๐ฅ BREACHES & INCIDENTS
- Brazilian Government Health Platform Exposed 79GB of Sensitive Data Online
Brazil's Health Surveillance Information System (SISVISA) platform exposed 79GB of sensitive data publicly without password protection or encryption.
- Exposed data includes 102,215 documents with personally identifiable information, identification records, contact details, and health compliance information
- Data exposure discovered by researcher Jeremiah Fowler who reported it to authorities
- Exposure included inspection reports, licensing applications, and backups related to public health surveillance ๐ Coverage: expressvpn.com ยท ๐ via @metacurity@infosec.exchange
๐ CVEs & KEV
- CVE-2026-15307 โ CVSS 8.8 โ Server-side file-write and request forgery via spatial lookups
- CVE-2026-56848 โ CVSS 7.5 โ A flaw in Node.js HTTP/2 handling allows
nghttp2_session_mem_send()to be corrupted - CVE-2026-34486 โ Apache Tomcat โ CVSS 7.5 โ Apache Tomcat Missing Encryption of Sensitive Data Vulnerability [KEV]
- CVE-2026-18775 โ CVSS 6.3 โ NousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot service
- CVE-2026-18774 โ CVSS 6.3 โ NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py flaw
- CVE-2026-15920 โ CVSS 6.1 โ Potential cross-site scripting via URLField values in the admin
- CVE-2026-15830 โ CVSS 5.3 โ Potential denial-of-service vulnerability via nested geometry collections
- CVE-2026-15337 โ CVSS 5.3 โ Potential denial-of-service vulnerability in check_for_language()
- CVE-2026-18556 โ N-able N-central โ CVSS โ โ N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability [KEV]
๐ต๏ธ RESEARCH & DEEP DIVES
-
Hackers Exploit Microsoft Copilot to Hijack CEO Emails and Redirect Wire Transfers Attackers weaponize Microsoft Copilot to take over CEO accounts and steal wire transfers.
- Targets Microsoft 365 users with Microsoft Copilot AI assistant enabled
- Attack begins with a compromised employee inbox to escalate access to CEO account
- Copilot abused to create stealth inbox rules hiding sign-in alerts and aid reconnaissance
- Copilot drafts convincing phishing emails mimicking victim's style to bypass MFA via MITM proxy
- Attackers use Copilot to identify pending $247,500 wire transfer and redirect funds fraudulently ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Critical Code Injection Flaw in IBM Langflow OSS 1.0.0 to 1.10.0 Enables Remote Code Execution
CVE-2026-9198IBM Langflow OSS versions 1.0.0 to 1.10.0 have a critical code injection vulnerability allowing full remote code execution.- Vulnerability allows unauthenticated attackers to mint SUPERUSER tokens via /api/v1/auto_login
- Attack chains token minting with /api/v1/validate/code endpoint to execute arbitrary code using exec()
- Leads to full remote code execution on default Langflow deployments without authentication ๐ Coverage: nvd.nist.gov ยท ๐ Original: ibm.com ยท ๐ via CISA KEV
-
Flowise prior to 3.1.3 vulnerable to RCE, SSRF bypass, and unauthenticated property injection
CVE-2026-69257CVE-2026-69258CVE-2026-69259Flowise drag & drop UI for building LLM flows has multiple critical vulnerabilities fixed in version 3.1.3.- CVE-2026-69259: Authenticated RCE via SQLite Record Manager node by overwriting database path and injecting shell syntax
- CVE-2026-69258: Unauthenticated property injection allows control of flow execution context
- CVE-2026-69257: SSRF protection bypass using IPv4-mapped IPv6 addresses enables requests to internal services ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Multiple critical vulnerabilities found in Veeam Service Provider Console before version 9.3
CVE-2026-58067CVE-2026-58071CVE-2026-58072CVE-2026-58073CVE-2026-58074CVE-2026-58075CVE-2026-64630CVE-2026-64631CVE-2026-64633CVE-2026-64634Veeam Service Provider Console has multiple vulnerabilities allowing remote code execution and data breaches.- Arbitrary file write leading to remote code execution (CVE-2026-58072)
- Unauthenticated attacker can impersonate managed agents and steal credentials (CVE-2026-58073)
- High-privileged users can execute arbitrary code on the server (CVE-2026-58074)
- Low-privileged users can perform SQL injection to extract database contents (CVE-2026-64631) and access report data beyond shared scope (CVE-2026-64630) ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 Defensive-leaning breakdown of The Gentlemen intrusion using EtherRAT with Ethereum smart contract command and control.
- Detection surface includes X-Bot-Server HTTP header on EtherRAT polling traffic
- Scheduled task names: WinSvcUpdate2, WindowsUpdSvc31, WindowsUpdateSvc, SysUpdate
- LOLBAS chain: certutil.exe fetches ๐ Coverage: reddit.com ยท ๐ via r/netsec
โ ๏ธ UNDER-REPORTED
- House probe finds Chinese telecom firms kept footholds in US networks despite FCC bans
Chinese state-owned telecoms retained equipment and network ties in US after FCC restrictions, sustaining malicious infrastructure.
- Applies to China Mobile, China Telecom, and China Unicom operating in the US
- Equipment, data center space, and network connections persisted despite FCC revoking service authorizations from 2019 to 2022
- Networks appeared in routing paths to Salt Typhoon espionage servers in 2024
- Nearly 109,000 incidents of unauthorized US internet address hijacks linked to Chinese or Hong Kong networks
- No definitive evidence China Mobile USA employees knew of Salt Typhoon, but network ties could aid Beijing's cyber espionage ๐ Coverage: nextgov.com ยท ๐ via @metacurity@infosec.exchange