N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

2026-09-16T13:24:01Z•7f3e0af27262188da6bf18b3dee36f0f87b421864aec221297c09b8205fbc0d0
CVE-2026-5430CVE-2026-58704CVE-2026-76461CVE-2026-87886AcronisCISA-KEVChina-linkedCiscoGiteaGoogle-PixelIran-linkedWSO2WordPressaccount-takeoveractive-exploitationbanking-malwarebrowser-extensioncloud-securitycredential-theftidentity-securitymalwarephishingprivilege-escalationremote-code-executionsupply-chainweb-shellzero-day

What happened

The document is a threat-intelligence digest covering active exploitation, malware campaigns, phishing, credential theft, cloud compromise, and newly disclosed vulnerabilities. Several high-impact vulnerabilities are reportedly exploited in the wild, including flaws in WSO2 API Manager, Cisco Secure Email Gateway, Acronis Backup for cPanel/WHM, Google Pixel Cellular Modem, and WooCommerce Wholesale Lead Capture. Additional reporting describes browser-extension abuse, passkey phishing, exposed development-server credential theft, web shells, root privilege escalation, and state-linked espionage

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
7f3e0af27262188da6bf18b3dee36f0f87b421864aec221297c09b8205fbc0d0
Enrichment time
2026-09-16T13:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security · Baitaphish