Security Intel Feed
Cyber Hose
Page 10 of 51
Vendor Bulletins & Advisories
CISA Adds Six Actively Exploited Flaws to KEV Catalog
Read digest- CISA Adds Six Actively Exploited Flaws to KEV Catalog — CISA's KEV catalog update flags six vulnerabilities as actively exploited, requiring urgent remediation.
- Spring Security UnboundID LDAP Server Critical Admin Credential Exposure (CVE-2026-59270) — A CVSS 9.4 vulnerability in Spring Security's UnboundID LDAP Server exposes critical admin credentials.
- Joomla Extension Privileged Remote Code Execution (CVE-2026-77991) — A CVSS 9.4 privileged RCE vulnerability affects a Joomla extension from joomlaeventmanager.net.
Vendor Bulletins & Advisories
WatchGuard Agent Flaws Enable Unauthenticated Code Execution on
Read digest- WatchGuard Agent Flaws Enable Unauthenticated Code Execution on Windows — Two critical WatchGuard Agent for Windows vulnerabilities (CVSS 9.3 and 9.4) enable unauthenticated remote code execution with SYSTEM-level privileges from an adjacent network.
- Study finds LLM agents overshare private data in most tool calls — Research shows GPT-4o, Claude 3.5 Sonnet, and Llama-3.3-70B include unnecessary privacy-sensitive data in 81–88% of tool calls, even with explicit privacy instructions.
- Adobe Campaign Classic flaws enable unauthenticated arbitrary code execution — Adobe disclosed unauthenticated arbitrary code execution vulnerabilities in Campaign Classic.
Vendor Bulletins & Advisories
Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities in 9, 10.1, 8.5
Read digest- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Affecting 9, 10.1 and 8.5 — Apache Tomcat patched 11 vulnerabilities across supported and end-of-life releases, including security-constraint bypasses, access-control bypasses, and an HTTP/2 denial-of-service flaw.
- Reported Log4j FOIS Bypass May Enable RCE in Narrow Setups — A reported Log4j deserialization bypass exploits MarshalledObject to evade FilteredObjectInputStream allowlists, potentially enabling RCE in narrowly configured applications.
- CVE-2026-80202: Kimai Authorization Bypass via TimesheetVoter (CVSS 9.3) — Kimai before 2.56.0 suffers an authorization bypass via TimesheetVoter, the highest-scoring CVE in a batch of multiple Kimai vulnerabilities disclosed this run.
Vulnerabilities & CVEs
KubePi unauthenticated SSO/OIDC flaw enables admin account takeover
Read digest- CVE-2026-65956 — CVSS 10.0 — KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover — A CVSS 10.0 vulnerability in KubePi allows unauthenticated attackers to exploit SSO/OIDC configuration and take over admin accounts.
- Two vulnerabilities affect Reactor Netty HTTP servers — Spring issued an advisory for two vulnerabilities affecting Reactor Netty HTTP servers used across many Spring-based applications.
- OpenStack Keystone flaw exposes cloud-wide role assignments to readers — An OpenStack Keystone vulnerability exposes cloud-wide role assignment data to unauthorized readers.
- CVE-2026-16639 — CVSS 9.8 — Internationalization Single Sign-On - Critical - Access bypass — A critical access bypass flaw in the Internationalization Single Sign-On module carries a CVSS 9.8 rating.
Vendor Bulletins & Advisories
Critical Avada WordPress Theme Flaw Enables Unauthenticated RCE
Read digest- Critical Avada WordPress Theme Flaw Enables Unauthenticated RCE — A six-step chain of authorization and input-validation weaknesses in the Avada theme with over one million sales enables unauthenticated arbitrary file writes and PHP execution.
- Trump order restricts risky foreign equipment in U.S. bulk-power system — A national emergency declaration empowers the Energy Secretary to prohibit acquisitions of covered foreign equipment in the U.S. bulk-power system.
- Dark Caracal Deploys GoCaracal Malware Framework in Latin America — The Dark Caracal APT group is using the new GoCaracal framework for cyberespionage against Latin American organizations, stealing files and credentials.
- CVE-2026-65641 — CVSS 9.3 — Unauthenticated SMB authentication coercion — A high-severity vulnerability allows an unauthenticated network attacker to coerce SMB authentication, the highest-CVSS entry in this run.
Active Exploits & Incidents
FBI Disrupts Chinese Espionage Platform Targeting U.S. Agencies
Read digest- FBI Disrupts Chinese Espionage Platform Targeting U.S. Agencies — The FBI seized infrastructure linked to China-based Nanjing Xinjiuwei that targeted NASA, the Federal Reserve, and dozens of organizations across multiple sectors for over eight years.
- CVE-2026-70419 — Dell Cloud Disaster Recovery RCE via OS Command Injection — A CVSS 9.1 OS command injection flaw in Dell Cloud Disaster Recovery could allow remote code execution.
Active Exploits & Incidents
Citrix NetScaler CVE-2026-8452 exploited in the wild
Read digest- Citrix NetScaler CVE-2026-8452 exploited in the wild — A pre-authentication heap overflow in Citrix NetScaler ADC and Gateway enables remote code execution via crafted SAML messages, with public PoC and active exploitation.
- UAT-10147 Exploited AjaxPro CVE-2021-23758 Against Web Servers — Threat actor UAT-10147 used AI-assisted intrusion campaigns to exploit AjaxPro deserialization flaws across roughly 170,000 URLs, deploying web shells and RATs.
- Microsoft details attacks targeting LiteLLM, RAGFlow and Kestra AI workloads — Attackers compromised exposed AI infrastructure to steal model-provider keys, database credentials, and monetize compute through cryptomining.
- Nimbus Manticore Adds TWOSTROKE-Like Backdoor and Reverse SSH Tool — Group-IB identified new Nimbus Manticore malware targeting defense, aerospace, and IT service providers with a C++ backdoor and reverse SSH tool.
Active Exploits & Incidents
Hackers Probe Microsoft SharePoint RCE Chain After PoCs Published
Read digest- Hackers Probe Microsoft SharePoint RCE Chain After PoCs Published — Public PoCs for a SharePoint JWT bypass and BCS remote code execution chain are being actively probed against 8,700-plus exposed deployments.
- CISA: Hackers Targeted More Than 100 U.S. Water Systems in July — Attackers scanned exposed PLCs with default credentials across more than a dozen states, disrupting pumps and triggering boil-water advisories.
- Bishop Fox Demonstrates Unauthenticated RCE in Veeam Service Provider Console — Chaining two CVEs lets an unauthenticated attacker impersonate a backup agent and achieve remote code execution on multi-tenant VSPC servers.
Active Exploits & Incidents
FBI disrupts proxy network used in Chinese espionage operations
Read digest- FBI disrupts proxy network used in Chinese espionage operations — The FBI disrupted a proxy infrastructure used to profile targets and support data theft by China-linked operators across U.S. defense, government, healthcare, finance, and energy sectors.
- Ubiquiti patches critical vulnerabilities across UniFi products — Ubiquiti patched multiple remotely exploitable command injection flaws in UniFi Access, Protect, Network, and OS Server with CVSS scores ranging from 9.0 to 9.9.
- NovaCookies Phishing Service Steals Microsoft 365 Sessions for $320 Monthly — A subscription phishing service targets Microsoft 365 users at hundreds of organizations using adversary-in-the-middle relays and genuine DocuSign lures.
- Suspected Chinese-Speaking Operator Breached Philippine Nuclear and Naval Groups — A suspected Chinese-speaking operator stole reactor data and credentials from a Philippine nuclear agency and a Navy-contracted marine engineering firm.
Active Exploits & Incidents
Cyberattack disrupts Boston Scientific's global operations
Read digest- Cyberattack disrupts Boston Scientific's global operations — Boston Scientific detected a cyberattack on August 25 that disrupted IT systems, customer orders, product shipments, and forced at least one plant shutdown.
- OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Operation — OpenAI removed Russian-origin ChatGPT accounts that generated English-language content to promote a pro-Russia influence campaign across multiple platforms.
- Treasury helps financial firms transition to quantum-resistant encryption — The U.S. Treasury is guiding financial firms toward quantum-resistant encryption to protect against future harvest-now-decrypt-later attacks.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check