Ten agencies from seven countries document how Integrity Technology Group, a Chinese company sanctioned by the US Treasury since January 2025, supplies automated scanners, botnets, hijacked VPNs and exfiltration scripts to actors linked to Flax Typhoon. Eight old vulnerabilities, five of them just added to CISA’s KEV catalogue, remain successfully exploited.
CTI & OSINT, Vulnerabilities & Alerts
UAC-0277: ClickFix, smart contracts and LUNEXSTEALER
by •

Ukraine’s government incident response team describes a ClickFix campaign served from more than a hundred compromised sites and steered through a smart contract. One of its three installation chains loads a vulnerable AMD driver whose sample does not appear in the April 2026 copy of the Microsoft blocklist examined here.
Vulnerabilities & Alerts
NetScaler CVE-2026-19490: three distinct CVEs
by •
Projects & Governance, Vulnerabilities & Alerts
VINCE-NT and the Nationalization of the Bug: When CISA Cuts the Academic Cord
by •

CISA officially migrated its Coordinated Vulnerability Disclosure (CVD) platform on September 17. Behind the acronym VINCE-NT (Vulnerability Information and Coordination Environment – New Technology), which replaces the venerable VINCE operated since 2020 by the CERT/CC, lies much more than a mere interface facelift or a welcome alignment with CSAF status frameworks. This is an act…
Vulnerabilities & Alerts
Linux kernel: three exploited CVEs enter the KEV catalogue
by •
Vulnerabilities & Alerts, Compliance & Standards
VINCE-NT replaces VINCE: what the switch changes
by •
Compliance & Standards, Projects & Governance
The ANSSI investigation guidance, read with SIM3
by •
CTI & OSINT, Vulnerabilities & Alerts
Oracle’s September 2026 CSPU: 673 security patches
by •

Oracle released 673 security patches on 15 September 2026, 247 of them for vulnerabilities that are remotely exploitable without authentication. Six carry the maximum score of 10.0, five of those in Fusion Middleware. TLP:CLEAR PAP:CLEAR Unlimited disclosure, no restriction on use. Published 16 September 2026 Subject Oracle, September 2026 CSPU Distribution Public Confidence…
Practical Cybersecurity, Projects & Governance
Three days to patch: what the data actually says about AI-accelerated exploitation
by •
CTI & OSINT, Practical Cybersecurity
Active Directory: the 2026 revision of the CISA guide
by •
Eighteen Active Directory compromise techniques, their Windows event identifiers, and the logging plan that has to come first.










