Zero Day Wire

Critical Appsmith Vulnerability Enables Account Takeover Through Origin Header Manipulation (CVE-2026-22794)

Alerts

Critical Appsmith Vulnerability Enables Account Takeover Through Origin Header Manipulation (CVE-2026-22794)

A critical authentication vulnerability in Appsmith allows attackers to take over user accounts by manipulating the HTTP Origin header during the password reset process, with over 1,600 vulnerable instances currently exposed on the internet, according to research published by Resecurity. The vulnerability, tracked as CVE-2026-22794, carries a CVSS score

By Zero Day Wire
China-Aligned APT Groups Deploy PeckBirdy JScript Framework for Fileless Attacks on Government Targets

Threats

China-Aligned APT Groups Deploy PeckBirdy JScript Framework for Fileless Attacks on Government Targets

China-aligned advanced persistent threat groups have been using a previously undocumented JScript-based command-and-control framework called PeckBirdy to conduct fileless attacks against Asian government entities, educational institutions, and Chinese gambling operations since 2023, according to research published by Trend Micro. PeckBirdy is built entirely in JScript and leverages the Windows Script

By Zero Day Wire
Malicious npm Package "G_Wagon" Steals Browser Credentials and 100+ Cryptocurrency Wallets

Threats

Malicious npm Package "G_Wagon" Steals Browser Credentials and 100+ Cryptocurrency Wallets

A sophisticated malicious npm package disguised as a UI component library has been discovered deploying a multi-stage infostealer that targets browser credentials, over 100 cryptocurrency wallet extensions, cloud credentials, and messaging tokens, according to research published by Aikido Security. The package, named ansi-universal-ui, describes itself as "a lightweight, modular

By Zero Day Wire
Mustang Panda Upgrades CoolClient Backdoor with Clipboard Monitoring and Credential Theft Capabilities

Threats

Mustang Panda Upgrades CoolClient Backdoor with Clipboard Monitoring and Credential Theft Capabilities

The China-linked advanced persistent threat group HoneyMyte, also known as Mustang Panda or Bronze President, has significantly upgraded its CoolClient backdoor with new surveillance capabilities including clipboard monitoring, HTTP proxy credential sniffing, and browser credential theft, according to research published by Kaspersky. The group continues to actively target government entities

By Zero Day Wire
Salt Typhoon Hacked Downing Street Mobile Phones for Years, Exposing Senior UK Government Communications

Breaches

Salt Typhoon Hacked Downing Street Mobile Phones for Years, Exposing Senior UK Government Communications

Chinese state-sponsored hackers compromised mobile phones of senior Downing Street officials for several years, exposing private communications of some of the closest aides to three British prime ministers, according to a report by The Telegraph. The espionage operation, attributed to the Beijing-linked threat group Salt Typhoon, targeted phones of senior

By Zero Day Wire
Fake Notepad++ and 7-Zip Websites Distribute Weaponized RMM Tools to Deploy Backdoor Malware

Threats

Fake Notepad++ and 7-Zip Websites Distribute Weaponized RMM Tools to Deploy Backdoor Malware

Threat actors are exploiting legitimate Remote Monitoring and Management software as an initial infection vector, distributing weaponized RMM tools through fake download sites impersonating popular utilities like Notepad++, 7-Zip, Telegram, and ChatGPT, according to research published by ASEC. The campaigns represent a shift in attacker tactics. Traditionally, threat actors deployed

By Zero Day Wire
Pakistan-Linked APT Targets Indian Government with New Golang Malware Using GitHub for Command and Control

Threats

Pakistan-Linked APT Targets Indian Government with New Golang Malware Using GitHub for Command and Control

A Pakistan-linked advanced persistent threat group is targeting Indian government entities with three previously undocumented malware tools that leverage private GitHub repositories for command-and-control communication, according to research published by Zscaler ThreatLabz. The campaign, dubbed Gopher Strike, deploys a new downloader called GOGITTER, a backdoor named GITSHELLPAD, and a shellcode

By Zero Day Wire
CISA Adds Four Vulnerabilities to KEV Catalog Including Critical SmarterMail Authentication Bypass

Alerts

CISA Adds Four Vulnerabilities to KEV Catalog Including Critical SmarterMail Authentication Bypass

CISA has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, including two critical flaws in SmarterTools SmarterMail that could allow unauthenticated attackers to achieve full administrative compromise of mail servers. Federal agencies must apply mitigations by February 16, 2026. Critical SmarterMail Authentication Bypass The most severe addition is CVE-2026-23760,

By Zero Day Wire