Skip to content
October 4, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Malware
  • AV-TEST: 119 samples malware using Meltdown/Spectre vulnerabilities for spreading
  • Malware

AV-TEST: 119 samples malware using Meltdown/Spectre vulnerabilities for spreading

Do Son February 5, 2018 2 minutes read
Meltdown Spectre malware
Add Daily CyberSecurity as a preferred source on Google

Security researchers found that an increasing number of malware samples are trying to capitalize on the Meltdown and Specter security vulnerabilities of Intel CPUs.

According to experts such as AV-TEST, Fortinet, and Minerva Labs, there are currently public announcements of vulnerabilities related to Meltdown (CVE-2017-5754) and Specter (CVE-2017-5715, CVE-2017-5753) Attack PoC code. Researchers from AV-TEST have now detected 119 malware samples related to the CPU vulnerabilities described above.

Shortly after the release of the PoC code for Meltdown and Specter vulnerabilities, researchers found a number of malware samples related to it at VirusTotal. The report released by Fortinet shows that most of these samples include PoC code or its variants directly.

All of the current evidence shows that most of these samples are intended for trial use by security researchers for PoC code, but experts do not rule out the possibility that some samples may come from genuine malware authors who want to turn PoC code into weaponized malicious tools.

Omri Moyal, co-founder and research vice president at Minerva Labs, said: “I actually haven’t seen real in-the-wild samples yet. Just a lot of PoC/research/tests.”

Meltdown and Specter are serious security vulnerabilities that, once exploited by an attacker, will allow them to gain vast amounts of information from kernel memory space and from other applications. Mozilla has confirmed the concern that attackers will be able to take advantage of Specter vulnerabilities remotely by embedding attack code into common JavaScript files delivered through web pages.

It is now widely accepted that these two vulnerabilities are likely to first appear in the malware mix of state-backed attackers before they are gradually introduced into other exploits and spam emails.

However, considering the large number of new samples that appear daily, one can conclude that research on PoC code is currently underway. In addition, not all samples will be uploaded to VIrusTotal or other malware libraries for testing. This means that professional malware authors may also be using the results of these codes, but most security researchers are still unable to determine exactly what they want to achieve.

Related coverage

  • Veil#Drop Malware Uses Blogspot to Deliver PureLog Stealer
  • SHADOW#REACTOR Malware Builds Remcos RAT via Text Files
  • Android Malware Surge: Adware Trojans, Spyware Trojans, and Banking Malware on the Rise
  • PhantomRaven: 126 Malicious npm Packages Steal Developer Tokens and Secrets Using Hidden Dependencies
  • XCSSET Malware Returns with Enhanced Obfuscation and Persistence Techniques
  • BRICKSTORM Malware: China-Linked Hackers Stealthily Target US Tech and Legal Firms for 393 Days
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Meltdown Spectre

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intel📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105086CVSS 9.3
    WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105089CVSS 9.3
    WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject...
    📅 Updated: Oct 4, 2026
  • CVE-2026-82042CVSS 9.3
    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105215CVSS 9.3
    ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105211CVSS 9.2
    ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105209CVSS 9.3
    ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless...
    📅 Updated: Oct 4, 2026
  • CVE-2026-105207CVSS 9.3
    ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without...
    📅 Updated: Oct 4, 2026
  • CVE-2026-103355CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements...
    📅 Updated: Oct 4, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.