Security Intel Feed
Cyber Hose
Page 19 of 52
Active Exploits & Incidents
SafePal breach exposes order data of nearly 40,000 customers
Read digest- SafePal breach exposes order data of 39,798 customers — An authorization flaw in SafePal’s order-tracking plug-in exposed customer order details, exploited for phishing and scams.
- Edimax EW-7478APC buffer overflow vulnerabilities CVE-2026-19961 and CVE-2026-19959 — Two CVSS 8.6 buffer overflow vulnerabilities were identified in Edimax EW-7478APC devices.
Threat Research & Deep Dives
Black Hat: Enterprise Java pre-auth RCE and AI-agent hijacking
Read digest- Black Hat speakers detail enterprise Java pre-auth RCE and AI-agent hijacking — Black Hat speakers discussed pre-auth remote code execution in enterprise Java deployments and methods for hijacking AI coding agents.
- Authenticated command injection found in Zyxel export-cgi PKCS#12 handling — CVE-2026-6837 allows authenticated attackers to execute commands on Zyxel devices via crafted PKCS#12 certificate export input.
Active Exploits & Incidents
DDoS attacks disrupt Threema messaging services for two days
Read digest- DDoS attacks disrupt Threema messaging services for two days — Large-scale DDoS attacks targeted Threema's hosted services and colocation partner, causing extended outages for users and work customers.
- CVE-2026-19598 — CVSS 9.8 — Pods through 3.3.9 Unauthenticated Privilege Escalation via Authorization Bypass — A critical CVSS 9.8 vulnerability allows unauthenticated privilege escalation in Pods versions through 3.3.9 via authorization bypass.
- CVE-2026-73056 — CVSS 9.3 — SiYuan Kernel API Token Brute-Force — A high-severity brute-force vulnerability in SiYuan's Kernel API token could allow attackers to compromise authentication.
Active Exploits & Incidents
TheHatman Sells Azure Directory Data From Nine Major Enterprises
Read digest- TheHatman Sells Azure Directory Data From Nine Major Enterprises — A threat actor is selling employee directories from Azure and Entra tenants of nine major enterprises, with records tied to infostealer-compromised credentials.
Vulnerabilities & CVEs
Critical CVSS 9.8 flaw in ARforms plugin through 1.8.5
Read digest- Critical CVSS 9.8 flaw in ARforms plugin through 1.8.5 — CVE-2024-13784 is an unauthenticated critical vulnerability in the ARforms WordPress plugin through version 1.8.5.
Threat Research & Deep Dives
WP Travel Engine up to 6.8.4 exposes customer booking data
Read digest- WP Travel Engine up to 6.8.4 exposes customer booking data — CVE-2026-16737 lets unauthenticated attackers read and overwrite customer booking and billing records via unauthorized cart actions.
- Bookly WordPress Plugin through 27.7 Exposed to Unauthenticated Stored XSS — Unauthenticated attackers can inject stored XSS payloads that execute when administrators view diagnostic logs.
- Kirki WordPress Plugin Through 6.1.1 Exposes User Metadata — Authenticated users can read sensitive metadata belonging to any WordPress user including administrators.
- Gallery by BestWebSoft through 4.7.9 Exposes Authenticated SQL Injection — Unsanitized array keys in post metadata enable Editor-level users to extract sensitive database information via SQL injection.
Vulnerabilities & CVEs
CVE-2026-16098: Unauthenticated File Upload in ProSolution WP
Read digest- CVE-2026-16098: Unauthenticated Arbitrary File Upload in ProSolution WP Client — A CVSS 9.8 flaw allows unauthenticated arbitrary file upload in ProSolution WP Client through version 2.0.10.
- CVE-2026-14524: Unauthenticated Arbitrary File Deletion in ProSolution WP Client — A CVSS 9.1 flaw enables unauthenticated arbitrary file deletion in ProSolution WP Client through version 2.0.8.
Threat Research & Deep Dives
SiYuan before v3.7.4 affected by 11 authentication, XSS and RCE flaws
Read digest- SiYuan before v3.7.4 affected by 11 authentication, XSS and RCE flaws — Eleven vulnerabilities including authentication bypasses, stored XSS, server-side template injection, and remote code execution affect SiYuan versions before 3.7.4.
- Evooo1Bot Mirai Variant Targets Internet-Facing Edge Devices — FortiGuard Labs identified a Mirai-derived Linux botnet targeting internet-facing edge devices from multiple vendors.
- CVE-2026-74764 — CVSS 10.0 — Path Traversal in TAR Archive Extraction — A CVSS 10.0 path traversal flaw in TAR archive extraction allows arbitrary file writes in Pandora.
Active Exploits & Incidents
Evooo1Bot Mirai Botnet Hijacks Routers as SOCKS5 Relay Nodes
Read digest- Evooo1Bot Mirai Botnet Hijacks Routers as SOCKS5 Relay Nodes — Evooo1Bot exploits internet-facing edge devices from multiple vendors using a long chain of known CVEs to build a Mirai-derived Linux botnet.
Vendor Bulletins & Advisories
Microsoft to Make Passkeys Default in Entra ID, Retire SMS MFA
Read digest- Microsoft to Make Passkeys Default in Entra ID, Retire SMS and Voice MFA — Microsoft will make passkeys the default authentication method in Entra ID, ending SMS and voice MFA by February 2027.
- CVE-2026-18438 — Templately through 3.7.1 — Authenticated Arbitrary File Upload to RCE — A CVSS 8.8 flaw in the Templately WordPress plugin allows authenticated contributors to achieve remote code execution via arbitrary file upload.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check