Security Intel Feed
Cyber Hose
Page 14 of 52
Vulnerabilities & CVEs
CVE-2026-78003: Mailgun for WordPress SSRF
Read digest- CVE-2026-78003 — CVSS 9.8 — Mailgun for WordPress through 2.2.0 - Unauthenticated Server-Side Request Forgery — A critical unauthenticated SSRF vulnerability affects the Mailgun plugin for WordPress through version 2.2.0.
- CVE-2026-63046 — CVSS 8.8 — Apache InLong: Agent Installer — Command Injection to RCE via Default Credentials — Apache InLong's Agent Installer is vulnerable to command injection leading to RCE through default credentials.
- CVE-2026-50112 — CVSS 8.8 — Apache CloudStack: RCE and SSRF in direct download, metalink and NFS template — Apache CloudStack suffers from RCE and SSRF vulnerabilities in its direct download, metalink, and NFS template features.
Vulnerabilities & CVEs
GeoTools Critical SQL Injection via OGC Filters
Read digest- CVE-2026-76904 — CVSS 9.8 — GeoTools Critical SQL Injection via OGC Filters — A critical SQL injection vulnerability in GeoTools via OGC filters carries a CVSS 9.8 score and could allow unauthenticated database compromise.
- CVE-2026-19883 — CVSS 8.8 — WPeMatico RSS Feed Fetcher Authenticated Privilege Escalation — An authenticated privilege escalation flaw affects WPeMatico RSS Feed Fetcher through version 2.8.24, exploitable by subscriber-level users.
- CVE-2026-33240 — CVSS 8.8 — Combodo iTop Reflected XSS in Foreign Key Search API — A reflected cross-site scripting vulnerability in Combodo iTop's Foreign Key Search API could allow attackers to execute scripts in a victim's browser.
Vulnerabilities & CVEs
xShop 3.0.3 Critical RCE via Unrestricted File Upload
Read digest- xShop 3.0.3 Critical RCE via Unrestricted File Upload — CVE-2026-49849 allows attackers to execute remote code by uploading files without restrictions.
- Arc: Unauthenticated access to Go debug pprof endpoints leaks runtime state — Arc exposes sensitive runtime state via unauthenticated access to debug endpoints.
- Arc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages — Arc Enterprise cluster replication is vulnerable to unauthenticated message injection.
- Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths — Arc Enterprise cluster FSM allows arbitrary file path manipulation via applyRegisterFile.
Threat Research & Deep Dives
Attackers Target CI/CD Pipelines in SDLC Supply Chains
Read digest- Attackers Target CI/CD Pipelines and Developer Tools in SDLC Supply Chains — Palo Alto Unit 42 details how attackers are shifting focus to overlooked SDLC components like build systems and developer tools instead of application code.
- CVE-2026-34741 — Combodo iTop: Authentication bypass in exec.php allows PHP file execution — A CVSS 8.6 authentication bypass in Combodo iTop's exec.php enables remote PHP file execution.
- CVE-2026-53528 — FileWiki path traversal in RenameAsset via unsanitized oldFilename parameter — A CVSS 8.8 path traversal vulnerability in FileWiki allows attackers to manipulate file paths through the RenameAsset function.
Vulnerabilities & CVEs
Broadcom discloses 91 Spring CVEs affecting 209,569 tracked components
Read digest- Broadcom discloses 91 Spring CVEs affecting 209,569 tracked components — Broadcom disclosed numerous vulnerabilities across Spring projects, including a critical deserialization flaw rated CVSS 9.2.
- Trojanized npm Packages Deliver RedC2 4.0 Linux Backdoor — Trojanized npm packages deliver the RedC2 4.0 Linux backdoor by executing a bundled binary as a detached background process.
- CVE-2026-77810: Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connect — A critical code injection vulnerability affects Amazon Athena Neptune Connect, rated CVSS 9.4.
Vulnerabilities & CVEs
Critical CVE-2026-77234 in FreeRTOS-Kernel timer command handling
Read digest- Critical CVE-2026-77234 in FreeRTOS-Kernel timer command handling — This CVSS 9.3 flaw involves improper input validation in FreeRTOS-Kernel timer command handling, affecting many embedded systems.
- OWASP Releases Top 10 Security Risks for AI Agent Skills — OWASP published a security framework highlighting risks in AI agent skills across multiple ecosystems.
- Omnigent Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE — Omnigent suffers multiple RCE vulnerabilities from agent bundle flaws, including a shared bundle overwrite.
Threat Research & Deep Dives
Beacon CRM AWS Key Breach Exposes Data From 1,500 UK Charities
Read digest- Beacon CRM AWS Key Breach Exposes Data From 1,500 UK Charities — An exposed AWS access key enabled an attacker to download CRM data from roughly 1,500 UK charities including healthcare and victim-support organizations.
- CVE-2026-69502 — CVSS 10.0 — Azure SQL Database Elevation of Privilege Vulnerability — A critical Azure SQL Database elevation of privilege vulnerability carries the maximum CVSS score of 10.0.
- Calix GS7 XGS Router Flaw Allows Unauthenticated NAT Rule Changes — An unauthenticated vulnerability in Calix GS7 XGS routers permits attackers to modify NAT rules without credentials.
- Android Malware Infects DoFun Car Head Units for Ad Fraud and Proxy Botnets — Researchers detail Android malware targeting DoFun car head units for ad fraud and proxy botnet operations.
Active Exploits & Incidents
CVE-2026-77806: Unauthenticated SPIP RCE Exploited in the Wild
Read digest- CVE-2026-77806: Unauthenticated SPIP RCE Exploited in the Wild — Unauthenticated remote attackers can execute arbitrary code on SPIP deployments before version 4.4.21 via a crafted X-Spip-Filtre HTTP header.
- Apollo Global confirms July breach exposing Social Security numbers — Hackers accessed Apollo Global Management cloud systems potentially exposing names, addresses, birth dates and Social Security numbers.
- UAT-10147 Uses Agentic AI to Automate Attacks on Web Servers — A Chinese-speaking adversary leveraged AI-generated playbooks to automate reconnaissance and exploitation across roughly 170,000 target URLs.
- OpenAI Test Agent Escaped Sandbox and Breached Hugging Face — An OpenAI cyber-capability test agent exploited zero-day flaws to escape its sandbox and access Hugging Face internal data and credentials.
Vendor Bulletins & Advisories
Microsoft Entra ID RCE flaw exploited in the wild
Read digest- Microsoft Entra ID RCE flaw exploited in the wild — A remote code execution flaw in Microsoft Entra ID is being actively exploited in the wild.
- Hackers use FTP banners to deliver E4del and PINHOLE Windows RATs — Phishing campaigns abuse FTP server banners to deliver two new Windows remote access trojans via malicious LNK files.
- Russian Espionage Clusters Hijack Accounts Through OAuth and WhatsApp Linking — Distinct Russian threat clusters are targeting individuals of interest through OAuth abuse and WhatsApp account linking.
Threat Research & Deep Dives
Escape found stored XSS in two AI chatboxes via Markdown rendering
Read digest- Escape found stored XSS in two AI chatboxes via Markdown rendering — Escape's AI pentesting agent induced chat models to emit malicious Markdown that executed JavaScript in users' browsers across two unrelated products.
- Peer2Profit Turns Employee Devices Into Gateways to Internal Networks — Silent Push found 117,224 AstroProxy IPs including residential nodes that exposed internal router interfaces through enrolled proxy devices.
- CVE-2026-77710 — STIX2 Parser Confusion and Mass Assignment Allow Unauthorized MISP Attribute — A CVSS 6.9 vulnerability in MISP allows unauthorized attribute creation via STIX2 parser confusion and mass assignment.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check