DIL Observatory: when the World Escalates, the Underground Responds

2026-05-29T14:51:47Z49552faf90d8d0e5a3145856593b4b921a60edcf5e9468d01454464fa1755387
19.6 billion filesAndroid RATBTMOBBitLockerCISACVE-2026-35616CVE-2026-48172CVE-2026-8398CarnivalChaotic EclipseDefenderFortiClientFox TempestKnown Exploited VulnerabilitiesLiteSpeedMicrosoft DCUS3/bucketscloud misconfigurationcode-signingdata breachexposed passportswindowszero-day

What happened

Recent SecurityAffairs reporting aggregates multiple high-impact events: a researcher known as Chaotic Eclipse publicly released six Windows zero-days (affecting Defender/BitLocker among others), with three already exploited in the wild; a critical FortiClient EMS RCE (CVE-2026-35616, CVSS 9.1) is being actively exploited; CISA added multiple flaws to its Known Exploited Vulnerabilities catalog including LiteSpeed cPanel Plugin (CVE-2026-48172, CVSS 10.0) and other entries (e.g., CVE-2026-8398); a commercial Android full-device takeover kit called BTMOB RAT is being sold as a point-and-click R

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
49552faf90d8d0e5a3145856593b4b921a60edcf5e9468d01454464fa1755387
Enrichment time
2026-05-29T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.