Please turn JavaScript on

CybelAngel

We bring you the latest updates from CybelAngel through a simple and fast subscription.

We can deliver your news in your inbox, on your phone or you can read them here on this website on your personal news page.

Unsubscribe at any time without hassle.

CybelAngel's title: External Threat Intelligence | CybelAngel

Is this your feed? Claim it!

Publisher:  Unclaimed!
Message frequency:  0.68 / day

Message History

What does it take for one unpatched server to expose thousands of endpoints across dozens of organizations at once? On the evidence of CVE-2026-86218, no credentials, no phishing, no advanced tradecraft. Just an internet-exposed management console and a static code injection flaw rated a perfect CVSS 10.0. On September 9, 2026, CISA added the vulnerability […]

The post...


Read full story

What does it take to run a persistent espionage operation inside European government, diplomatic and defense manufacturing networks? In 2026, considerably less than the phrase “advanced persistent threat” would lead you to expect. HOOKEDGE is a Windows batch script. It arrives in a macro-enabled Word document. It asks the recipient to click Enable Content. It […]

The p...


Read full story

A Linux rootkit is running inside F5 BIG-IP APM devices right now, injecting a PHP web shell directly into server memory while leaving every file on disk completely unchanged. What is unsettling is that the standard file integrity monitoring finds nothing, and The PHP scripts look clean. The web shell is not there, until it […]

The post


Read full story

A phishing page served from a github.io subdomain inherits three things its operator never had to buy or configure: a valid TLS certificate on a GitHub-controlled domain, a parent domain with enough legitimate traffic that reputation engines score it neutral or better, and free static hosting that survives the first round of abuse reports because […]

The post


Read full story

Here are the main stories you missed last week. 1. Microsoft Exchange: CVE-2026-62911 lets any attacker with basic network access take over every mailbox on a server, and 21,899 servers are still unpatched The headline: As of August 31, 21,899 internet-facing Microsoft Exchange servers remained unpatched against CVE-2026-62911, an authentication bypass by capture-replay flaw ...


Read full story