Security Intel Feed
Cyber Hose
Page 11 of 52
Active Exploits & Incidents
Cyberattack disrupts Boston Scientific's global operations
Read digest- Cyberattack disrupts Boston Scientific's global operations — Boston Scientific detected a cyberattack on August 25 that disrupted IT systems, customer orders, product shipments, and forced at least one plant shutdown.
- OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Operation — OpenAI removed Russian-origin ChatGPT accounts that generated English-language content to promote a pro-Russia influence campaign across multiple platforms.
- Treasury helps financial firms transition to quantum-resistant encryption — The U.S. Treasury is guiding financial firms toward quantum-resistant encryption to protect against future harvest-now-decrypt-later attacks.
Threat Research & Deep Dives
TranslatePress Flaw Enables Unauthenticated WordPress Account Takeover
Read digest- TranslatePress Flaw Enables Unauthenticated WordPress Account Takeover — CVE-2026-19632 allows unauthenticated attackers to extract password-reset keys and seize WordPress admin accounts on over 400,000 sites.
- SonicWall NetExtender Flaws Enable Arbitrary File Writes as Root — Two vulnerabilities in the SonicWall NetExtender Linux client enable path traversal file writes as root and symlink manipulation in the auto-upgrade process.
- Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign — Attackers used signed remote monitoring tools and convincing document lures to blend malicious access with normal IT operations across 46 countries.
- Q2 2026 exploit activity spans AI frameworks, exposed systems and DeFi — Rapid7 counted 8,539 high- and critical-severity disclosures with a 76% rise in public proof-of-concept code across enterprise, AI, and DeFi technologies.
Threat Research & Deep Dives
Core Werewolf Uses CoreRAT to Take Over Russian Windows Systems
Read digest- Core Werewolf Uses CoreRAT to Take Over Russian Windows Systems — A previously undocumented C++ RAT is being deployed against Russian public-sector and defense organizations via Telegram phishing campaigns.
Vendor Bulletins & Advisories
Russia Blocks DoH and DoT as Hacktivists Leak Spanish Personnel Data
Read digest- Russia Blocks DoH and DoT as Hacktivists Leak Spanish Personnel Data — Russia blocked DNS-over-HTTPS and DNS-over-TLS protocols while hacktivists leaked data belonging to Spanish police and military personnel.
- Microsoft Teams outage disrupted meetings and screen sharing in Asia-Pacific — A Microsoft Teams outage disrupted meetings and screen sharing for users across the Asia-Pacific region.
Vulnerabilities & CVEs
Trestle SSTI vulnerability CVE-2026-54757 disclosed with CVSS 7.8
Read digest- CVE-2026-54757 — Trestle Server-Side Template Injection via Recursive Template Re-evaluation — A CVSS 7.8 server-side template injection in Trestle enables code execution through recursive template re-evaluation.
- CVE-2026-41707 — Spring Security DPoP Proof Replay vulnerability — Spring Security's DPoPProofJwtDecoderFactory is vulnerable to DPoP proof replay, rated CVSS 7.4.
- CVE-2026-44476 — Doorkeeper OpenID Connect Dynamic Client Registration flaw — Doorkeeper OpenID Connect's dynamic client registration creates public clients insecurely, rated CVSS 6.3.
Threat Research & Deep Dives
Hidden Email Prompts Can Manipulate Microsoft Copilot Summaries
Read digest- Hidden Email Prompts Can Manipulate Microsoft Copilot Summaries — Attackers can embed invisible HTML prompts in emails to produce false Copilot summaries, deceptive alerts, or malicious instructions via cross-prompt injection.
- CVE-2026-65083 — CVSS 9.9 — NVIDIA OpenShell for Linux sandbox provisioning vulnerability — A critical vulnerability in NVIDIA OpenShell for Linux's sandbox provisioning could allow attackers to escape isolation controls.
- CyberLeek leaks unreleased GTA VI footage in extortion-style campaign — Threat actor CyberLeek published unreleased GTA VI clips and assets in a drip-feed extortion campaign tied to crypto donations and a memecoin.
- CVE-2026-80104 — CVSS 9.3 — DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload — A path traversal flaw in DB-GPT's skill upload feature allows arbitrary file writes through crafted filenames.
Active Exploits & Incidents
Attackers Exploit Zimbra Command-Injection Flaw for Unauthenticated
Read digest- Attackers Exploit Zimbra Command-Injection Flaw for Unauthenticated RCE — CVE-2026-73570 enables unauthenticated OS command injection via crafted SMTP requests in Zimbra Collaboration Suite before version 10.1.20.
- DDoS attack disrupts Norway's government digital services — A sustained DDoS attack flooded Norway's shared government infrastructure, causing outages across ID-porten, Altinn, and other public-sector portals.
- Kaltura HTML5 Player Flaws Enable Arbitrary File Reads and Remote Code Execution — Two Kaltura HTML5 player vulnerabilities allow unauthenticated local file disclosure and remote code execution via unsafe deserialization.
- Chinese Hackers Scale Cyberattacks With Low-Cost AI Tools — Chinese-linked operators are combining multiple AI subagents to automate reconnaissance, exploitation, and persistence against government and internet-facing targets.
Active Exploits & Incidents
Nutex Health says attackers stole data in cyberattack
Read digest- Nutex Health says attackers stole data in cyberattack — Nutex Health is investigating a breach where an unauthorized party accessed and exfiltrated data from its servers.
- ASOS Reports Customer Account Access Using Compromised Credentials — ASOS customers were affected by unauthorized account access using externally sourced credentials.
- NVIDIA NemoClaw flaw lets malicious webpages poison local AI models — A malicious webpage can control NemoClaw’s local Ollama server, modifying AI models via an exposed API.
- ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Attack Commands — ToxNetV2 botnet leverages NVIDIA AI to craft shell and SSH attack commands targeting AArch64 Linux systems.
- Marimo Flaw Let Crafted Notebooks Execute MCP Commands in Edit Mode — Marimo notebooks before version 0.23.15 allowed attacker-supplied MCP commands execution via crafted notebooks.
Active Exploits & Incidents
Attackers breach 274 Zimbra servers via actively exploited RCE flaw
Read digest- Attackers breach 274 Zimbra servers through actively exploited RCE flaw — Unauthenticated attackers exploit an SNMP notification RCE in Zimbra Collaboration Suite, compromising 274 servers with 8,200 more unpatched.
- Mirage2FA Targets 9,426 Microsoft 365 Accounts and Steals Sessions — An AiTM phishing campaign steals M365 credentials, MFA codes, and session cookies across 94 countries with over 4,500 potentially compromised addresses.
- CVE-2026-8508 Enables Captive-Portal Bypass on 39 Zyxel Models — A pre-authentication flaw lets unauthenticated attackers bypass social-login controls on 39 Zyxel access points and routers via the guest Wi-Fi captive portal.
Threat Research & Deep Dives
Operation Jackal IV arrests 58 suspects in global cybercrime crackdown
Read digest- Operation Jackal IV arrests 58 suspects in global cybercrime crackdown — Authorities arrested 58 suspects linked to West African cybercrime networks involved in scams across 22 countries.
- EvilTokens Hijacks Microsoft 365 Sessions for AI-Assisted Fraud — EvilTokens steals Microsoft 365 tokens to conduct AI-assisted targeted financial fraud across 344 organizations.
- Malicious Rust Crates Delivered Build-Time Malware Across Developer Environments — Compromised Rust crates executed malware during builds, affecting developers on Windows, macOS, and Linux.
- Fake Codex ads trick Mac developers into running AMOS-like malware — Fake OpenAI Codex ads deliver macOS infostealer malware to developers via malicious Google ads and sites.
- Unit 42 Finds Most AI-Enabled Malware Samples Are Not Operational — Most AI-enabled malware samples remain in research stages, with few observed in production environments.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check