq üçün yeni crypter-as-a-service","title_en":"New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide","url":"https://ctiaze.tech/xeber/ad3a44de6ff6-cruciferra-antivirusdan-yayınmaq-üçün-yeni-crypter-as-a-serv","source_url":"https://securityaffairs.com/196151/malware/new-crypter-as-a-service-cruciferra-fuels-stealthy-malware-attacks-worldwide.html","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T10:32:11.957Z"},{"id":"url:acf64765746b2c48","title_az":"Fastjson-da patch olunmamış boşluq artıq hücumlarda istifadə olunur","title_en":"Unpatched Fastjson Vulnerability Exploited in Attacks","url":"https://ctiaze.tech/xeber/acf64765746b-fastjson-da-patch-olunmamış-boşluq-artıq-hücumlarda-istifadə","source_url":"https://www.securityweek.com/unpatched-fastjson-vulnerability-exploited-in-attacks/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T10:32:08.438Z"},{"id":"url:5e198d339f662320","title_az":"Coca-Cola: Fairlife-a qarşı ransomware hücumunda data oğurlanıb","title_en":"Coca-Cola confirms hackers stole data in Fairlife ransomware attack","url":"https://ctiaze.tech/xeber/5e198d339f66-coca-cola-fairlife-a-qarşı-ransomware-hücumunda-data-oğurlan","source_url":"https://www.helpnetsecurity.com/2026/07/28/coca-cola-fairlife-dairy-subsidiary-ransomware-attack/","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T10:32:04.962Z"},{"id":"cve:CVE-2026-63077","title_az":"⚠️ TeamCity-də kritik boşluq: autentifikasiyasız RCE mümkündür","title_en":"JetBrains Patches Critical TeamCity Flaw Allowing Server Takeover","url":"https://ctiaze.tech/xeber/CVE-2026-630-teamcity-də-kritik-boşluq-autentifikasiyasız-rce-mümkündür","source_url":"https://nitter.net/TheHackersNews/status/2082020736546357397#m","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2026-63077"],"region_relevant":false,"published_at":"2026-07-28T10:32:01.406Z"},{"id":"url:825ca8ce1b25d177","title_az":"Origin Energy-də data breach: 900,000 avstraliyalının məlumatı sızıb","title_en":"Origin Energy Data Breach Affects 900,000 Australians","url":"https://ctiaze.tech/xeber/825ca8ce1b25-origin-energy-də-data-breach-900000-avstraliyalının-məlumatı","source_url":"https://www.securityweek.com/origin-energy-data-breach-affects-900000-australians/","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T06:24:14.386Z"},{"id":"url:f20533a203c3d4fe","title_az":"Shadow AI insidentlərində loglar araşdırma başlamazdan əvvəl yox olur","title_en":"Shadow AI incident response begins with logs that may already be gone","url":"https://ctiaze.tech/xeber/f20533a203c3-shadow-ai-insidentlərində-loglar-araşdırma-başlamazdan-əvvəl","source_url":"https://www.helpnetsecurity.com/2026/07/28/brandy-wityak-levelblue-shadow-ai-incident-response/","category":"research","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T06:24:10.988Z"},{"id":"url:ece7e205354215ba","title_az":"⚠️ Arista VeloCloud Orchestrator-da CVSS 10.0 zəiflik aktiv istismar olunur","title_en":"🚨 Attackers are exploiting a CVSS 10.0 command injection flaw in on-prem Arista VeloCloud Orchestrator. A successful exploit could compromise the orchestrator and give attackers access to managed Edge devices. CISA has ordered federal agencies to patch by July 30. Details: https://thehackernews.com/2026/07/attackers-exploit-arista-velocloud.html","url":"https://ctiaze.tech/xeber/ece7e2053542-arista-velocloud-orchestrator-da-cvss-100-zəiflik-aktiv-isti","source_url":"https://nitter.net/TheHackersNews/status/2081964073588285467#m","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T06:24:07.561Z"},{"id":"url:52745364d5a220ed","title_az":"AI agent Hermes vasitəsilə Tailandın Maliyyə Nazirliyinə casusluq hücumu","title_en":"AI Agent Drives Espionage Attack on Thai Ministry of Finance","url":"https://ctiaze.tech/xeber/52745364d5a2-ai-agent-hermes-vasitəsilə-tailandın-maliyyə-nazirliyinə-cas","source_url":"https://www.darkreading.com/cyberattacks-data-breaches/ai-agent-espionage-attack-thai-ministry-finance","category":"apt","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T02:08:23.232Z"},{"id":"url:868d586d629799ee","title_az":"Hakerlər FastJson-dakı zero-day ilə ABŞ şirkətlərinə hücum edir","title_en":"Hackers target US firms in FastJson RCE zero-day attacks","url":"https://ctiaze.tech/xeber/868d586d6297-hakerlər-fastjson-dakı-zero-day-ilə-abş-şirkətlərinə-hücum-e","source_url":"https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-day-attacks/","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-28T02:08:19.865Z"},{"id":"url:8830c194875eec1f","title_az":"Reuters: OpenAI-ın AI agenti Hugging Face-i həftələrlə hack edib, heç kim bilməyib","title_en":"Reuters: OpenAI Agent Hacked Hugging Face for Days Before Being Detected","url":"https://ctiaze.tech/xeber/8830c194875e-reuters-openai-ın-ai-agenti-hugging-face-i-həftələrlə-hack-e","source_url":"https://securityaffairs.com/196120/ai/reuters-openai-agent-hacked-hugging-face-for-days-before-being-detected.html","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T22:58:08.789Z"},{"id":"url:9fde653927265f83","title_az":"MedusaHVNC troyanı gizli desktop yaradıb browser-ləri ələ keçirir","title_en":"MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data","url":"https://ctiaze.tech/xeber/9fde65392726-medusahvnc-troyanı-gizli-desktop-yaradıb-browser-ləri-ələ-ke","source_url":"https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidden-desktops-to-hijack-browsers-and-steal-data.html","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:41:04.051Z"},{"id":"url:6d928a94e93b543e","title_az":"Thailand-ın Maliyyə Nazirliyinə qarşı avtonom AI agent ilə casusluq həyata keçirilib","title_en":"Hackers used autonomous AI agent to spy on Thailand's finance ministry","url":"https://ctiaze.tech/xeber/6d928a94e93b-thailand-ın-maliyyə-nazirliyinə-qarşı-avtonom-ai-agent-ilə-c","source_url":"https://therecord.media/thailand-hackers-ai-finance-ministry","category":"apt","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:28:41.567Z"},{"id":"url:2b189bc478294ba2","title_az":"Aftercall reklamları Android istifadəçilərini əldən salır","title_en":"Aftercall ads are driving Android users crazy","url":"https://ctiaze.tech/xeber/2b189bc47829-aftercall-reklamları-android-istifadəçilərini-əldən-salır","source_url":"https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:28:38.178Z"},{"id":"url:91fce1ccc332a612","title_az":"DentaQuest-də data breach 23 milyondan çox insanı təsirləndirib","title_en":"DentaQuest disclosed a data breach that impacted +23 million individuals","url":"https://ctiaze.tech/xeber/91fce1ccc332-dentaquest-də-data-breach-23-milyondan-çox-insanı-təsirləndi","source_url":"https://securityaffairs.com/196100/data-breach/dentaquest-disclosed-a-data-breach-that-impacted-23-million-individuals.html","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:28:34.813Z"},{"id":"url:46bf72e8fc829f21","title_az":"AnMed sağlamlıq sistemi malware hücumundan sonra ofislərini bağladı","title_en":"Health system in South Carolina, Georgia closes offices after malware affects networks","url":"https://ctiaze.tech/xeber/46bf72e8fc82-anmed-sağlamlıq-sistemi-malware-hücumundan-sonra-ofislərini","source_url":"https://therecord.media/health-system-south-carolina-georgia-disruptions-malware","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:28:31.497Z"},{"id":"url:dc5cc74fb1c45792","title_az":"Haker-lər hacklənmiş public Wi-Fi gateway-lərdən korporativ credential-ları oğurlayır","title_en":"Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials","url":"https://ctiaze.tech/xeber/dc5cc74fb1c4-haker-lər-hacklənmiş-public-wi-fi-gateway-lərdən-korporativ","source_url":"https://www.securityweek.com/hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials/","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:28:28.146Z"},{"id":"url:16ac7903dd7c9e2a","title_az":"Dysphoria botnet 200 min cihazı ələ keçirib, DDoS üçün istifadə edir","title_en":"New Dysphoria DDoS botnet spreads to 200k devices worldwide","url":"https://ctiaze.tech/xeber/16ac7903dd7c-dysphoria-botnet-200-min-cihazı-ələ-keçirib-ddos-üçün-istifa","source_url":"https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:25:51.099Z"},{"id":"cve:CVE-2026-61511","title_az":"CVE-2026-61511: vBulletin-də kritik pre-auth RCE aşkarlandı","title_en":"New vBulletin Vulnerability!","url":"https://ctiaze.tech/xeber/CVE-2026-615-cve-2026-61511-vbulletin-də-kritik-pre-auth-rce-aşkarlandı","source_url":"https://www.reddit.com/r/netsec/comments/1v8192k/new_vbulletin_vulnerability/","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2026-61511"],"region_relevant":false,"published_at":"2026-07-27T21:25:47.830Z"},{"id":"url:898c6b8dba0454b3","title_az":"⚠️ Operation BlueDash: saxta Microsoft Teams yeniləməsi eyni anda iki RMM alətini quraşdırır","title_en":"🛑 A fake Microsoft Teams update deploys two legitimate RMM tools on the same Windows host. Operation BlueDash installs Level RMM and ScreenConnect in parallel, apparently to retain remote access if one is removed. How the phishing chain works: https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html","url":"https://ctiaze.tech/xeber/898c6b8dba04-operation-bluedash-saxta-microsoft-teams-yeniləməsi-eyni-and","source_url":"https://nitter.net/TheHackersNews/status/2081720929017803065#m","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:25:44.557Z"},{"id":"url:da0468c2370557c2","title_az":"Dysphoria botnet-i C2 infrastrukturunu blockchain-ə köçürdü","title_en":"🚨 After law enforcement disrupted JackSkid, Dysphoria shifted its IoT botnet C2 to blockchain name services and infected-device relays. Weak Telnet and SSH passwords remain the main way in. Read how the botnet adapted: https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html","url":"https://ctiaze.tech/xeber/da0468c23705-dysphoria-botnet-i-c2-infrastrukturunu-blockchain-ə-köçürdü","source_url":"https://nitter.net/TheHackersNews/status/2081791591266824676#m","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:25:41.107Z"},{"id":"url:28f6b08a9fb8a220","title_az":"GitLab-da kritik RCE zənciri aşkarlandı — dərhal patch edin","title_en":"GitLab Users Urged to Patch After Research Reveals Critical RCE Chain","url":"https://ctiaze.tech/xeber/28f6b08a9fb8-gitlab-da-kritik-rce-zənciri-aşkarlandı-dərhal-patch-edin","source_url":"https://securityaffairs.com/196062/hacking/gitlab-users-urged-to-patch-after-research-reveals-critical-rce-chain.html","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:25:37.751Z"},{"id":"url:8fd9fc8b6af3c6b9","title_az":"Yeni AI hücumu klaviatura səslərindən yazılan mətni 90-99% dəqiqliklə bərpa edə bilir","title_en":"New AI attack can reconstruct typed text from keyboard sounds with 90-99% accuracy","url":"https://ctiaze.tech/xeber/8fd9fc8b6af3-yeni-ai-hücumu-klaviatura-səslərindən-yazılan-mətni-90-99-də","source_url":"https://www.reddit.com/r/cybersecurity/comments/1v8bsul/new_ai_attack_can_reconstruct_typed_text_from/","category":"research","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:25:34.432Z"},{"id":"url:000e1a41f42d9544","title_az":"GitHub və PyPI supply chain hücumlarına qarşı vaxt-əsaslı yeni müdafiə mexanizmi əlavə edib","title_en":"GitHub, PyPI add time-based defenses against supply chain attacks","url":"https://ctiaze.tech/xeber/000e1a41f42d-github-və-pypi-supply-chain-hücumlarına-qarşı-vaxt-əsaslı-ye","source_url":"https://www.reddit.com/r/cybersecurity/comments/1v8bz5w/github_pypi_add_timebased_defenses_against_supply/","category":"supply-chain","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:19:06.800Z"},{"id":"url:24874bcefdca0f29","title_az":"Google-da axtarış nəticələrində 70+ saxta sayt Windows 11 tətbiqləri adı ilə malware yayır","title_en":"Be careful downloading Windows 11 apps from Google, 70+ fake sites are pushing malware right now","url":"https://ctiaze.tech/xeber/24874bcefdca-google-da-axtarış-nəticələrində-70-saxta-sayt-windows-11-tət","source_url":"https://www.reddit.com/r/cybersecurity/comments/1v86m6s/be_careful_downloading_windows_11_apps_from/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:19:03.494Z"},{"id":"url:7b64233b8acac4db","title_az":"Google Cloud və Microsoft Azure-da 'Confused Deputy' zəiflikləri hələ də aradan qaldırılmayıb","title_en":"'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure","url":"https://ctiaze.tech/xeber/7b64233b8aca-google-cloud-və-microsoft-azure-da-confused-deputy-zəifliklə","source_url":"https://www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:19:00.179Z"},{"id":"url:2b717ab1a810e195","title_az":"Residential proxy botnet-lər böyüyən təhlükəyə çevrilir","title_en":"Inside the growing residential proxy botnet threat","url":"https://ctiaze.tech/xeber/2b717ab1a810-residential-proxy-botnet-lər-böyüyən-təhlükəyə-çevrilir","source_url":"https://www.reddit.com/r/blueteamsec/comments/1v893w5/inside_the_growing_residential_proxy_botnet_threat/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:18:56.913Z"},{"id":"url:caebd5b0b1455a54","title_az":"Vidar malware: Windows-da işləyən çoxaxınlı (multithreaded) stealer necə işləyir","title_en":"Vidar Malware: How the Multithreaded Windows Stealer Works","url":"https://ctiaze.tech/xeber/caebd5b0b145-vidar-malware-windows-da-işləyən-çoxaxınlı-multithreaded-ste","source_url":"https://www.reddit.com/r/blueteamsec/comments/1v879ug/vidar_malware_how_the_multithreaded_windows/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:18:53.591Z"},{"id":"url:2620031407cc6e95","title_az":"Claude Code-da Opus-5 ilə /init-dən RCE-yə: indirect prompt injection nümunəsi","title_en":"From /init to Code Execution with Opus-5 in Claude Code - An Indirect Prompt Injection Story","url":"https://ctiaze.tech/xeber/2620031407cc-claude-code-da-opus-5-ilə-init-dən-rce-yə-indirect-prompt-in","source_url":"https://www.reddit.com/r/blueteamsec/comments/1v84ba7/from_init_to_code_execution_with_opus5_in_claude/","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:18:50.119Z"},{"id":"url:a18ae72d1ac1ee93","title_az":"Telegram üzərindən fərdiləşdirilmiş phishing kampaniyası aktivist və istifadəçiləri hədəf alıb","title_en":"Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis","url":"https://ctiaze.tech/xeber/a18ae72d1ac1-telegram-üzərindən-fərdiləşdirilmiş-phishing-kampaniyası-akt","source_url":"https://therecord.media/telegram-belarus-activist-russia-cyberattack","category":"apt","severity":null,"kev":false,"cve_ids":[],"region_relevant":true,"published_at":"2026-07-27T21:11:28.234Z"},{"id":"url:f2ce61b68c01a016","title_az":"MedusaHVNC malware görünməz Windows desktop-larından istifadə edir","title_en":"MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection","url":"https://ctiaze.tech/xeber/f2ce61b68c01-medusahvnc-malware-görünməz-windows-desktop-larından-istifad","source_url":"https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:27.512Z"},{"id":"url:e75b60c9ee9032cb","title_az":"Helpdesk-i hədəf alan hücumçular: Teams vishing, Quick Assist və GoGRPC backdoor","title_en":"Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor","url":"https://ctiaze.tech/xeber/e75b60c9ee90-helpdesk-i-hədəf-alan-hücumçular-teams-vishing-quick-assist","source_url":"https://www.reddit.com/r/blueteamsec/comments/1v8791f/helpdesk_hijackers_teams_vishing_quick_assist_and/","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:26.868Z"},{"id":"url:c2c0f9a53ed3ac84","title_az":"Tədqiqatçılar Seedworm-a aid edilən MaaS aktivliyinə şübhə ilə yanaşır","title_en":"Really Muddy Waters — Refuting the Seedworm Attribution of Commodity MaaS","url":"https://ctiaze.tech/xeber/c2c0f9a53ed3-tədqiqatçılar-seedworm-a-aid-edilən-maas-aktivliyinə-şübhə-i","source_url":"https://www.reddit.com/r/blueteamsec/comments/1v8992i/really_muddy_waters_refuting_the_seedworm/","category":"research","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:26.471Z"},{"id":"cve:CVE-2026-64600","title_az":"CVE-2026-64600: XFS reflink race condition ilə local privilege escalation","title_en":"Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs","url":"https://ctiaze.tech/xeber/CVE-2026-646-cve-2026-64600-xfs-reflink-race-condition-ilə-local-privileg","source_url":"https://www.bleepingcomputer.com/news/linux/new-refluxfs-linux-flaw-lets-attackers-gain-root-privileges/","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2026-64600"],"region_relevant":false,"published_at":"2026-07-27T21:11:25.579Z"},{"id":"url:253e5c9215b540be","title_az":"Coca-Cola: Fairlife-a qarşı ransomware hücumunda data oğurlanıb","title_en":"Coca-Cola confirms data theft in Fairlife ransomware attack","url":"https://ctiaze.tech/xeber/253e5c9215b5-coca-cola-fairlife-a-qarşı-ransomware-hücumunda-data-oğurlan","source_url":"https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:21.475Z"},{"id":"url:d6836927f4a03744","title_az":"Volvo/Eicher-in flot idarəetmə platformasında bütün istifadəçilər və avtomobillər üzərində nəzarət mümkün olub","title_en":"Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles","url":"https://ctiaze.tech/xeber/d6836927f4a0-volvoeicher-in-flot-idarəetmə-platformasında-bütün-istifadəç","source_url":"https://www.reddit.com/r/netsec/comments/1v832a6/exploiting_volvoeichers_fleet_management_platform/","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:20.959Z"},{"id":"url:e6390d49b53f314e","title_az":"100 min istifadəçili Chrome extension AI prompt-larını gizli toplayır","title_en":"BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms","url":"https://ctiaze.tech/xeber/e6390d49b53f-100-min-istifadəçili-chrome-extension-ai-prompt-larını-gizli","source_url":"https://www.reddit.com/r/blueteamsec/comments/1v85dyf/braindrain_a_chrome_extension_that_collects_your/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:20.536Z"},{"id":"url:fd07d6d7a654776e","title_az":"ShinyHunters Ernst & Young-dan data breach-i öz üzərinə götürdü","title_en":"Ernst & Young data breach claimed by ShinyHunters extortion gang","url":"https://ctiaze.tech/xeber/fd07d6d7a654-shinyhunters-ernst-young-dan-data-breach-i-öz-üzərinə-götürd","source_url":"https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:19.724Z"},{"id":"url:05ee0e8e9ee1c153","title_az":"⚠️ PTC Windchill boşluğu ransomware kampaniyalarında istismar olunur","title_en":"PTC Windchill Vulnerability Exploited in Ransomware Campaign","url":"https://ctiaze.tech/xeber/05ee0e8e9ee1-ptc-windchill-boşluğu-ransomware-kampaniyalarında-istismar-o","source_url":"https://www.securityweek.com/ptc-windchill-vulnerability-exploited-in-ransomware-campaign/","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:13.169Z"},{"id":"url:26c71139d9544cbe","title_az":"OceanLotus/APT-C-00 kampaniyasına aid yeni indicator-lar tapılıb","title_en":"RT by @cyb3rops: Quick follow-up on the OceanLotus / APT-C-00 campaign from the recent 360 report - the one using disc-image delivery, Analyzer.exe DLL sideloading, and http://NTUSER.MAN persistence. We turned up more indicators tied to the same group, and both are barely detected: An ISO container (6/60) with the same anti-debug + long-sleep traits, seen via China on 2 Jun 2026. Billfish.rar (2/63), tagged persistence + anti-debug, seen via Japan on 24 Jul 2026 9130d7d2271e9cb118dd83907d9865cba547304a1f6c72743973efd59813df18 (ISO image) 0bae4acd83015b8447e90aec97efa2e81d136bfd512a69301d6187fed2e45c74 (Billfish.rar)","url":"https://ctiaze.tech/xeber/26c71139d954-oceanlotusapt-c-00-kampaniyasına-aid-yeni-indicator-lar-tapı","source_url":"https://nitter.net/nextronresearch/status/2081738627613114590#m","category":"apt","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:12.883Z"},{"id":"url:48fd37b241344fa1","title_az":"KB5014754 patch-i bypass edilərək AD CS-də Domain Admin əldə olunur","title_en":"The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS","url":"https://ctiaze.tech/xeber/48fd37b24134-kb5014754-patch-i-bypass-edilərək-ad-cs-də-domain-admin-əldə","source_url":"https://www.reddit.com/r/blueteamsec/comments/1v896ql/the_sid_that_wasnt_there_bypassing_kb5014754_to/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:12.571Z"},{"id":"url:bd11017f18adc25f","title_az":"Dysphoria IoT botnet-i blockchain-based C2-yə keçib","title_en":"Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption","url":"https://ctiaze.tech/xeber/bd11017f18ad-dysphoria-iot-botnet-i-blockchain-based-c2-yə-keçib","source_url":"https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:12.205Z"},{"id":"url:2f8c103cea2a19a4","title_az":"Lynx ransomware hücumçuları Veeam backup-larını silib","title_en":"RDP bitmap cache artifacts revealed the threat actor opening the Veeam Backup & Replication console, reviewing backup jobs, tape & storage infrastructure — and removing backups from the configuration database. Full report 👇 https://thedfirreport.com/2025/12/17/cats-got-your-files-lynx-ransomware/","url":"https://ctiaze.tech/xeber/2f8c103cea2a-lynx-ransomware-hücumçuları-veeam-backup-larını-silib","source_url":"https://nitter.net/TheDFIRReport/status/2081715012171641045#m","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:11.931Z"},{"id":"url:9693ae395f0e939a","title_az":"⚠️ Xəbərdarlıq: vBulletin üçün public PoC - bir sorğu ilə kod icrası mümkündür","title_en":"RT by @TheHackersNews: 🛑 WARNING - Public PoC released for a vBulletin flaw that turns one unauthenticated request into code execution. No login, no click. The request reaches PHP’s eval(). Self-hosted admins should update now. Details: https://thehackernews.com/2026/07/public-exploit-released-for-patched.html","url":"https://ctiaze.tech/xeber/9693ae395f0e-xəbərdarlıq-vbulletin-üçün-public-poc---bir-sorğu-ilə-kod-ic","source_url":"https://nitter.net/TheHackersNews/status/2081753483259335139#m","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:08.486Z"},{"id":"url:9225e457d46e6a3f","title_az":"Certighost: Windows domenini ələ keçirməyə imkan verən yeni PoC exploit","title_en":"New Certighost PoC exploit lets attackers hijack Windows domains","url":"https://ctiaze.tech/xeber/9225e457d46e-certighost-windows-domenini-ələ-keçirməyə-imkan-verən-yeni-p","source_url":"https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:08.173Z"},{"id":"url:a9e928fac27f6b39","title_az":"vBulletin-in patch olunmuş pre-auth RCE zəifliyi üçün public exploit yayıldı","title_en":"Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw","url":"https://ctiaze.tech/xeber/a9e928fac27f-vbulletin-in-patch-olunmuş-pre-auth-rce-zəifliyi-üçün-public","source_url":"https://thehackernews.com/2026/07/public-exploit-released-for-patched.html","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T21:11:07.861Z"},{"id":"cve:CVE-2026-16812","title_az":"Arista VeloCloud Orchestrator-da kritik OS command injection - KEV siyahısında","title_en":"Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw","url":"https://ctiaze.tech/xeber/CVE-2026-168-arista-velocloud-orchestrator-da-kritik-os-command-injection","source_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16812","category":"vuln","severity":null,"kev":true,"cve_ids":["CVE-2026-16812"],"region_relevant":false,"published_at":"2026-07-27T21:11:07.531Z"},{"id":"cve:CVE-2025-68686","title_az":"Fortinet FortiOS-da CVE-2025-68686 aşkarlandı - artıq KEV siyahısında","title_en":"U.S. CISA adds Arista VeloCloud Orchestrator and Fortinet FortiOS flaws to its Known Exploited Vulnerabilities catalog","url":"https://ctiaze.tech/xeber/CVE-2025-686-fortinet-fortios-da-cve-2025-68686-aşkarlandı---artıq-kev-si","source_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68686","category":"vuln","severity":null,"kev":true,"cve_ids":["CVE-2025-68686"],"region_relevant":false,"published_at":"2026-07-27T21:11:05.803Z"},{"id":"url:412f2204e5464ce0","title_az":"Spring Boot-un /actuator/heapdump endpoint-inə qarşı skan aktivliyi müşahidə olunur","title_en":"Java Spring Boot \"heapdump\" scans, (Mon, Jul 27th)","url":"https://ctiaze.tech/xeber/412f2204e546-spring-boot-un-actuatorheapdump-endpoint-inə-qarşı-skan-akti","source_url":"https://isc.sans.edu/diary/rss/33188","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T10:48:24.094Z"},{"id":"url:bc014d7853cf97eb","title_az":"Dependabot yeniləmələrində 3 günlük gecikmə: poisoned package riskini azaldan addım","title_en":"⚡ A poisoned package can land in a Dependabot update PR before registries remove it. GitHub is adding a 3-day cooldown for routine version updates, while security fixes will still move immediately. Why three days, and what the delay cannot stop: https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html","url":"https://ctiaze.tech/xeber/bc014d7853cf-dependabot-yeniləmələrində-3-günlük-gecikmə-poisoned-package","source_url":"https://nitter.net/TheHackersNews/status/2081652559492915607#m","category":"supply-chain","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T10:48:23.653Z"},{"id":"url:b1809b7e17b9eb1b","title_az":"GitHub Dependabot-a 3 günlük cooldown əlavə edir","title_en":"GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption","url":"https://ctiaze.tech/xeber/b1809b7e17b9-github-dependabot-a-3-günlük-cooldown-əlavə-edir","source_url":"https://thehackernews.com/2026/07/github-adds-3-day-dependabot-cooldown.html","category":"supply-chain","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T10:48:23.257Z"},{"id":"cve:CVE-2026-54121","title_az":"CertiGhost: AD CS-də sadə domain user-i domain admin-ə çevirən boşluq (CVE-2026-54121)","title_en":"Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS). An authenticated, low-privileged attacker with network access could manipulate certificate enrollment to impersonate a Domain Controller, potentially enabling privileged operations and full domain compromise. Exploitation requires no administrative privileges or user interaction, but does require network access and a valid domain account. The publication of proof-of-concept code increases the likelihood of exploitation attempts, so we recommend customers prioritize installing the July 2026 security update as soon as possible. Microsoft has observed researcher testing activity but has not confirmed active exploitation by threat actors. In response to these early signs of activity, we are sharing detection and hunting guidance to help defenders identify potential exploitation attempts, particularly in environments where the security update has not yet been applied. Microsoft Defender detects malicious certificate requests associated with this vulnerability and generates the alert: - “Potential Certighost (CVE-2026-54121) AD CS abuse.” - \"Active Directory Certificate Services attack tool activity \" Other alerts, including the following, may also appear during the attack chain. These signals support investigation but are not independently specific to Certighost. - Security principal reconnaissance (LDAP) - Suspicious Active Directory Certificate Services abuse tool activity - Suspected suspicious Kerberos ticket request - DCSync attack (replication of directory services) Customers should apply the July 14, 2026 security update to every server running an Enterprise Certification Authority (CA). The security update provides the primary protection by validating the enrollment chase target before the CA contacts it, preventing invalid or attacker-controlled systems from influencing certificate issuance. Customers who can't apply the July 14, 2026 security update immediately for all affected servers, should consider configuring the following audit logs to enable the mentioned detections and forensic: - Enable Certification Services auditing for both successful and failed operations. - Configure the CA audit filter to capture certificate lifecycle activity. - Monitor Security events 4886 and 4887 for anomalous certificate requests and issuance. - Investigate certificates requested through machine templates that contain unexpected Domain Controller identity information.","url":"https://ctiaze.tech/xeber/CVE-2026-541-certighost-ad-cs-də-sadə-domain-user-i-domain-admin-ə-çevirə","source_url":"https://nitter.net/aniqfakhrul/status/2080502257808756811#m","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2026-54121"],"region_relevant":false,"published_at":"2026-07-27T10:48:22.888Z"},{"id":"url:86965e6ed0b8177a","title_az":"ExfilSquad ransomware qrupu Wesco International-ı leak saytında yerləşdirib","title_en":"Ransomware: ExfilSquad → Wesco International","url":"https://ctiaze.tech/xeber/86965e6ed0b8-exfilsquad-ransomware-qrupu-wesco-international-ı-leak-saytı","source_url":"wesco.com","category":"ransomware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T07:00:19.048Z"},{"id":"url:733af3862c68eaec","title_az":"MCBS-da data breach 1.2 milyon insanın məlumatına təsir edib","title_en":"MCBS Data Breach Affects 1.2 Million Individuals","url":"https://ctiaze.tech/xeber/733af3862c68-mcbs-da-data-breach-12-milyon-insanın-məlumatına-təsir-edib","source_url":"https://www.securityweek.com/mcbs-data-breach-affects-1-2-million-individuals/","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T07:00:14.690Z"},{"id":"url:fa3b688fbf573592","title_az":"Nono: AI agent-ləri üçün açıq mənbəli sandbox","title_en":"Nono: Open-source sandbox for AI agents","url":"https://ctiaze.tech/xeber/fa3b688fbf57-nono-ai-agent-ləri-üçün-açıq-mənbəli-sandbox","source_url":"https://www.helpnetsecurity.com/2026/07/27/nono-open-source-ai-agent-sandboxing/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T07:00:14.365Z"},{"id":"url:2dbc545698baea37","title_az":"Google Ads-dən terminala: Apple Support-u təqlid edən kampaniya Claude Share-dan istifadə edib","title_en":"From Google Ads to Terminal: Dissecting an Apple Support Impersonation Campaign Abusing Claude Share.","url":"https://ctiaze.tech/xeber/2dbc545698ba-google-ads-dən-terminala-apple-support-u-təqlid-edən-kampani","source_url":"https://www.reddit.com/r/netsec/comments/1v7s9hw/from_google_ads_to_terminal_dissecting_an_apple/","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T07:00:14.057Z"},{"id":"url:1915476011cf031b","title_az":"GitHub yeniləmələri gecikdirir ki, malware əvvəlcədən tutulsun","title_en":"GitHub delays version updates so malware gets caught first","url":"https://ctiaze.tech/xeber/1915476011cf-github-yeniləmələri-gecikdirir-ki-malware-əvvəlcədən-tutulsu","source_url":"https://www.helpnetsecurity.com/2026/07/27/github-dependabot-cooldown/","category":"research","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T07:00:13.615Z"},{"id":"url:bfa277bfc0894daf","title_az":"Marathon Petroleum-un CISO-su: OT təhlükəsizliyi və supply chain riskləri","title_en":"Marathon Petroleum’s CISO on OT security automation, supply chain risk","url":"https://ctiaze.tech/xeber/bfa277bfc089-marathon-petroleum-un-ciso-su-ot-təhlükəsizliyi-və-supply-ch","source_url":"https://www.helpnetsecurity.com/2026/07/27/mary-rose-martinez-marathon-petroleum-ot-security-automation/","category":"policy","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-27T07:00:13.296Z"},{"id":"url:307c599a2ae3d7ed","title_az":"Hotel Wi-Fi-də DNS poisoning ilə Microsoft 365 hesabları oğurlanır","title_en":"RT by @cyb3rops: Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/","url":"https://ctiaze.tech/xeber/307c599a2ae3-hotel-wi-fi-də-dns-poisoning-ilə-microsoft-365-hesabları-oğu","source_url":"https://nitter.net/Dinosn/status/2081262815751393430#m","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T22:56:53.348Z"},{"id":"cve:CVE-2026-12877","title_az":"CVE-2026-12877: WordPress plugin-də SQL injection zəifliyi aşkarlanıb","title_en":"CVE-2026-12877: The Project Management, Bug and Issue Tracking Plugin  WordPress plugin before 5.1.0 does ","url":"https://ctiaze.tech/xeber/CVE-2026-128-cve-2026-12877-wordpress-plugin-də-sql-injection-zəifliyi-aş","source_url":"https://wpscan.com/vulnerability/e9d0ea92-1046-457b-9619-38b61848e36a/","category":"vuln","severity":null,"kev":false,"cve_ids":["CVE-2026-12877"],"region_relevant":false,"published_at":"2026-07-26T22:56:53.047Z"},{"id":"url:f4e31b4a7c201505","title_az":"Deadlock ransomware qrupu Caspian One-u qurban kimi elan edib","title_en":"Ransomware: Deadlock → Caspian One","url":"https://ctiaze.tech/xeber/f4e31b4a7c20-deadlock-ransomware-qrupu-caspian-one-u-qurban-kimi-elan-edi","source_url":"www.caspianone.com","category":"ransomware","severity":null,"kev":false,"cve_ids":[],"region_relevant":true,"published_at":"2026-07-26T20:53:49.944Z"},{"id":"url:3a48f8e58621fa27","title_az":"Fransa Rusiyanın gizli kiber-casusluq şəbəkəsini ifşa edib","title_en":"RT by @cyb3rops: France Exposes Russia's Secret Cyber Espionage Network https://www.unredacted.info/russia/france-exposes-russias-secret-cyber-espionage-network/","url":"https://ctiaze.tech/xeber/3a48f8e58621-fransa-rusiyanın-gizli-kiber-casusluq-şəbəkəsini-ifşa-edib","source_url":"https://nitter.net/Dinosn/status/2081264108582699240#m","category":"apt","severity":null,"kev":false,"cve_ids":[],"region_relevant":true,"published_at":"2026-07-26T20:53:49.648Z"},{"id":"url:0639f1a7a6b2ed01","title_az":"Torrent filmi kimi yayılan .exe əslində Lumma Stealer imiş","title_en":"> free time today > what was bro doing with a torrent movie .exe > download > 1gb .exe > lmfao binary inflation > bonk bonk > remove junk > deflate binary > 500kb > bonk bonk > no imports > crt stripped > position independent > checks language > kills self if in belarus or russia > runs 2000 random functions in random order > trying to stall to evade VMs > decrypts .exe from inside itself > runs mystery .exe in memory > .exe steals goop off machine > bonk bonk > yara flags as lumma stealer overall this wasnt the greatest goop ive ever seen, but i was a big fan of free_movie.exe. its a certified limewire 2002 classic. inflated binary: e25ae92b95809ee42f61810a0253ead29b3a6aa8adf91f785c80c9bec5f38bd8 stripped binary: 732d7a945163a3f31eae25028562bd5d9a352c31eb90c777042bceeeb1c6b3ec in-memory payload (partially reconstructed): 3e561eecde0071766626d80d6ce3cf1626fb2dbed0ef437948f622c283a0e91e c2: overcjo(.)cyou betavmt(.)cyou hiatuft(.)cyou auditva(.)cyou","url":"https://ctiaze.tech/xeber/0639f1a7a6b2-torrent-filmi-kimi-yayılan-exe-əslində-lumma-stealer-imiş","source_url":"https://nitter.net/vxunderground/status/2081436506237841643#m","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T19:17:55.637Z"},{"id":"url:a97f6090fb5c14d1","title_az":"ESAFENET CDG 3 sistemində zəif login-lərə görə skan aktivliyi artıb","title_en":"Scans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)","url":"https://ctiaze.tech/xeber/a97f6090fb5c-esafenet-cdg-3-sistemində-zəif-login-lərə-görə-skan-aktivliy","source_url":"https://isc.sans.edu/diary/rss/33184","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T16:55:01.032Z"},{"id":"url:2697dc06420410d6","title_az":"GitHub və PyPI Dependabot-a supply chain hücumlarına qarşı vaxt əsaslı müdafiə əlavə edib","title_en":"GitHub, PyPI add time-based defenses against supply chain attacks","url":"https://ctiaze.tech/xeber/2697dc064204-github-və-pypi-dependabot-a-supply-chain-hücumlarına-qarşı-v","source_url":"https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/","category":"supply-chain","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T15:01:37.387Z"},{"id":"url:c85de0f06abfa575","title_az":"Hacker-lər hotel Wi-Fi-larını ələ keçirib Microsoft 365 credential-larını oğurlayır","title_en":"Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials","url":"https://ctiaze.tech/xeber/c85de0f06abf-hacker-lər-hotel-wi-fi-larını-ələ-keçirib-microsoft-365-cred","source_url":"https://securityaffairs.com/196017/security/hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-credentials.html","category":"breach","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T15:01:36.980Z"},{"id":"url:2de9878dcba3f8be","title_az":"Bit2Watt: cloud tenant enerji şəbəkəsini çökərdə bilərmi?","title_en":"Can a cloud tenant really black out the power grid? We asked the Bit2Watt researchers. Their answer 🠒 the scariest result only works if thousands of GPUs spike their power at the same instant, and in reality they never line up that cleanly, which blunts the attack. Also notable: they didn't warn any cloud provider first, because there's no product bug to patch. Read: https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html","url":"https://ctiaze.tech/xeber/2de9878dcba3-bit2watt-cloud-tenant-enerji-şəbəkəsini-çökərdə-bilərmi","source_url":"https://nitter.net/TheHackersNews/status/2081305020335865969#m","category":"research","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T11:17:25.940Z"},{"id":"url:31312317ad9d2b0c","title_az":"ExfilSquad ransomware qrupu Microsoft-u leak site-ında qeyd edib","title_en":"Ransomware: ExfilSquad → Microsoft","url":"https://ctiaze.tech/xeber/31312317ad9d-exfilsquad-ransomware-qrupu-microsoft-u-leak-site-ında-qeyd","source_url":"microsoft.com","category":"ransomware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T11:17:25.628Z"},{"id":"cve:CVE-2026-42533","title_az":"NGINX-də güclü RCE bug-ı: PoC açıq mənbə oldu (CVE-2026-42533)","title_en":"🚨 UPDATE - Public PoC exploit released for CVE-2026-42533, chaining an #nginx memory leak and heap overflow to bypass ASLR and achieve unauthenticated command execution. Read: https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html","url":"https://ctiaze.tech/xeber/CVE-2026-425-nginx-də-güclü-rce-bug-ı-poc-açıq-mənbə-oldu-cve-2026-42533","source_url":"https://nitter.net/Markak_/status/2080832510838337940#m","category":"exploit","severity":null,"kev":false,"cve_ids":["CVE-2026-42533","CVE-2026-42530"],"region_relevant":false,"published_at":"2026-07-26T08:59:30.690Z"},{"id":"url:870742b306adb92b","title_az":"🚨 GitLab-da RCE PoC yayımlandı: authenticated user git user kimi kod işlədə bilir","title_en":"RT by @TheHackersNews: 🚨 A public GitLab RCE PoC lets an authenticated user run commands as the git user on an unpatched 18.11.3 server. No admin rights, CI runner access, victim interaction, or access to another user’s project. See how the notebook-diff chain works: https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html","url":"https://ctiaze.tech/xeber/870742b306ad-gitlab-da-rce-poc-yayımlandı-authenticated-user-git-user-kim","source_url":"https://nitter.net/TheHackersNews/status/2080935864402911627#m","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T08:57:23.095Z"},{"id":"url:2854d2b0f472796c","title_az":"Rockwell Arena Simulation Software-də code execution boşluqları bağlandı","title_en":"Rockwell Patches Code Execution Flaws in Arena Simulation Software","url":"https://ctiaze.tech/xeber/2854d2b0f472-rockwell-arena-simulation-software-də-code-execution-boşluql","source_url":"https://www.securityweek.com/rockwell-patches-code-execution-flaws-in-arena-simulation-software/","category":"vuln","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T08:56:15.491Z"},{"id":"url:e4420d62b7ee27c9","title_az":"SourTrade: brauzer özü zərərli faylı yığır","title_en":"Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable","url":"https://ctiaze.tech/xeber/e4420d62b7ee-sourtrade-brauzer-özü-zərərli-faylı-yığır","source_url":"https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T08:56:14.896Z"},{"id":"url:4551d9bde2dfa754","title_az":"DevMan ransomware RaaS-ı artıq tam affiliate portalına malikdir","title_en":"⚠️ DevMan RaaS now runs a full affiliate portal. Experts (tracking it as Funky Mantis) say the platform handles payload builds, victim records, chat, teams, support, and payouts in one place. Affiliates get structured workflows, deadlines, and an 80/20 cut. 184 victims claimed so far. Read: https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html","url":"https://ctiaze.tech/xeber/4551d9bde2df-devman-ransomware-raas-ı-artıq-tam-affiliate-portalına-malik","source_url":"https://nitter.net/TheHackersNews/status/2080958590936871366#m","category":"ransomware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T08:56:10.415Z"},{"id":"url:b463f9683716c700","title_az":"SourTrade malvertising: malware parça-parça göndərilir, brauzer özü yığır","title_en":"RT by @TheHackersNews: 🚨 The malware arrives in pieces. The victim’s browser puts it together. SourTrade malvertising delivers a legitimate Bun runtime, malicious bytecode, and PE components separately, then uses the browser to build the final Windows executable with a different hash each session. See how the browser-assembled malware chain works: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html","url":"https://ctiaze.tech/xeber/b463f9683716-sourtrade-malvertising-malware-parça-parça-göndərilir-brauze","source_url":"https://nitter.net/TheHackersNews/status/2081089670923051127#m","category":"malware","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T08:56:10.137Z"},{"id":"url:79b43370c9df2205","title_az":"GitLab-da default konfiqurasiyada RCE tapıldı","title_en":"RT by @cyb3rops: We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or application-logic layers. This time, guided by the @depthfirstlabs spirit, we went deeper: into the low-level gem dependency chain beneath GitLab. The result? By sending crafted JSON data, we could exploit memory-corruption vulnerabilities buried deep in that chain and take control of the GitLab application server. @depthfirstlabs brings together some of the smartest people, and is building the best security AI agent. Follow our work, and come join us! Read more about this in the comment...","url":"https://ctiaze.tech/xeber/79b43370c9df-gitlab-da-default-konfiqurasiyada-rce-tapıldı","source_url":"https://nitter.net/wupco1996/status/2080763568044290535#m","category":"exploit","severity":null,"kev":false,"cve_ids":[],"region_relevant":false,"published_at":"2026-07-26T08:56:09.843Z"}]}