THE **Security Affairs Malware Newsletter Round 101** provides a curated collection of notable articles and research pertaining to malware threats and developments. Key highlights include insights into various malware types such as IronWorm, Miasma, and Gafgyt variants. Notable articles cover topics like the propagation of self-replicating npm worms, malware analysis using AI, IoT botnet vulnerabilities, and new tools for malware detection. The newsletter aims to keep readers informed about the evolving malware landscape and significant cyber threats.
Security Affairs Newsletter Highlights New Malware Variants
CyberSIXT Evidence Panel
Primary Source
fortinet.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
GitHub Actions Abused to Steal Credentials from PHP Packages
cybersixt.com
-
CISA Flags CVE-2026-50522 in KEV, Warns of SharePoint RCE Risk
cybersixt.com
-
CISA Adds CVE-2026-50522 to Known Exploited Vulnerabilities Catalogue
cybersixt.com
-
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
cybersixt.com
-
CISA adds DDWRT, Langflow and WordPress bugs to KEV list
cybersixt.com
-
CVE-2026-50522: SharePoint Flaw Lets Site Owners Run Remote Code
cybersixt.com
-
CISA warns of active exploits in WordPress, Langflow, DDWRT
cybersixt.com
-
CISA warns of critical Langflow RCE flaw CVE-2026-0770
cybersixt.com
-
CISA Warns of Critical WordPress Flaw CVE‑2026-63030 in KEV
cybersixt.com
-
CISA flags critical WordPress SQLi flaw in KEV, urges patch
cybersixt.com
-
SharePoint flaw CVE-2026-50522 under active attack after PoC leak
cybersixt.com
-
Critical WordPress Bug Lets Attackers Run Code Remotely
cybersixt.com
-
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
cybersixt.com
-
WordPress core flaw CVE-2026-63030 lets attackers execute code
cybersixt.com
-
AI crafted WordPress exploit chain triggers urgent CVE patches
cybersixt.com
-
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
cybersixt.com
-
Public PoC exploits hit critical WordPress CVEs, urging patches
cybersixt.com
-
WordPress SQLi bug allows remote code execution, update now
cybersixt.com
-
WordPress REST API flaw lets attackers run code remotely
cybersixt.com
-
Security Affairs Newsletter Highlights New Malware Variants
securityaffairs.com
-
COXMO botnet hijacks devices via CVE-2021-27137 flaw worldwide
cybersixt.com
-
New Gafgyt Botnet Variant C0XMO Hijacks DDWRT Routers for DDoS
cybersixt.com