🚨 ACTIVE EXPLOITS & INCIDENTS
- Critical flaw in Oracle E-Business Suite is under immediate threat — Cybersecurity Dive A critical vulnerability in Oracle E-Business Suite could allow attackers to compromise Oracle Payments. Exploitation is actively observed, urging immediate patching and monitoring of payment processing environments.
- Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters — The Hacker News An unauthenticated code execution flaw in Argo CD’s repo-server component enables potential full Kubernetes cluster takeover if the internal port is reachable. No patch or CVE yet; organizations should restrict network access and monitor Argo CD deployments closely.
- bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform|DHS confirms hackers breached HSIN info-sharing platform> — BleepingComputer The Department of Homeland Security confirms a breach of the Homeland Security Information Network (HSIN), a critical platform for federal and partner agencies. Investigation ongoing; heightened vigilance and access reviews recommended for HSIN users.
- SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT — The Hacker News A widespread campaign uses SEO-poisoned fake software sites to distribute AsyncRAT via ScreenConnect remote access tool. Malicious installers masquerade as popular apps, enabling remote code execution and data theft. Users should verify download sources and monitor for AsyncRAT indicators.
- bleepingcomputer.com/news/security/chocopoc-malware-delivered-via-trojanized-exploits-on-github|ChocoPoc malware delivered via trojanized exploits on GitHub> — BleepingComputer Weaponized PoC exploits hosted on GitHub are delivering ChocoPoC, a Python-based RAT capable of command execution and data theft. Security teams should audit GitHub usage and block suspicious PoC repositories.
🔓 VULNERABILITIES & CVEs
- Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands — The Hacker News Two high-severity Cursor AI code editor vulnerabilities (CVE-2026-50548, CVE-2026-50549, CVSS 9.8) allow prompt injection to break sandbox restrictions and execute arbitrary commands without user interaction. Immediate patching is critical for developers using Cursor.
- Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic — The Hacker News Adobe released patches for seven critical (CVSS 10.0) vulnerabilities in ColdFusion and Campaign Classic that enable arbitrary code execution, privilege escalation, and security bypass. Urgent updates required for affected deployments.
- Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution — CIS Advisories Confirms Adobe ColdFusion and Campaign Classic flaws with potential for full system compromise depending on user privileges. Aligns with Adobe’s recent patch release; prioritize patching and privilege audits.
- Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution — CIS Advisories Multiple critical vulnerabilities in Mozilla Firefox and Thunderbird could lead to arbitrary code execution. Impact varies by user privilege level. Immediate patching recommended.
🕵️ THREAT RESEARCH & DEEP DIVES
- VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer — The Hacker News New multi-stage malware campaign VEIL#DROP uses social engineering and Blogger-hosted pages to deliver PureLogs info stealer. Initial infection vectors include spear-phishing and drive-by compromises. Monitoring for related IOCs and user awareness training advised.
- Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures — The Hacker News Ousaban trojan targets Spanish and Portuguese Windows users with phishing PDFs disguised as corrupted files. The payload is hidden inside images and aims to steal banking credentials. Regional banks and users should increase phishing defenses and endpoint monitoring.
📋 VENDOR BULLETINS & ADVISORIES
- securityweek.com/microsoft-adds-new-teams-controls-to-block-unauthorized-ai-bots-from-meetings|Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings> — SecurityWeek Microsoft introduces Teams admin policies requiring organizer approval for external AI bots, enhancing meeting security against unauthorized automated participants. Recommended to review and enable these controls in sensitive environments.
- aws.amazon.com/blogs/security/secure-amazon-container-workloads-using-container-attribute-based-rules-in-aws-network-firewall|Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall> — AWS Security Blog AWS now supports container attribute-based firewall rules for Amazon EKS and ECS, enabling granular network protection for containerized workloads, including AI/ML pipelines. Security teams should evaluate and implement these rules to reduce attack surface.
- aws.amazon.com/blogs/security/how-to-use-the-aws-workload-credentials-provider-for-cross-account-secret-retrieval-and-prefetching-secrets|How to use the AWS Workload Credentials Provider for cross-account secret retrieval and prefetching secrets> — AWS Security Blog New AWS Workload Credentials Provider features enable secure, low-latency cross-account secret retrieval and prefetching, improving secret management in multi-account environments. Recommended for teams managing complex AWS deployments.