🚨 ACTIVE EXPLOITS & INCIDENTS
- CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities — SecurityWeek
CISA warns of active exploitation of three SharePoint vulnerabilities, including two zero-days currently used in targeted attacks. Immediate patching is critical to prevent unauthorized access and potential data breaches.
🔓 VULNERABILITIES & CVEs
-
Unpatched Cursor Vulnerability Exposes Users to Code Execution — SecurityWeek
A critical flaw in Cursor allows automatic execution of a maliciousgit.exeplaced in a project root, enabling remote code execution. No patch available yet; mitigation requires restricting project root contents and monitoring for suspicious executables. -
Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py (CVE-2026-43637) — CVE ThreatInt
Cornac versions prior to 2.6.0 are vulnerable to a Tar Slip path traversal allowing arbitrary file writes outside the cache directory via crafted TAR archives. CVSS likely high; upgrade to 2.6.0 or later recommended. -
Fortinet FortiSIEM Basic XSS Vulnerability (CVE-2026-59838) — CVE ThreatInt
FortiSIEM versions 7.2.0–7.2.6, 7.3.0–7.3.4, and 7.4.0 suffer from improper neutralization of script-related HTML tags leading to basic cross-site scripting (XSS). Exploitation could allow session hijacking or UI manipulation; patching advised.
🕵️ THREAT RESEARCH & DEEP DIVES
- We built a vulnerability vending machine: AI tokens in, zero-days out — BleepingComputer
Researchers detail an AI-powered system combining code slicing and large language models to autonomously discover complex zero-day vulnerabilities. The tool recently uncovered and exploited a previously unknown WordPress plugin zero-day, with multiple additional zero-days responsibly disclosed. This marks a significant evolution in automated vulnerability discovery and exploitation.
📋 VENDOR BULLETINS & ADVISORIES
- Establishing a Coordinated Vulnerability Disclosure Program — CISA Advisories
Joint guidance from CISA, NSA, and partners outlines best practices for software vendors and service providers to implement coordinated vulnerability disclosure (CVD) programs. It covers policy design, triage, remediation, CVE assignment, and leveraging third-party intermediaries to improve transparency and security collaboration.
📰 LESSER-KNOWN / UNDER-REPORTED
- Alleged Russian Cyber Spy in Boston Previously Worked for Kaspersky — @metacurity on Infosec.exchange
New reporting reveals the alleged Russian cyber espionage suspect arrested in Boston has prior employment history with Kaspersky. This connection may have implications for attribution and insider threat assessments in espionage investigations.