CVE
CVE-2026-43499
rtmutex: Use waiter::task instead of current in remove_waiter()
Exploitation IoCs 5
Filename Kuailian VPN
Filename Kuailian VPN.msi
Filename node.exe
Package Braintree.Net
Package Jscrambler
MITRE ATT&CK TTPs 33
T1021.001 T1021.003 T1055 T1056.001 T1059.001 T1068 T1071.001 T1071.004 T1082 T1083 T1098 T1105 T1110 T1114 T1120 T1132 T1133 T1185 T1190 T1202 T1203 T1210 T1484.001 T1490 T1491 T1542 T1543.003 T1557 T1566 T1573 T1588.001 T1595 T1659
Remote Desktop Protocol
Lateral Movement
Distributed Component Object Model
Lateral Movement
Process Injection
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Web Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Email Collection
Collection
Peripheral Device Discovery
Discovery
Data Encoding
Command And Control
External Remote Services
Persistence
Browser Session Hijacking
Collection
Exploit Public-Facing Application
Initial Access
Indirect Command Execution
Defense Evasion
Exploitation for Client Execution
Execution
Exploitation of Remote Services
Lateral Movement
Group Policy Modification
Defense Evasion
Inhibit System Recovery
Impact
Defacement
Impact
Pre-OS Boot
Defense Evasion
Windows Service
Persistence
Adversary-in-the-Middle
Credential Access
Phishing
Initial Access
Encrypted Channel
Command And Control
Malware
Resource Development
Active Scanning
Reconnaissance
Content Injection
Initial Access
Source Articles
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
A high-severity vulnerability in Firefox's JIT compiler, tracked as CVE-2026-10702, allows arbitrary code execution in the browser's renderer process simply by visiting a malicious webpage. This flaw affects Firefox versions 147 through 151.0.2 and also impacts Tor Browser versions based on these Firefox releases. The vulnerability was exploited in a browser-to-kernel chain called IonStack, combining it with a Linux kernel flaw (CVE-2026-43499, GhostLock) to achieve root access on ARM64 Android 17 devices. Mozilla has patched the issue in Firefox 151.0.3, but exploitation remains possible in unpatched systems.
hacker-news Jul 29, 2026
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Multiple threat actors are leveraging compromised software supply chains, AI-driven attacks, and unpatched vulnerabilities to deploy malware, steal credentials, and conduct ransomware operations. Notable activities include the exploitation of Citrix Bleed 2 (CVE-2025-5777) for DragonForce ransomware deployment, a compromised npm package distributing a Rust-based stealer, and the emergence of HalluSquatting attacks targeting AI coding assistants. Additionally, new backdoors like GigaWiper and RedHook are being used for persistent access and data exfiltration across Windows and Android platforms.
hacker-news Jul 13, 2026