View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

CISA Adds Ray Code-Injection Flaw CVE-2025-62593 to KEV Catalog

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • CISA Adds Ray Code-Injection Flaw CVE-2025-62593 to KEV Catalog CVE-2025-62593
    CISA added a Ray code-injection flaw to its exploited-vulnerabilities catalog.

    • Ray developers and users may be affected.
    • CVE-2025-62593 is a Ray code-injection vulnerability that enables remote code execution.
    • The flaw is exploitable through Firefox and Safari.
    • CISA added the vulnerability to KEV on August 18, 2026; exploitation in ransomware campaigns is listed as unknown.
      πŸ“„ Source: github.com Β· πŸ“Ž Coverage: cisa.gov Β· πŸ‘ via CISA KEV
  • CircleCI MCP Server Exposed to Unauthenticated RCE via Allowlist Bypass
    CircleCI’s MCP server is vulnerable to unauthenticated remote code execution.

    • The issue affects users running CircleCI’s MCP server with AI assistants such as Claude or Cursor.
    • The MCP server allows unauthenticated remote code execution.
    • Its Host/Origin allowlist can be bypassed by any non-browser client.
    • The issue is tracked as GHSA-xv5j-cwgj-22r4; no CVE identifier is listed.
      πŸ“„ Source: reddit.com Β· πŸ“Ž Coverage: remedio.io Β· πŸ‘ via r/netsec
  • Certighost flaw lets domain users abuse Enterprise CAs for privilege escalation CVE-2026-54121
    CVE-2026-54121 lets a standard domain user escalate privileges through an Enterprise CA.

    • Active Directory environments using Enterprise Certificate Authorities are affected.
    • CVE-2026-54121 can let a standard domain user turn an Enterprise CA into a Domain Controller.
    • The flaw abuses an AD CS enrollment chase or callback path.
    • The CA trusts requester-supplied attributes when resolving the identity placed in an issued certificate.
      πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer
  • AI-authored GitHub Actions change exposed Snowflake repo to workflow injection
    Wiz found that Copilot Autofix introduced a workflow injection flaw in a Snowflake repository.

    • Snowflake’s public snowflakedb/snowflake-connector-net repository was affected.
    • The jira_issue.yml workflow allowed unauthenticated GitHub issue titles to execute arbitrary commands on a GitHub Actions runner.
    • Copilot Autofix co-authored commit 4a1b8ce on June 18, 2026, replacing env-and-jq parsing with direct shell interpolation of the issue title.
    • Wiz Red Agent exploited the flaw on June 23 using a crafted issue title and exfiltrated Jira credentials to subdomain.oast.me from runner IP 20.106.182.197.
    • The exposed token authenticated as qa@snowflake.net and provided read access to Snowflake Jira projects.
      πŸ“„ Source: github.com Β· πŸ“Ž Coverage: wiz.io Β· πŸ‘ via @metacurity@infosec.exchange
  • Operation ASTERIX Exposed a Crypto-Fraud Pipeline Using AI-Assisted Tooling
    Rapid7 uncovered an exposed infrastructure supporting a cryptocurrency fraud operation.

    • Cryptocurrency users were targeted by the operation.
    • The exposed server held phone-number datasets, validated leads, phishing panels, fake wallets, and exfiltration tools.
    • Vishing and phishing workflows used voice-dialing scripts and impersonation lures.
    • AI coding assistants helped build Electron applications, obfuscate code, modify phishing infrastructure, and package malware.
    • Rapid7-listed infrastructure included 136.0.213.184:1337 and atechservicecentre.co.uk.
      πŸ“„ Source: github.com Β· πŸ“Ž Coverage: rapid7.com Β· πŸ‘ via rapid7.com (discovered)
  • CrowdStrike Trains AI to Reason Through Security Detection Triage
    CrowdStrike developed reasoning-enabled AI models for detection triage.

    • CrowdStrike Charlotte AI triage models assess security detections.
    • The models classify alerts as true positives or false positives with calibrated confidence scores.
    • NVIDIA Nemotron-powered models weigh command lines, behavioral context, and other signals.
    • Step-by-step reasoning produces a transparent chain before issuing a verdict.
      πŸ“Ž Coverage: crowdstrike.com Β· πŸ‘ via CrowdStrike Blog
  • Detecting NTDS.dit Extraction Attempts on Domain Controllers
    Attackers may extract NTDS.dit from domain controllers to steal Active Directory credentials.

    • Active Directory environments and domain controllers are affected.
    • NTDS.dit contains directory objects, password hashes, and other identity data.
    • Attackers can copy or extract the database for offline credential attacks and domain access.
    • Shadow copies can be used to access and copy ntds.dit from the domain controller.
      πŸ“Ž Coverage: clearpathsecurity.co.uk Β· πŸ‘ via securityboulevard.com (discovered)

πŸ”“ CVEs & KEV

  • CVE-2026-19693 β€” CVSS 8.1 β€” extract-zip arbitrary file write outside the destination directory via a syml...

  • CVE-2026-16138 β€” CVSS 8.0 β€” Remote code execution via unsafe deserialization in Progress ShareFile Storag...

  • CVE-2026-15218 β€” CVSS 7.9 β€” Models-as-a-service: red hat openshift ai: maas-api and maas-controller servi...

  • CVE-2026-59910 β€” CVSS 7.8 β€” Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz...

  • CVE-2026-56686 β€” CVSS 7.8 β€” Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz...

  • CVE-2026-56090 β€” CVSS 7.3 β€” Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Searc...

  • CVE-2026-56685 β€” CVSS 7.3 β€” Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz...

  • CVE-2026-68821 β€” Microsoft App Installer β€” CVSS 7.3 β€” Pretty laughable/predictable MS response

  • CVE-2026-16137 β€” CVSS 7.2 β€” Path traversal via unsanitized upload filename leads to arbitrary file write ...

  • CVE-2026-16139 β€” CVSS 7.2 β€” Arbitrary file write via path traversal in Progress ShareFile Storage Zones C...

  • CVE-2026-59909 β€” CVSS 7.1 β€” Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vuln...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check