Robuta

Sponsor of the Day: Jerkmate
https://bugs.gentoo.org/show_bug.cgi?id=CVE-2021-30184 780855 – (CVE-2021-30184) games-board/gnuchess-6.2.8-r1: code execution via malicious PGN file code execution viacve 2021games board https://thehackernews.com/2026/03/russian-ctrl-toolkit-delivered-via.html Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels Russian CTRL toolkit spread via malicious LNK files in February 2026, routing C2 through FRP-tunneled RDP to evade detection. delivered viarussianctrltoolkitmalicious https://bugs.gentoo.org/show_bug.cgi?id=CVE-2021-3624 839366 – (CVE-2021-3624) media-gfx/dcraw: integer overflow via malicious x3f cve 2021 3624media gfxinteger overflowvia maliciousdcraw https://thecybersecurity.news/general-cyber-security-news/sglang-cve-2026-5760-cvss-9-8-enables-rce-via-malicious-gguf-model-files-36483/ SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files | The Cyber Security News A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems.... cvss 9 8cyber security newscve 2026rce viagguf model https://www.securitymagazine.com/articles/101873-malicious-actors-spread-malware-via-metas-advertising-system Malicious Actors Spread Malware Via Meta’s Advertising System | Security Magazine Aug 28, 2025 - A Meta malvertising campaign has expanded to Android phones. spread malwaresystem securitymaliciousactorsvia https://blog.knowbe4.com/malicious-pdfs-carry-stealthy-backdoor New Malicious PDFs Carry Stealthy Backdoor And Exfiltrate Data Via Email Dec 26, 2025 - The Turla threat group, certainly Russian-speaking and widely attributed to Russian intelligence services, is back with a new phishing technique. stealthy backdoordata vianewmaliciouspdfs https://safedep.io/malicious-velora-dex-sdk-npm-compromised-rat/ Malicious @velora-dex/sdk Delivers Go RAT via npm - Real-time Open Source Software Supply Chain... Version 9.4.1 of @velora-dex/sdk, a DeFi SDK with ~2,000 weekly downloads, was compromised to deliver a Go-based remote access trojan (minirat) targeting macOS... real time opensource software supplydelivers govia npmmalicious