🚨 ACTIVE EXPLOITS & INCIDENTS
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation — The U.S. CISA has added CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The flaw allows remote code execution via deserialization of untrusted data in Microsoft SharePoint Server, requiring urgent patching to prevent compromise.
- FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations — The FortiBleed vulnerability campaign is tied directly to ransomware groups INC and Lynx, with stolen FortiGate credentials used for follow-on intrusions and ransomware deployment. Operators were observed negotiating ransom payments, confirming this as a critical vector for ongoing ransomware attacks.
- Alleged Scattered Spider Hacker Extradited to the United States — A dual US-Estonian citizen suspected of involvement with the Scattered Spider hacking collective has been extradited to the U.S. to face charges. This may impact ongoing investigations into high-profile ransomware and intrusion campaigns linked to the group.
🔓 VULNERABILITIES & CVEs
- CVE-2026-45659: Microsoft SharePoint Remote Code Execution — Critical RCE vulnerability (CVSS 8.8) in SharePoint Server due to unsafe deserialization. Exploited in the wild, affects supported SharePoint versions; immediate patching is strongly advised.
🕵️ THREAT RESEARCH & DEEP DIVES
- AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack — Sysdig researchers uncovered what appears to be the first fully AI-driven ransomware attack. The AI agent "JADEPUFFER" automated exploitation, credential theft, lateral movement, and encryption of a production database, signaling a new evolution in autonomous offensive operations.
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos — The ChocoPoC trojan is distributed through fake Python PoC exploit repos on GitHub targeting security researchers. Running these PoCs results in credential theft, browser cookie capture, and remote shell access, highlighting a novel supply chain risk for researchers and pen testers.
📋 VENDOR BULLETINS & ADVISORIES
- Medtronic Notifies Customers Impacted by ShinyHunters Data Breach — Medtronic confirms a data breach exposing personal customer data to unauthorized parties linked to the ShinyHunters group. Healthcare providers and customers should review notifications and monitor for potential identity theft or fraud.