Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Rescana
rescana.com > post > active-exploitation-alert-threat-actors-abuse-anthropic-claude-ai-to-extract-secrets-from-1-8m-android-apps-in-major-cre

Active Exploitation Alert: Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign

7+ hour, 19+ min ago   (367+ words) Rescana Technical Analysis of Malware/TTPs The attack chain began with the automated mass-download of 1.8 million Android APKs from multiple app stores using a distributed pipeline orchestrated on ten AWS EC2 instances. The APKs were decompiled and scanned for hardcoded secrets…...

Rescana
rescana.com > post > jsceal-infostealer-malware-bypasses-google-authentication-and-2fa-via-stolen-browser-session-cookies

JSCeal Infostealer Malware Bypasses Google Authentication and 2FA via Stolen Browser Session Cookies

1+ week, 4+ hour ago   (237+ words) No public attribution to a specific APT group has been made, but the sophistication and targeting patterns suggest a well-organized criminal operation with a focus on financial gain. The malware’s modular architecture and rapid evolution indicate ongoing development and adaptation…...

Rescana
rescana.com > post > critical-cve-2026-20212-vulnerability-in-cisco-nexus-9000-series-switches-allows-unauthenticated-remote-code-execution

Critical CVE-2026-20212 Vulnerability in Cisco Nexus 9000 Series Switches Allows Unauthenticated Remote Code Execution

1+ week, 1+ day ago   (422+ words) No exploitation in the wild or public proof-of-concept (PoC) has been confirmed as of September 4, 2026. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and there is no CISA-confirmed active exploitation. However, the exposure is automatable…...

Rescana
rescana.com > post > falconflank-zero-day-exposes-critical-privilege-escalation-vulnerability-in-crowdstrike-falcon-sensor-for-windows-11-and

FalconFlank Zero-Day Exposes Critical Privilege Escalation Vulnerability in CrowdStrike Falcon Sensor for Windows 11 and Windows Server 2026

1+ week, 1+ day ago   (555+ words) rescana.com FalconFlank Zero-Day Exposes Critical Privilege Escalation Vulnerability in CrowdStrike Falcon Sensor for Windows 11 and Windows Server 2026 A critical zero-day vulnerability, designated FalconFlank, has been publicly disclosed in the CrowdStrike Falcon Sensor for Windows. This flaw enables local attackers…...

Rescana
rescana.com > post > large-scale-phishing-campaign-uses-invisible-unicode-and-activecampaign-to-evade-email-security-filters

Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters

1+ week, 1+ day ago   (772+ words) rescana.com Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters A newly identified, large-scale phishing campaign is actively exploiting invisible Unicode characters to bypass traditional email security filters, sending millions of malicious emails globally. This…...

Rescana
rescana.com > post > jetbrains-cadence-breach-attackers-exploit-unpatched-teamcity-cve-2026-63077-to-exfiltrate-aws-credentials-and-source-co

JetBrains Cadence Breach: Attackers Exploit Unpatched TeamCity CVE-2026-63077 to Exfiltrate AWS Credentials and Source Code

1+ week, 1+ day ago   (299+ words) The breach demonstrates a pattern of targeting CI/CD platforms for supply chain compromise, credential theft, and lateral movement. The lack of timely patching, even by the vendor, highlights the importance of rapid vulnerability management in environments with access to…...

Rescana
rescana.com > post > active-exploitation-alert-north-korean-apts-deploy-ted-backdoor-in-compromised-haproxy-builds-to-hijack-web-traffic

Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic

1+ week, 1+ day ago   (517+ words) Rescana Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic Technical Analysis of Malware/TTPs The Ted backdoor is not a vulnerability in the official HAProxy codebase, but rather a malicious plugin…...

Rescana
rescana.com > post > trezor-shipmonk-breach-exposes-67-000-u-s-customer-records-via-metabase-zero-day-vulnerability-cve-2026-72898

Trezor ShipMonk Breach Exposes 67,000 U.S. Customer Records via Metabase Zero-Day Vulnerability (CVE-2026-72898)

1+ week, 1+ day ago   (289+ words) Attribution for the attack has been assigned to the ShinyHunters extortion gang, based on reporting from enterprise blockchain security firm Holborn. While this attribution is consistent with ShinyHunters’ historical targeting of SaaS, e-commerce, and supply chain providers, it is based…...

Rescana
rescana.com > post > critical-unpatched-vulnerabilities-in-kaltura-mwembed-expose-organizations-to-remote-code-execution-and-file-read-attack

Critical Unpatched Vulnerabilities in Kaltura mwEmbed Expose Organizations to Remote Code Execution and File Read Attacks (CVE-2026-19912, CVE-2026-19913)

2+ week, 5+ day ago   (209+ words) Both vulnerabilities are remotely exploitable via HTTP(S) requests to the vulnerable endpoint and require no authentication or user interaction. The attack surface is significant, with over 600 internet-exposed instances identified through search engine reconnaissance, including those hosted on Kaltura’s own infrastructure....

Rescana
rescana.com > post > active-exploitation-alert-toxicpanda-2-0-and-golddigger-banking-malware-escalate-on-device-fraud-against-android-users-g

Active Exploitation Alert: ToxicPanda 2.0 and GoldDigger Banking Malware Escalate On-Device Fraud Against Android Users Globally

3+ week, 4+ day ago   (255+ words) Persistence is achieved by exploiting Accessibility Services to automate the disabling of battery optimization and auto-start restrictions, ensuring the malware remains active even after device reboots or system updates. Device Admin privileges are leveraged to prevent uninstallation and enable remote…...