Security Intel Feed
Cyber Hose
Page 18 of 52
Threat Research & Deep Dives
Claude Code Drove a Gentlemen Ransomware Affiliate's Intrusion
Read digest- Claude Code Drove a Gentlemen Ransomware Affiliate's Intrusion — A suspected Gentlemen affiliate used Claude Code interactively across ransomware intrusions against at least eight organizations.
- Apple Patches Dozens of WebKit Flaws in iOS and macOS Updates — Apple fixed dozens of WebKit vulnerabilities across iOS, iPadOS, and macOS that could corrupt memory, escape sandboxes, or exfiltrate data.
- CVE-2026-15371 — Velociraptor Stored XSS in URL column types — A CVSS 8.1 stored cross-site scripting flaw in Velociraptor's web GUI could be exploited via URL column types.
Active Exploits & Incidents
Pokémon Center customer data exposed in CEVA Logistics breach
Read digest- Pokémon Center customer data exposed in CEVA Logistics breach — A breach of CEVA Logistics servers exposed Pokémon Center customer data across the UK and Germany, disrupting eight warehouses and causing shipping delays.
Vulnerabilities & CVEs
MLflow Unauthenticated SSRF via Webhook Test Endpoint
Read digest- CVE-2026-64849 — CVSS 9.3 — MLflow Unauthenticated SSRF via Webhook Test Endpoint — A high-severity SSRF vulnerability in MLflow allows unauthenticated attackers to abuse the webhook test endpoint.
- DeadLock Ransomware Uses Polygon Smart Contracts to Resist Takedowns — Group-IB details how DeadLock ransomware leverages Polygon blockchain smart contracts to evade takedown efforts.
Threat Research & Deep Dives
Unisoc VoLTE Exploit Chain Enables Full Android Kernel Access
Read digest- Unisoc VoLTE Exploit Chain Enables Full Android Kernel Access — Researchers demonstrated full Android kernel access via a malformed SIP video call exploiting Unisoc modem firmware across multiple budget device models with no vendor fix available.
- CVE-2026-71424 — CVSS 9.6 — Onyx AI Platform Critical OAuth Token Exposure — A critical OAuth token exposure vulnerability in the Onyx AI platform carries a CVSS score of 9.6 and could allow attackers to hijack authentication tokens.
- CVE-2026-70495 — CVSS 8.8 — search-v2-operator Privilege Escalation to Cluster Admin — A privilege escalation flaw in search-v2-operator enables attackers to elevate to cluster admin privileges with a CVSS score of 8.8.
Active Exploits & Incidents
Threat actor claims 3.6 million records stolen from Azure tenants
Read digest- Threat actor claims 3.6 million records stolen from Azure tenants — Nine large enterprises including McDonald's and TCS were named in an alleged theft of 3.64 million employee records from Azure and Entra tenants.
- Critical GitLab flaws could let attackers delete projects or inject code — GitLab fixed a critical CVSS 9.4 GraphQL flaw allowing unauthenticated attackers to modify or delete public projects across CE and EE editions.
- BlackFile Rebrand Redact Targets Financial and Professional Services Firms — UNC6671, formerly BlackFile, extorts financial and professional services firms via help-desk impersonation and scripted Microsoft 365 data theft.
Vulnerabilities & CVEs
CVE-2026-74253: CVSS 10.0 unauthenticated RCE in Joomla extension
Read digest- CVE-2026-74253 — CVSS 10.0 — Joomla Extension Unauthenticated RCE — An unauthenticated remote code execution vulnerability rated CVSS 10.0 affects a Joomla extension from regularlabs.com.
- CVE-2026-74254 — CVSS 9.3 — Joomla Extension SQL injection in Page Builder CK — A high-severity SQL injection vulnerability affects Page Builder CK before version 3.6.5 in a Joomla extension from joomlack.fr.
- CVE-2026-62982 — CVSS 8.8 — Glances incomplete fix allows sanitizer bypass — An incomplete fix for a prior Glances vulnerability allows the action-template sanitizer to be bypassed.
Active Exploits & Incidents
Baylor Genetics hack exposed sensitive patient and employee data
Read digest- Baylor Genetics hack exposed sensitive patient and employee data — Baylor Genetics disclosed that a June cyberattack exposed sensitive patient and employee information including lab results, Social Security numbers, and financial details.
- CVE-2026-75045 — CVSS 9.1 — JetBrains YouTrack unauthenticated vulnerability — A high-severity vulnerability in JetBrains YouTrack before multiple 2026 versions could allow unauthenticated exploitation.
- C2Looper Rust Backdoor Likely Supports Ransomware Operations via GitHub C2 — Zscaler identified a Rust-based backdoor using GitHub for command-and-control that may be delivered through a multi-stage ClickFix chain to enable ransomware activity.
- MCPwned Presentation Details a Skeleton-Key Vulnerability in MCP Servers — Jonathan Leitschuh presented research at BSidesSF 2026 describing a skeleton-key vulnerability capable of compromising Model Context Protocol servers used by AI assistants.
Threat Research & Deep Dives
CISA Adds Ray Code-Injection Flaw CVE-2025-62593 to KEV Catalog
Read digest- CISA Adds Ray Code-Injection Flaw CVE-2025-62593 to KEV Catalog — CISA added a Ray code-injection vulnerability enabling remote code execution to its Known Exploited Vulnerabilities catalog.
- CircleCI MCP Server Exposed to Unauthenticated RCE via Allowlist Bypass — CircleCI's MCP server allows unauthenticated remote code execution by bypassing its Host/Origin allowlist with any non-browser client.
- Certighost flaw lets domain users abuse Enterprise CAs for privilege escalation — CVE-2026-54121 lets a standard domain user escalate privileges by turning an Enterprise CA into a Domain Controller via AD CS enrollment abuse.
- AI-authored GitHub Actions change exposed Snowflake repo to workflow injection — Copilot Autofix introduced a workflow injection flaw in a Snowflake repository that allowed unauthenticated issue titles to execute arbitrary commands.
Threat Research & Deep Dives
TeamPCP Trivy Compromise Led to Malicious LiteLLM Releases
Read digest- TeamPCP Trivy Compromise Led to Malicious LiteLLM Releases — Compromised Trivy tooling exposed LiteLLM's PyPI publishing token, enabling malicious releases that harvested credentials from over 2,500 organizations.
- France's DGFiP confirms taxpayer data theft affecting 678,000 users — France's tax authority confirmed unauthorized access to its systems resulting in the theft of taxpayer data for 678,000 users.
- AppFlowy Cloud Exposes Authenticated SQL Injection in qcuiknote — CVE-2026-16007 allows authenticated users of self-hosted AppFlowy Cloud deployments to inject arbitrary SQL and exfiltrate database contents.
Threat Research & Deep Dives
Attackers Probe GeoServer SQL Injection That Can Enable RCE
Read digest- Attackers Probe GeoServer SQL Injection That Can Enable RCE — Unauthenticated attackers can inject SQL through CQL filters on public OGC endpoints, and elevated PostgreSQL privileges can escalate to OS command execution.
- MessiahGPT Offers Criminals Low-Cost AI for Ransomware and Phishing — A low-cost criminal AI service advertises ransomware, phishing kits, and stealers on dark-web forums with subscriptions starting around eight dollars per month.
- CVE-2026-15623 — CVSS 9.4 — Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widget — A high-severity authenticated blind SQL injection vulnerability affects the Google Cloud SecOps SOAR dashboard widget.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check