View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical CosmosEscape Flaw in Azure Cosmos DB Allowed Cross-Tenant

๐Ÿšจ ACTIVE EXPLOITATION

  • Critical CosmosEscape Flaw in Azure Cosmos DB Allowed Cross-Tenant Key Access A vulnerability in Azure Cosmos DB's Gremlin API allowed attackers to access any database across tenants.

    • Applies to Microsoft Azure Cosmos DB customers and Microsoft internal systems
    • Vulnerability in Cosmos DB's Gremlin API enabled sandbox escape via .NET reflection misuse
    • Attackers could execute arbitrary code on the DB Gateway component
    • Exposed a platform-wide Cosmos Master Key granting full read-write access across tenants, regions, and APIs
    • Allowed enumeration of accounts via the Config Store directory and retrieval of primary keys ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News, Cyber Security News
  • Chaos ransomware deployed via Microsoft Teams vishing attacks on North American firms Threat actors use Microsoft Teams vishing calls to deploy Chaos ransomware on corporate devices.

    • Targets: Dozens of US and Canadian organizations across services, manufacturing, energy, and construction sectors
    • Attack vector: Impersonation of IT support in Microsoft Teams calls to convince employees to grant remote access
    • Tools: Remote access via Microsoft Quick Assist and RemSupp, later primarily RemSupp for evasion
    • Persistence: PowerShell backdoors disguised as Realtek and Windows audio components in registry
    • Outcome: At least three intrusions led to Chaos ransomware deployment, with one encrypting files within 17 hours ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via Cybersecurity Dive, BleepingComputer
  • Home Assistant FFmpeg Flaw Allows File Theft and Root Command Execution Home Assistant's FFmpeg integration flaw enables file theft and root command execution.

    • Applies to Home Assistant smart home platform, specifically Wyoming integration announce feature
    • Vulnerability allows argument injection in FFmpeg input, enabling reading of arbitrary local files
    • Attack uses FFmpeg pseudo-protocols (file:, concat:, subfile:) to bypass input validation
    • Exfiltrates sensitive data like SUPERVISOR_TOKEN, enabling root-level command execution
    • Requires attacker to control paired Wyoming Assist satellite and valid Home Assistant API token
    • Patched in Home Assistant Core version 2026.6.2 with strict FFmpeg protocol allowlist ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • GenieLocker ransomware by Toy Ghouls targets Windows, Linux, and ESXi systems GenieLocker ransomware attacks Windows, Linux, and VMware ESXi systems in Russia's manufacturing sector.

    • Targets Windows, Linux, and VMware ESXi systems, mainly in Russia's manufacturing sector since March 2026
    • Operated by Toy Ghouls group, formerly using LockBit, Babuk, and RedAlert ransomware families
    • Initial access via OpenVPN using stolen valid credentials from trusted partner networks
    • Uses tools like OpenSSH, socks5.exe, SoftPerfect Network Scanner, Mimikatz, PsExec, PAExec, and reverse SSH tunnels
    • Windows variant includes anti-debugging, secret argument validation, and encrypts files selectively using libsodium crypto library
    • Linux and ESXi variants lack anti-debugging but can stop VMs and encrypt virtual disks, risking virtual infrastructure ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Server-Side Request Forgery in Boruta OAuth and OpenID URIs Allows Remote Attacker Requests CVE-2026-54885 Boruta OAuth/OpenID server is vulnerable to unauthenticated SSRF via request_uri and jwks_uri parameters.

    • Applies to Boruta versions from 2.3.2 before 2.3.7
    • Vulnerability in OAuth request_uri and OpenID jwks_uri fetching code paths
    • Allows unauthenticated remote attacker to make server issue HTTP requests to attacker-chosen URIs
    • No validation of URI scheme, host, IP allowlist, or response size limits
    • Enables SSRF attacks targeting internal services and cloud metadata endpoints ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Hackers Exploit Nearly One in Four Vulnerabilities Before CVE Publication in 2026 Attackers exploited 23.43% of vulnerabilities before their CVEs were published in early 2026.

    • Applies to vulnerabilities tracked by VulnCheck in the first half of 2026
    • 23.43% of exploited vulnerabilities showed active attacks on or before CVE publication date
    • Median time from CVE publication to known exploitation dropped from 120 to 80 days
    • Content management systems, especially WordPress plugins, were most targeted
    • Network edge devices from Cisco, Palo Alto, Fortinet, and others were heavily attacked
    • AI development tools were also targeted, including exploits like CVE-2026-0769 and CVE-2026-5027 ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

โš ๏ธ BREACHES & INCIDENTS

  • Analog Devices confirms June 2026 data breach with file exfiltration, operations unaffected Analog Devices suffered unauthorized access and file exfiltration in June 2026.

    • Applies to Analog Devices internal systems detected on June 23, 2026
    • Unauthorized party accessed and exfiltrated certain company files
    • Incident response activated with external cybersecurity experts engaged
    • Operations remained uninterrupted; no confirmed data leak or fraud use reported
    • Extortion group ExfilSquad claimed stolen customer data but link to breach unverified ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ“„ Original: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer, Cyber Security News
  • ExfilSquad claims theft of 740,000 records from UK education and police databases ExfilSquad hackers stole over 740,000 records from UK education and police databases.

    • Targets include UK Department for Education helpdesk and Turing portals, and Police National Legal Database
    • Data stolen includes names, emails, phone numbers, job titles of officials, school staff, police officers, and public
    • Hackers posted data samples on leak site and demanded ransom from at least 14 victims including a UK university
    • Police database breach exposed work-related info but no confidential victim, witness, or offender data
    • Cybersecurity firm Sophos verified data legitimacy; ExfilSquad's social media account was suspended ๐Ÿ“Ž Coverage: metacurity.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange
  • River Bank Discloses Paying Threat Actor to Conceal Cybersecurity Incident River Bank paid a threat actor to cover up a cybersecurity incident.

    • Applies to River Bank, a financial institution
    • Incident involves a cybersecurity breach
    • Bank paid the threat actor to conceal the incident
    • Disclosure made via an SEC 8-K filing ๐Ÿ“Ž Coverage: cyberplace.social ยท ๐Ÿ“„ Original: sec.gov ยท ๐Ÿ‘ via @GossiTheDog@cyberplace.social

๐Ÿ“‹ ADVISORIES

  • foreUP golf management API has two critical vulnerabilities exposing customer and merchant data foreUP's golf management API exposes merchant credentials and customer data via broken object-level authorization.
    • Applies to foreUP golf management platform used by over 2,000 golf courses
    • CVE-2026-15657 exposes Finix merchant API credentials in customer record responses
    • CVE-2026-15658 allows unauthorized access to any customer's profile and payment tokens by changing golfer_id
    • Attack requires only a valid low-privilege customer account and exploits missing object-level authorization
    • Vulnerabilities affect all facilities using foreUP due to shared web API ๐Ÿ“Ž Coverage: kb.cert.org ยท ๐Ÿ“„ Original: kb.cert.org ยท ๐Ÿ‘ via CERT/CC Vulnerability Notes

๐Ÿ”“ CVEs & KEV

  • Other: 20 CVEs (worst 8.6)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check