A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
In brief

CVE-2026-42608: Grav Path Traversal Flaw Used to Breach Clop Ransomware Site

The breach of Clop’s ransomware leak site by rival extortion group ShinyHunters is an unusual example of cybercriminal infrastructure…

Sep 26, 2026

Kiteworks Urges Six-Hour Global Server Shutdown Over Imminent Cyberattack Warning

Kiteworks’ extraordinary recommendation that customers worldwide temporarily shut down their servers for a six-hour window demonstrat…

Sep 26, 2026

Elementor Flaw Lets Attackers Create WordPress Admin Accounts With a Single Click

A newly disclosed vulnerability in the Elementor Website Builder plugin demonstrates how a seemingly narrow Cross-Site Request Forgery issu…

Sep 26, 2026

PamStealer macOS Malware Adds Live C2 Decryption and Multi-Layer Persistence

The latest version of PamStealer shows how quickly macOS information-stealing malware is evolving from relatively straightforward cred…

Sep 26, 2026

CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279 CISA Warns of Active Exploitation in SharePoint, WSO2, Adobe Commerce and MikroTik

CISA’s latest Known Exploited Vulnerabilities update highlights a particularly uncomfortable mix of enterprise attack surfaces: Micro…

Sep 25, 2026

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Severity: HIGH · Priority: P2 — CI/CD credential theft from active build pipelines, investigate on hit Rule note — GS TROJAN: Mini Shai-Hul…

Sep 25, 2026

Bitget Says Suspected North Korean Hackers Stole $351.6 Million After Backend Compromise

The theft of approximately $351.6 million from cryptocurrency exchange Bitget is another major reminder that securing digital assets r…

Sep 25, 2026

CVE-2026-5430 and CVE-2026-71362 Added to CISA's Exploited Vulnerability Catalog

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming evidence of active exploitation: CV…

Sep 25, 2026

Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts

The discovery of Carbonato, a newly documented botnet targeting exposed Docker hosts, highlights how traditional infrastructure weakne…

Sep 25, 2026

MacSync Malware Abuses Public iCloud Calendars to Deliver New macOS Payloads

The latest evolution of the MacSync malware demonstrates how macOS threats are becoming more modular, evasive, and increasingly willin…

Sep 25, 2026

New Android Spyware Targets Logistics Workers to Intercept MFA Codes and Redirect Calls

The discovery of Corp MDM, a new Android spyware implant targeting logistics organizations, highlights a broader shift in cybercrime: …

Sep 25, 2026