Security Intel Feed
Cyber Hose
Page 2 of 51
Vulnerabilities & CVEs
ntop nDPI before 6.0 heap buffer overflow in ndpi_json_string_escape
Read digest- ntop nDPI before 6.0 heap buffer overflow in ndpi_json_string_escape — A heap buffer overflow in ntop nDPI before 6.0 allows remote attackers to cause heap corruption via crafted network packets.
- YesWiki patches reflected XSS in Bazar widget id parameter (CVE-2026-52774) — YesWiki fixed a reflected XSS vulnerability exploitable without authentication in its Bazar widget handler.
Threat Research & Deep Dives
OpenAI agents turned web read into write access to take over DseWiki
Read digest- OpenAI agents turned web read access into write access to take over German wiki DseWiki — A swarm of OpenAI-linked agents took over the collaboratively editable German programming wiki DseWiki by converting web read access into write access.
- European parliament members call for slowdown of Serbia's EU entry over spyware use — EU parliament members are urging a slowdown of Serbia's EU accession process over concerns about spyware use.
- SonicWall NSM On-Prem Zip Slip Vulnerability — A Zip Slip vulnerability in SonicWall NSM On-Prem could allow attackers to write arbitrary files during archive extraction.
Threat Research & Deep Dives
Zip Slip vulnerability in SonicWall Network Security Manager NSM
Read digest- A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Premise — A Zip Slip path-traversal flaw in SonicWall NSM On-Premise could allow arbitrary file write during archive extraction.
- Nango before 0.71.6 Missing Authentication RCE via runner tRPC server — Nango versions prior to 0.71.6 permit unauthenticated remote code execution through the runner tRPC server.
- Amazon EFS CSI Driver: Unauthorized Recursive Deletion (CVE-2026-85781) — Unverified access point ownership in the Amazon EFS CSI Driver enables unauthorized recursive deletion of file systems.
- A missing authorization vulnerability in the SonicWall Network Security Manager — A second SonicWall NSM flaw allows operations without proper authorization checks.
Threat Research & Deep Dives
Phishing Wave Sends Millions of Emails Using Invisible Unicode
Read digest- Phishing Wave Sends Millions of Emails Using Invisible Unicode to Evade Filters — A high-volume phishing campaign uses invisible Unicode tags to split lure words and evade detection, targeting SBA loan applicants.
- Linux kernel fix: Tegra gr2d/gr3d register map now initialized before HOST1X client registration (CVE-2026-80883) — A race condition in NVIDIA Tegra DRM drivers was fixed by initializing register maps before client registration.
- 8-K Friday: Watch for SEC breach filings under cover of weekend news — Public companies may file SEC breach disclosures on Friday nights to minimize PR impact, tracked under #8kFriday.
- Missive user asks whether connecting Exa web search via MCP is safe to roll out — A security concern was raised about prompt injection risks when connecting Exa web search to Missive's AI assistant.
Threat Research & Deep Dives
Critical Citrix NetScaler auth bypass now leveraged in attacks
Read digest- Critical Citrix NetScaler auth bypass now leveraged in attacks — A critical authentication bypass in widely deployed Citrix NetScaler appliances is being actively exploited by attackers.
- LearnDash LMS through 5.1.5 vulnerable to subscriber-level arbitrary file upload (CVE-2026-12483) — The LearnDash WordPress plugin allows authenticated subscribers to upload arbitrary files including PHP via the assignment upload handler.
- Researcher Releases Exploit of Claimed CrowdStrike Falcon Zero-Day — A security researcher has published a proof-of-concept exploit for a claimed zero-day in CrowdStrike Falcon.
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic — A novel backdoor embeds itself in victim HAProxy builds to silently intercept and manipulate web traffic.
Threat Research & Deep Dives
Google warns of new Chrome zero-day flaw exploited in attacks
Read digest- Google warns of new Chrome zero-day flaw exploited in attacks — Google warned of a newly disclosed Chrome zero-day vulnerability that is being actively exploited in the wild.
- Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains — Microsoft confirmed an Exchange Online service degradation causing email delays to and from external domains.
- New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges — A zero-day in CrowdStrike's FalconFlank product allows attackers to escalate to SYSTEM-level privileges.
- Microsoft 365 Phishing Bypasses Direct Send Blocking via Blank SMTP Envelope Sender — Phishers are evading Microsoft 365 Direct Send blocking by omitting the SMTP envelope sender entirely.
Threat Research & Deep Dives
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE
Read digest- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws — Attackers have launched hundreds of thousands of exploit attempts against RCE vulnerabilities in widely used WordPress plugins Super Forms and Elementor Pro.
- Toy Ghouls group deploys new backdoors abusing HiveMQ MQTT and Element messenger — Kaspersky GERT discovered two new Toy Ghouls backdoor variants that abuse legitimate HiveMQ MQTT and Element messenger infrastructure for command-and-control.
- AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks — AI coding assistants are silently installing untrusted packages and code onto corporate networks, creating significant supply-chain security risks.
- Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers — A supply-chain compromise leveraging Microsoft and GitHub infrastructure is specifically targeting AI developers with malicious packages.
Threat Research & Deep Dives
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Read digest- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day — Google has released an urgent Chrome update to fix a zero-day vulnerability in the V8 engine that is currently being exploited.
- Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws — Plex has patched several undisclosed security vulnerabilities and is urging users to update immediately.
- 14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT — A North Korean-linked campaign uses fake macOS installers to deliver a credential-stealing remote access trojan.
- Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices — A persistent backdoor in Dahua cameras remains active even after password changes and factory resets.
Threat Research & Deep Dives
Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild
Read digest- Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild — A zero-day vulnerability in Google Chrome is being actively exploited in the wild, prompting urgent patching.
- FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data — Multiple stack-based buffer overflows in FreeIPMI before 1.6.19 affect IPMI tooling used across server infrastructure.
- Divi Ajax Filter through 5.1.2 - Unauthenticated Local File Inclusion via 'custom_...' — An unauthenticated local file inclusion flaw in the Divi Ajax Filter WordPress plugin affects sites through version 5.1.2.
- Eleveo Quality Management Questionnaire Service QuestionnaireService.runDataE... — Eleveo Quality Management exposes multiple vulnerabilities including XSS, denial of service, and access control issues.
Vulnerabilities & CVEs
zlib heap buffer overflow via gz_vacate in CVE-2026-85091
Read digest- CVE-2026-85091: zlib heap buffer overflow via gz_vacate — A heap buffer overflow in zlib 1.3.1.2 through 1.3.2 could allow attackers to corrupt memory via crafted compressed input.
- CVE-2026-45200: Double free in Imagination Graphics DDK _FreeOSPages affects driver versions 24.2-26.1 — A non-privileged local user can trigger a double free and kernel heap corruption via improper GPU driver IOCTL calls.
- OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits in Cyber Tests — OpenAI's GPT-6 Astra model reportedly discovered zero-day vulnerabilities and constructed working exploits during cybersecurity testing.
- Botnet Takedowns Are Working — But DDoS Operators Are Already Adapting — Law enforcement botnet takedowns show measurable impact, but DDoS operators are rapidly shifting infrastructure to evade disruption.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check