Security Intel Feed
Cyber Hose
Page 21 of 52
Active Exploits & Incidents
Attackers Probe Unpatched GeoServer SQL Injection Zero-Day
Read digest- Attackers Probe Unpatched GeoServer SQL Injection Zero-Day — Attackers are actively probing an unpatched GeoServer zero-day affecting the jsonArrayContains function with no CVE assigned yet.
- CVE-2026-12949 — Wishlist Member X Unauthenticated Account Takeover — A CVSS 9.8 flaw in Wishlist Member X through 3.34.1 allows unauthenticated account takeover.
Vulnerabilities & CVEs
Critical PDF::WebKit argument injection flaw (CVE-2026-16770)
Read digest- Critical PDF::WebKit argument injection flaw (CVE-2026-16770) — CVSS 9.8 argument injection in PDF::WebKit for Perl could allow remote code execution through wkhtmltopdf.
- OpenChoreo Workflow Template command injection (CVE-2026-73667) — CVSS 8.8 command injection vulnerability in OpenChoreo Workflow Template could allow attackers to execute arbitrary commands.
- PDF::WebKit OS command injection via Perl (CVE-2026-17431) — CVSS 6.1 OS command injection in PDF::WebKit for Perl via a two-step process could lead to arbitrary command execution.
Vulnerabilities & CVEs
Critical CVE-2026-18749 (CVSS 9.8) authorisation flaw disclosed
Read digest- CVE-2026-18749 — CVSS 9.8 — authorisation bypass in case management — A critical CVSS 9.8 vulnerability involving a type=track branch authorisation flaw has been disclosed.
- CVE-2026-18744 — CVSS 6.5 — authenticated participant data exposure — An authenticated case participant can fetch another vendor's data due to insufficient access controls.
Active Exploits & Incidents
Clop-linked actors target Windchill and FlexPLM for data theft
Read digest- Clop-linked actors target Windchill and FlexPLM for engineering-data theft — Clop-linked actors exploit CVE-2026-12569 unauthenticated RCE in PTC Windchill and FlexPLM to steal engineering data for extortion.
- CSS Attacks Against Webmail Can Steal Passwords and Tokens — Researchers demonstrated CSS-only attacks that steal webmail credentials and authentication tokens across major email providers.
- Spain arrests suspect accused of using AI face swaps to obtain digital certificates — Spanish police arrested a suspect who allegedly used AI face swaps to fraudulently obtain digital certificates for 30 people.
Active Exploits & Incidents
Jewelbug breached government webmail while running crypto fraud
Read digest- Jewelbug breached government webmail while running crypto fraud — Jewelbug ran government espionage and cryptocurrency-fraud operations from shared infrastructure.
- Beacon CRM Confirms UK Charity Database Was Copied and Likely Downloaded — Beacon CRM confirmed attackers copied and likely downloaded its entire customer database, affecting more than 1,500 UK charities and nonprofits.
- Docker Sandboxes read-only mounts could be bypassed via a writable VirtioFS path — Docker Sandboxes running coding agents had a read-only mount bypass via the writable /mnt/host VirtioFS export; fixed in version 0.38.0.
- Cheaper AI models are becoming much better at hacking — XBOW found cheaper open-weight and proprietary AI models have become effective at complex hacking and exploitation tasks.
Threat Research & Deep Dives
Underground sellers resell discounted access to Claude and ChatGPT
Read digest- Underground sellers resell discounted access to Claude and ChatGPT — Criminals are reselling discounted access to Claude, ChatGPT and other frontier models via API gateways.
- AmnesiaStealer hijacks Chromium sessions for live macOS browser control — The Rust-based AmnesiaStealer infostealer targets macOS users, stealing keychain data and browser credentials and conducting live Chromium control via CDP.
- Unauthenticated Hybrid-Inverter API Could Create Grid Safety Risks — An unauthenticated API exposes hybrid inverter control functions, letting attackers disable protections or damage connected grid equipment.
- Chrome adds device-bound credentials to thwart session-cookie account takeovers — Chrome is rolling out device-bound session credentials so stolen session cookies fail validation on other devices.
Threat Research & Deep Dives
Jewelbug APT Runs Browser Espionage and Cryptocurrency Fraud Campaigns
Read digest- Jewelbug APT Runs Browser Espionage and Cryptocurrency Fraud Campaigns — APT group conducted large-scale espionage and cryptocurrency fraud targeting government and military organizations across Asia and the Middle East.
- ShipMonk breach exposes data of 13,689 Trezor customers — ShipMonk breach exposed personal data of 13,689 Trezor customers across seven countries, creating targeted phishing risk.
- Microsoft Releases August 2026 Security Updates for Exchange Server — August 2026 Exchange Server updates address denial-of-service, privilege escalation, RCE, spoofing, and security feature bypass flaws.
- Industrial ransomware incidents rose 12% to 1,140 in Q2 2026 — Dragos identified 1,140 ransomware incidents affecting industrial organizations in Q2 2026, a 12% increase.
Active Exploits & Incidents
Poland's MyDr breach exposes medical data of nearly 19 million people
Read digest- Poland's MyDr breach exposes medical data of nearly 19 million people — A breach of Poland's MyDr system exposed medical data linked to nearly 19 million people across 12,000 facilities.
- Internet-Exposed BMCs Expose Data Centers to Hardware-Level Takeover — Researchers found 36,872 internet-exposed BMC interfaces with 24,650 leaking authentication material before login.
- Fortinet Patches FortiWeb and FortiManager Authentication Flaws — Fortinet patched authentication flaws allowing unauthenticated GUI access and device impersonation in FortiWeb and FortiManager.
- Attackers exploit critical Microsoft SharePoint authentication bypass after PoC release — A critical Microsoft SharePoint authentication bypass is being exploited after proof-of-concept code was released.
Active Exploits & Incidents
Akira affiliate rebooted Windows host into Safe Mode to evade EDR
Read digest- Akira affiliate rebooted Windows host into Safe Mode to evade EDR — An Akira affiliate used Windows Safe Mode to disable EDR agents before deploying ransomware on organizations with exposed SonicWall SSL VPNs.
- Phantom Stealer Hides Encrypted Payloads in PNGs to Steal Windows Data — A .NET-based stealer targets Windows users across multiple countries, hiding decrypted payloads in PNG resources to exfiltrate credentials and sensitive data.
- White House Authorizes Vetted Firms to Conduct Cyber Operations Against Foreign Gangs — The White House authorized vetted U.S. cybersecurity companies to conduct government-supervised cyber operations against foreign cyber-enabled criminal organizations.
- CVE-2026-18391 — WooCommerce Subscriptions Unauthenticated RCE — A CVSS 9.8 unauthenticated remote code execution flaw via PHP object injection affects WooCommerce Subscriptions before 9.1.0.
Vulnerabilities & CVEs
UpSnap Unauthenticated Superuser Takeover Chains to Root RCE
Read digest- UpSnap Unauthenticated Superuser Takeover Chains to Root RCE — CVE-2026-49819 (CVSS 9.8) allows unauthenticated initial-superuser takeover chaining to root RCE in UpSnap.
- UpSnap Remote Code Execution via IP Field Template Injection — CVE-2026-49481 (CVSS 9.6) enables remote code execution in UpSnap through IP field template injection.
- Troy Hunt Weekly Update 516 Covers ShinyHunters and New Breaches — ShinyHunters is ramping up activity with breaches at Inter-Con Security, Exact Sciences, and Brinks Home.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check