This day 02:06 06:06 10:06 14:07 18:08 22:08
Info  2026-09-26 22:08Z · last 4h · 9 findings · glm-5.2:cloud

Threat Brief — 2026-09-26 — Lunex MaaS unmasked, AMD driver abused

Executive Summary

The most significant new development today is the identification of the Psychedelic Stealer campaign as part of a broader malware-as-a-service platform called Lunex, which abuses a legitimate AMD driver to disable security monitoring before exfiltrating browser credentials. This reframes what was initially reported as a single-stealer incident into a structured MaaS operation. No other fresh findings in this cycle introduce genuinely new developments beyond previously covered stories.

Top items

Themes

Bring-your-own-licensed-driver (BYOVD) remains a favoured evasion technique. Lunex's abuse of a legitimate AMD driver to blind security monitoring joins a well-established pattern of threat actors using signed kernel drivers to disable EDR and monitoring tools. The technique persists because it exploits trust in legitimately signed components rather than software vulnerabilities.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db