
Attackers exploited CVE-2026-35507 to manipulate Shynet password reset flows via Host header injection. The vulnerability enabled credential theft by redirecting users to attacker-controlled domains. Runtime segmentation helps contain such post-compromise lateral movement across cloud environments. #Vulnerability :link: Full breakdown: https://aviatrix.ai/threat-research-center/shynet-vulnerability-cve-2026-35507
Post summary
Attackers have leveraged a Host header injection flaw in Shynet’s password reset flow (CVE-2026-35507) to redirect users and steal credentials, with details further expanded in an external article.


