Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Rescana
rescana.com > post > active-exploitation-alert-threat-actors-abuse-anthropic-claude-ai-to-extract-secrets-from-1-8m-android-apps-in-major-cre

Active Exploitation Alert: Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign

6+ hour, 9+ min ago   (367+ words) Rescana Technical Analysis of Malware/TTPs The attack chain began with the automated mass-download of 1.8 million Android APKs from multiple app stores using a distributed pipeline orchestrated on ten AWS EC2 instances. The APKs were decompiled and scanned for hardcoded secrets…...

Rescana
rescana.com > post > jsceal-infostealer-malware-bypasses-google-authentication-and-2fa-via-stolen-browser-session-cookies

JSCeal Infostealer Malware Bypasses Google Authentication and 2FA via Stolen Browser Session Cookies

1+ week, 3+ hour ago   (237+ words) No public attribution to a specific APT group has been made, but the sophistication and targeting patterns suggest a well-organized criminal operation with a focus on financial gain. The malware’s modular architecture and rapid evolution indicate ongoing development and adaptation…...

Rescana
rescana.com > post > critical-cve-2026-20212-vulnerability-in-cisco-nexus-9000-series-switches-allows-unauthenticated-remote-code-execution

Critical CVE-2026-20212 Vulnerability in Cisco Nexus 9000 Series Switches Allows Unauthenticated Remote Code Execution

1+ week, 1+ day ago   (422+ words) No exploitation in the wild or public proof-of-concept (PoC) has been confirmed as of September 4, 2026. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and there is no CISA-confirmed active exploitation. However, the exposure is automatable…...

Rescana
rescana.com > post > falconflank-zero-day-exposes-critical-privilege-escalation-vulnerability-in-crowdstrike-falcon-sensor-for-windows-11-and

FalconFlank Zero-Day Exposes Critical Privilege Escalation Vulnerability in CrowdStrike Falcon Sensor for Windows 11 and Windows Server 2026

1+ week, 1+ day ago   (555+ words) rescana.com FalconFlank Zero-Day Exposes Critical Privilege Escalation Vulnerability in CrowdStrike Falcon Sensor for Windows 11 and Windows Server 2026 A critical zero-day vulnerability, designated FalconFlank, has been publicly disclosed in the CrowdStrike Falcon Sensor for Windows. This flaw enables local attackers…...

Rescana
rescana.com > post > large-scale-phishing-campaign-uses-invisible-unicode-and-activecampaign-to-evade-email-security-filters

Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters

1+ week, 23+ hour ago   (772+ words) rescana.com Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters A newly identified, large-scale phishing campaign is actively exploiting invisible Unicode characters to bypass traditional email security filters, sending millions of malicious emails globally. This…...

Rescana
rescana.com > post > active-exploitation-alert-north-korean-apts-deploy-ted-backdoor-in-compromised-haproxy-builds-to-hijack-web-traffic

Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic

1+ week, 1+ day ago   (517+ words) Rescana Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic Technical Analysis of Malware/TTPs The Ted backdoor is not a vulnerability in the official HAProxy codebase, but rather a malicious plugin…...

Rescana
rescana.com > post > critical-unpatched-vulnerabilities-in-kaltura-mwembed-expose-organizations-to-remote-code-execution-and-file-read-attack

Critical Unpatched Vulnerabilities in Kaltura mwEmbed Expose Organizations to Remote Code Execution and File Read Attacks (CVE-2026-19912, CVE-2026-19913)

2+ week, 4+ day ago   (209+ words) Both vulnerabilities are remotely exploitable via HTTP(S) requests to the vulnerable endpoint and require no authentication or user interaction. The attack surface is significant, with over 600 internet-exposed instances identified through search engine reconnaissance, including those hosted on Kaltura’s own infrastructure....

Rescana
rescana.com > post > active-exploitation-alert-toxicpanda-2-0-and-golddigger-banking-malware-escalate-on-device-fraud-against-android-users-g

Active Exploitation Alert: ToxicPanda 2.0 and GoldDigger Banking Malware Escalate On-Device Fraud Against Android Users Globally

3+ week, 3+ day ago   (255+ words) Persistence is achieved by exploiting Accessibility Services to automate the disabling of battery optimization and auto-start restrictions, ensuring the malware remains active even after device reboots or system updates. Device Admin privileges are leveraged to prevent uninstallation and enable remote…...

Rescana
rescana.com > post > active-exploitation-of-mlflow-ssrf-vulnerability-cve-2026-64849-enables-cloud-credential-theft-and-account-compromise

Active Exploitation of MLflow SSRF Vulnerability (CVE-2026-64849) Enables Cloud Credential Theft and Account Compromise

3+ week, 3+ day ago   (698+ words) Rescana Active Exploitation of MLflow SSRF Vulnerability (CVE-2026-64849) Enables Cloud Credential Theft and Account Compromise A critical vulnerability has been identified and is being actively exploited in MLflow, a widely used open-source platform for managing the machine learning lifecycle. The…...

Rescana
rescana.com > post > massive-azure-entra-credential-theft-exposes-fortune-500-employee-directories-in-global-exfiltration-campaign

Massive Azure/Entra Credential Theft Exposes Fortune 500 Employee Directories in Global Exfiltration Campaign

3+ week, 6+ day ago   (392+ words) The exposure of service accounts and privileged users provides attackers with a roadmap for subsequent social engineering, spear-phishing, and privilege escalation attacks. The structured nature of the data enables highly targeted Business Email Compromise (BEC) and impersonation campaigns, as attackers…...