Skip to content

Home/Digest/Past issues

Daily digest,

Urgent CVE-2021-3199 Vulnerability in ONLYOFFICE Exploited in the Wild (+7 more)

Vulnerabilities

Urgent CVE-2021-3199 Vulnerability in ONLYOFFICE Exploited in the Wild

A vulnerability, CVE-2021-3199, has been identified in ONLYOFFICE Document Server versions prior to 5.6.3, allowing remote code execution through a path traversal flaw when using JWT. Exploitation is confirmed in the wild, with attackers able to manipulate image upload parameters to gain unauthorized control over the document-processing service. This vulnerability poses a high risk as it can lead to complete system compromise, affecting organizations with internet-accessible collaborative document services. The issue was added to the CISA KEV catalog on 2026-10-08, indicating active exploitation. Users are advised to upgrade to version 5.6.3 or later immediately. Until then, restricting access to upload endpoints and validating upload paths is recommended.

Vulnerability · 2 sources · score 73 · CVE-2021-3199

Vulnerabilities Found in Apache HTTP Server

Multiple vulnerabilities have been identified in Apache HTTP Server, affecting versions prior to 2.4.69. Attackers can exploit these vulnerabilities to execute arbitrary code, bypass security restrictions, and cause denial of service. The vulnerabilities include remote code execution flaws in mod_rewrite and mod_http2, as well as denial of service issues in various components. Public exploits for these vulnerabilities exist, increasing the urgency for updates. Apache has released version 2.4.69 to address these issues. Security professionals are advised to apply the patch immediately to mitigate risks. The vulnerabilities are cataloged under several CVEs, including CVE-2026-46729 and CVE-2026-56153, which are classified as.

Vulnerability · 2 sources · score 70 · CVE-2026-42356, CVE-2026-42528, CVE-2026-46729, CVE-2026-47360, CVE-2026-48005

High-Severity Vulnerability Exposes Thousands of NVIDIA GPUs

Researchers discovered that thousands of NVIDIA DCGM Exporter monitoring endpoints are exposed to the public internet, allowing unauthorized access to GPU metrics. This exposure affects over 2,100 GPU servers and reveals telemetry from more than 12,000 GPUs, including high-value models like H100s and H200s. A vulnerability, CVE-2026-47483, with a CVSS score of 8.2, allows unauthenticated attackers to exhaust server resources and disrupt AI workloads. NVIDIA has patched this vulnerability in version 4.8.2 of the DCGM Exporter following responsible disclosure. The findings indicate that 60% of the exposed GPUs reported 0% utilization, raising concerns about potential misconfigurations. Full details of the research were submitted by an user on Reddit.

Vulnerability · 2 sources · score 58 · CVE-2026-47483

Breaches

Data Breach at St Andrew's Hospital Exposes Sensitive Patient Information

St Andrew's Hospital in Adelaide has confirmed a significant data breach affecting sensitive patient information. The breach involved unauthorized access to personal and medical data, including full names, addresses, email accounts, dates of birth, Medicare card numbers, and healthcare identifiers. The hospital has notified affected individuals and is working with federal privacy and cybersecurity agencies, including the Office of the Australian Information Commissioner and the Australian Cyber Security Centre. CEO Angela McCabe stated that the investigation has progressed to a point where direct communication with affected patients is necessary. South Australian Premier Peter Malinauskas has demanded transparency regarding the incident and is expecting updates on potential criminal implications. The exact number of individuals affected remains unclear, and forensic investigations are ongoing to determine the breach's full scope.

Breach · 2 sources · score 58

DriveWealth Data Breach Affects Over 2.5 Million Texans

DriveWealth, a New York-based fintech provider, reported a data breach that compromised the personal information of over 2.5 million Texas residents between September 4 and 5, 2026. The breach involved unauthorized access to sensitive data, including names and Social Security numbers, but no financial information or passwords were accessed. DriveWealth has launched an investigation with external cybersecurity experts and has notified the Texas Attorney General about the incident. The company stated that it has not observed any unauthorized brokerage account activity and is actively monitoring for suspicious activities. Affected individuals are advised to monitor their credit reports and report any unusual activity. This incident follows a previous breach involving DriveWealth's client, Revolut, which also exposed U.S. customer data.

Breach · 2 sources · score 55

Desert Orthopaedic Center Data Breach Exposes Sensitive Patient Information

Desert Orthopaedic Center (DOC) reported a data breach that may have exposed sensitive patient information, including Social Security numbers and medical records. The breach was discovered on August 7, 2026, and a public notice was posted on October 6, 2026. The investigation revealed that unauthorized access to patient data may have occurred, but the full scope of the breach is still under review. Affected individuals will be notified by mail once the investigation is complete. DOC is also offering complimentary credit monitoring and identity protection services to those impacted. The breach affects patients across multiple locations in southern Nevada.

Breach · 2 sources · score 51

Threat actors and malware

Malware Preinstalled on Thousands of Cheap Android Phones

Bitdefender has identified a malware campaign named Midnight Mimosa affecting low-cost Android phones built on MediaTek platforms. The malware is preinstalled in the firmware, granting it system-level access to install and remove applications without user consent. It primarily generates revenue through ad fraud and can turn infected devices into botnets. The malware has been observed on thousands of devices across over 150 countries, with significant detections in Mexico, France, and Italy. Notably, the malware can disable the Google Play Store temporarily to evade detection during payload installation. Researchers found at least 32 disguised applications associated with the malware, which utilize legitimate advertising services to generate fake ad impressions. The campaign raises concerns about the security of low-cost smartphones, especially counterfeit devices resembling popular brands. Currently, the malware cannot be uninstalled by users, leaving them vulnerable.

Malware · 6 sources · score 59 · Midnight Mimosa

Cyber and Physical Threats Loom Over Nigeria's 2027 Elections

Nigeria's upcoming 2027 elections face significant risks from both physical and cyber threats. An average of 700 people are killed and 500 abducted monthly due to violence from various groups, while the country experiences approximately 4,906 cyberattacks per organization weekly, more than double the global average. The Independent National Electoral Commission's ability to conduct free and fair elections is at stake if these threats are not adequately addressed. With a 45% year-on-year increase in cyberattacks, Nigeria is second only to Angola in Africa for cyber threats. Economic damages from cybercrime reached at least $5 billion in 2025, with substantial losses reported in the banking sector. Ransomware incidents also surged, with 5,822 detections in 2025, including a notable attack on the Nigeria Customs Service. The convergence of physical and cyber defenses is deemed critical for election security.

APT · 2 sources · score 52 · Sidewinder, UNC2814/GRIDTIDE, UNC2814/GRIDTIDE Campaign

New on leak sites

27 victims listed on ransomware leak sites by 10 groups in the 24 hours before this issue. The most active:

Also moving

  • APT groups: ShinyHunters, Sandworm, Uac-0099
  • Campaigns: ChainDrop, PolinRider, Anthropic Cyber Mission, Black Sea Grain Initiative, Contagious Interview
  • CVEs: CVE-2026-102489, CVE-2009-1151, CVE-2012-1007, CVE-2014-0114, CVE-2014-3569
  • Malware: MatchBoil, Matchwok, AMOS, Ashvein, BadPaw
  • Ransomware groups: Qilin, Akira, Akira Ransomware, Babuk2, BlackCat
  • Vulnerabilities: AgentCorruption, Copy Fail

Get the next one by email

The digest is free and arrives every morning. One click to leave.

Subscribe to the digest

A free account turns the digest into a personal watchlist: choose what you want to follow.