๐ต๏ธ RESEARCH & DEEP DIVES
-
Palo Alto's NOVA AI Finds 14,000+ Zero-Day Vulnerabilities in Open Source Palo Alto Networks' NOVA AI system autonomously discovered 14,090 confirmed zero-day vulnerabilities across 3,915 open-source projects in six major ecosystems including Go, JavaScript, PHP, C/C++, and Java/JVM.
- 99.4% of these vulnerabilities were previously unreported.
- 40% of the findings are high or critical severity.
- NOVA autonomously reviews code, creates proof-of-concept exploits, validates them, and generates patches.
- Vulnerabilities affect both small packages and large codebases exceeding 1 million lines.
- This accelerates vulnerability discovery and patching, enabling near-zero exposure with advanced virtual patching. ๐ Coverage: unit42.paloaltonetworks.com ยท ๐ Original: unit42.paloaltonetworks.com ยท ๐ via Palo Alto Unit 42
-
Researchers Show How Email AI Assistants Can Be Weaponized to Hijack Accounts Attackers abuse built-in email AI assistants linked to user accounts to stealthily delete detection emails, gather organizational info, and hijack executive accounts by mimicking writing styles in phishing emails.
- Phishing leads to session token theft, bypassing MFA.
- Compromised CEO accounts are used to authorize fraudulent financial transactions undetected. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
SMOKE#SCREEN Campaign Uses Fake Adobe and Zoom Updates to Deploy ScreenConnect RMM Attackers target enterprise users with spear-phishing emails themed as Adobe and Zoom updates to install ScreenConnect remote management software for persistent access.
- Uses VBScript droppers, batch loaders, and .NET executables.
- Employs environment checks to evade analysis and disables Windows security features.
- Payload connects to attacker-controlled relay servers.
- Delivery uses trusted hosting services like Dropbox and Cloudflare Quick Tunnel to bypass filters. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Google Removes 3 ADK AI Workflows After GitHub Issue Enables Privileged Agent Exploit Google deleted three Agent Development Kit (ADK) Python repository workflows after a GitHub issue allowed a malicious comment to bypass authorization and execute arbitrary code on CI runners.
- Workflows issue-analyze.yml, issue-fix.yml, and pr-analyze.yml were removed in June 2026. ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
Google Firebase Misconfiguration in tl;dv AI Tool Exposes Meeting Data A Firebase backend misconfiguration in the tl;dv AI meeting transcription tool allows unauthorized access to other users' meeting details and potential unauthorized call joining. ๐ Coverage: darkreading.com ยท ๐ via Dark Reading
-
Almost Half of Malware Samples Bypass DNS by Connecting Directly to IP Addresses 45.32% of malware samples with command-and-control activity connect directly to IP addresses, bypassing DNS-based defenses.
- Includes Phorpiex ransomware droppers, Mozi IoT botnets, and SectopRAT targeting educational institutions.
- Uses hard-coded IPs, obfuscated HTTP GET requests, and rotating IP/port schedules.
- Zero Trust IP enforcement verifies outbound IP connections against DNS responses to detect threats. ๐ Coverage: unit42.paloaltonetworks.com ยท ๐ Original: unit42.paloaltonetworks.com ยท ๐ via Palo Alto Unit 42
๐ ADVISORIES
- Six Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers Six remote code execution vulnerabilities in Flowise servers used to build AI agents and automated workflows could allow authenticated attackers to run commands on the underlying server, risking data, credentials, and connected systems. ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ CVEs & KEV
- CVE-2026-63248 โ Eclipse Milo โ In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes...
- CVE-2026-58080 โ Eclipse Milo โ In Eclipse Milo versions 1.0.0 through 1.1.4,
OpcUaServerConfig.copy()fail... - CVE-2026-63252 โ Eclipse Milo โ In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers ...
- CVE-2026-62927 โ Eclipse Milo โ In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the...
- CVE-2026-60007 โ Eclipse Milo โ In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing retur...
- CVE-2026-61387 โ Eclipse Milo โ In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting...
- CVE-2026-66883 โ Oidcc.Plug.Authorize โ user agent session binding inert due to case-sensitive h...
- CVE-2026-66884 โ Oidcc.Plug.AuthorizationCallback โ accepts callbacks with no authorize session ...
- CVE-2026-10050 โ Eclipse Jetty โ Digest authentication lossy encodingIn Eclipse Jetty, the Digest authenticati...
๐ต๏ธ RESEARCH & DEEP DIVES
- adform-breach-advertising-data โ @GossiTheDog@cyberplace.social
- botnet-hunting-diagnostic-tools-vulns โ SANS ISC