Security Intel Feed
Cyber Hose
Page 22 of 52
Threat Research & Deep Dives
Exposed Credentials at Major U.S. Tech Company Still Worked Months
Read digest- Exposed Credentials at Major U.S. Tech Company Still Worked Months Later — A researcher discovered that nearly all exposed credentials for a major U.S. tech company remained valid months after their claimed rotation.
Active Exploits & Incidents
Attackers exploit Adobe Commerce flaw to hijack customer accounts
Read digest- Attackers exploit Adobe Commerce flaw to hijack customer accounts — CVE-2026-71362 allows unauthenticated customer account takeover in Adobe Commerce and Magento Open Source stores and is being exploited in the wild.
- City-Forum Campaign Steals Exposed Salesforce and ServiceNow Data — A campaign dubbed City-Forum is exploiting exposed Salesforce and ServiceNow data.
Vendor Bulletins & Advisories
SonicWall Patches Critical RCE Flaws in Discontinued GMS Platform
Read digest- SonicWall Patches Critical RCE Flaws in Discontinued GMS Platform — SonicWall patched critical unauthenticated RCE and data disclosure flaws in its discontinued GMS platform with no known exploitation in the wild.
- CVE-2026-73300 — Budibase SQL Injection via multipleStatements — A CVSS 9.6 SQL injection vulnerability in Budibase via the multipleStatements setting leads this week's CVE roundup.
Threat Research & Deep Dives
Plug & Pwn chains Windows PnP installs into SYSTEM access
Read digest- Plug & Pwn chains Windows PnP installs into SYSTEM access — Researchers demonstrated chains that turn Windows PnP driver installation into SYSTEM execution on fully updated Windows 11, including over RDP.
- Palo Alto Networks patches 11 flaws in PAN-OS and security products — Palo Alto Networks patched 11 vulnerabilities across PAN-OS, GlobalProtect, Prisma Access Agent, and Prisma Browser.
- CVE-2026-73294 — Semaphore UI OS Command Injection — A CVSS 9.9 command injection flaw in Semaphore UI allows remote attackers to execute arbitrary OS commands.
Active Exploits & Incidents
Actively exploited Cisco ASA and FTD flaw can crash firewalls
Read digest- Actively exploited Cisco ASA and FTD flaw can crash firewalls — Attackers exploit a Cisco firewall flaw to remotely crash devices via crafted HTTP requests to SSL VPN; CISA added it to the KEV catalog.
- Attackers Weaponize Rapid7 SharePoint Authentication-Bypass PoC — Attackers are exploiting a Microsoft SharePoint JWT authentication-bypass vulnerability using Rapid7's public PoC.
- Nightmare Eclipse releases ShieldBreak Windows Defender zero-day PoC — A PoC for a Windows Defender zero-day allegedly grants SYSTEM privileges by bypassing Microsoft's fix for a prior privilege-escalation flaw.
- Colombia's Justice Ministry Hit by Ransomware Before Presidential Transition — Ransomware disrupted services at Colombia's Justice Ministry days before the presidential transition.
Active Exploits & Incidents
Suspected China-linked AI agents breach Taiwan government and energy
Read digest- Suspected China-linked AI agents breach Taiwan government and energy networks — China-linked actors used autonomous AI agents to compromise 85 government accounts and exfiltrate over 2,500 personnel files from Taiwanese infrastructure.
- City-Forum Campaign Targets Salesforce and ServiceNow Guest Access — Attackers exfiltrated exposed data through unauthenticated Salesforce and ServiceNow guest access across telecoms, banks, and public-sector portals.
- 737 Fake Chrome VPN Extensions Redirected Browser Traffic Through SOCKS5 Proxies — Hundreds of malicious Chrome VPN extensions amassed over 75,000 installs and routed browser traffic through attacker-controlled SOCKS5 proxies.
- 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Gets Pricier — DarkOwl reports 2.86 billion compromised credentials reached criminal markets in 2025, with initial-access-broker listings averaging over $113,000.
Active Exploits & Incidents
Attackers Exploit VMware vCenter CVE-2026-59310 for Persistent Access
Read digest- Attackers Exploit VMware vCenter CVE-2026-59310 for Persistent Access — A CVSS 9.8 directory-traversal flaw in vCenter Syslog Server enables arbitrary code execution and is being actively exploited across 47 countries.
- Intel and AMD Patch More Than 80 Vulnerabilities Combined — Intel and AMD released patches for over 80 vulnerabilities including high-severity flaws enabling privilege escalation or code execution.
- SP Page Builder 6.7.1 exposed Joomla sites to pre-auth RCE — A pre-authentication remote code execution in Joomla SP Page Builder allowed anonymous attackers to exploit PHP file-inclusion and arbitrary file-write flaws.
- KVM SEV-SNP Flaw Enables Guest-to-Host Heap Out-of-Bounds Access — Researchers disclosed a guest-to-host heap out-of-bounds access flaw in KVM hosts running AMD SEV-SNP virtual machines.
Active Exploits & Incidents
Lazarus Exploited Windows AFD.sys Zero-Day to Deploy ForestTiger
Read digest- Lazarus Exploited Windows AFD.sys Zero-Day to Deploy ForestTiger — Lazarus exploited CVE-2026-68820, a Windows AFD.sys use-after-free flaw, to escalate privileges and deploy ForestTiger against defense and aerospace targets.
- Malicious LiteLLM PyPI Releases Potentially Exposed 2,500 Organizations — Poisoned LiteLLM PyPI releases could steal cloud credentials and secrets from thousands of organizations and CI/CD pipelines.
- ShieldBreak PoC Claims to Bypass Microsoft Defender Fix for SYSTEM Access — A researcher released a PoC claiming to bypass Microsoft's fix for the RoguePlanet Defender privilege-escalation flaw CVE-2026-50656.
Vulnerabilities & CVEs
Microsoft SharePoint Server remote code execution vulnerability
Read digest- Microsoft SharePoint Server Vulnerability Allows Attackers to Inject and Execute Malicious Code Remotely — CVE-2026-63520 (CVSS 8.1) enables remote code execution on widely deployed SharePoint Server installations.
- Path Traversal and HTTP Parameter Pollution in Snowflake Python API — CVE-2026-19594 (CVSS 8.1) exposes Snowflake Python API users to path traversal and parameter pollution attacks.
- Velociraptor collect_client() Permissions Bypass — CVE-2026-64954 (CVSS 8.2) allows scheduling-based permissions bypass in Velociraptor's collect_client() function.
Vulnerabilities & CVEs
Microsoft Outlook RCE Vulnerability Allows Remote Code Execution
Read digest- Microsoft Outlook Vulnerability Allows Attackers to Execute Malicious Code Remotely — CVE-2026-70329 (CVSS 8.8) allows attackers to execute malicious code remotely via Microsoft Outlook.
- Critical RHACM flaw enables GitOpsCluster controller token redirection — A critical Red Hat Advanced Cluster Management flaw allows GitOpsCluster controller token redirection.
- Study Maps How LLM Prompt Injection Reaches Classic Web Vulnerabilities — Researchers identified LLM-mediated web attacks that carry attacker input into traditional application vulnerabilities.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check