ThreatCluster[verified]@threatclusterActive Exploitation
The article reports that hackers are actively exploiting RCE vulnerabilities in Qinglong task scheduler servers to drop a cryptominer.
ThreadLinqs[verified]@threadlinqsActive Exploitation
Threat intel reports that CVE‑2026‑3965 and CVE‑2026‑4047 are chained to enable unauthenticated RCE on Qinglong <= 2.20.1, with evidence of nine detections and 20 IOCs, signaling real‑world exploitation while no PoC or patch information is disclosed.
Archange Shadow[verified]@Archange_ShadowActive Exploitation
Hackers are actively exploiting two authentication bypass CVEs in Qinglong, enabling unauthenticated RCE and deploying a cryptominer that brings CPU usage to 85‑100%.
Cybersecurity News Everyday@TweetThreatNewsActive Exploitation
Hackers used auth‑bypass flaws CVE‑2026‑3965 and CVE‑2026‑4047 in Qinglong to deploy cryptominers via remote code execution starting Feb 7, and a fix was applied after initial mitigation failed.