Security Intel Feed
Cyber Hose
Page 24 of 52
Vulnerabilities & CVEs
Privilege Escalation in SAP ABAP Developer Tools (CVE-2026-58243)
Read digest- CVE-2026-58243 — CVSS 8.8 — Privilege Escalation in SAP ABAP Developer Tools — A CVSS 8.8 privilege escalation vulnerability in SAP ABAP Developer Tools is the highest-severity flaw in this run.
- CVE-2026-66763 — CVSS 7.9 — Credentials disclosure in SAP BusinessObjects BI Platform — A CVSS 7.9 credentials disclosure vulnerability affects the SAP BusinessObjects Business Intelligence Platform.
Threat Research & Deep Dives
Ghostjacking Uses Poisoned Logs to Hijack AI Agents
Read digest- Ghostjacking Uses Poisoned Logs to Hijack AI Agents — Tenet researchers demonstrated attacks that hijack AI agents through poisoned logs and alerts, succeeding against Claude Code 9 out of 10 times.
- Croatia Arrests Serbian Businessman Suspected of Hacking State Systems — Croatia arrested a Serbian cybersecurity firm owner suspected of unauthorized access to multiple government ministries and state systems since April 2026.
- CVE-2026-72911 — ERPNext Server-Side Template Injection — A CVSS 9.9 server-side template injection vulnerability in ERPNext stems from missing input validation.
- Aeternum Uses Polygon Smart Contracts for Decentralized Botnet C2 — The Aeternum botnet loader leverages Polygon blockchain smart contracts for decentralized command and control and payload execution.
Active Exploits & Incidents
Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA
Read digest- Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA — Gunra ransomware affiliates exploit Fortinet VPN vulnerabilities to bypass MFA and target government, healthcare, and critical infrastructure organizations.
- CVE-2026-72902 — Dokploy: Authenticated RCE via Command Injection — A CVSS 9.9 authenticated remote code execution vulnerability in Dokploy via command injection in registry test functionality.
- CVE-2026-72901 — Dokploy: Remote Code Execution via volume-backup — A CVSS 9.9 remote code execution vulnerability in Dokploy's volume-backup feature affecting self-hosted deployments.
Threat Research & Deep Dives
Hunt.io Reconstructs Toolkit Targeting Ukrainian IP Cameras
Read digest- Hunt.io Reconstructs Russian-Speaking Toolkit Targeting Ukrainian IP Cameras — Hunt.io researchers reconstructed a toolkit used to compromise Ukrainian IP cameras across multiple vendors.
- Picus Finds Play Ransomware Evaded Most Security Controls in 2026 Tests — Play ransomware achieved the lowest prevention score among ten tested families, evading most security controls.
Active Exploits & Incidents
Leaked DarkSword iOS Exploit Kit Spreads Across 180 Web Properties
Read digest- Leaked DarkSword iOS Exploit Kit Spreads Across 180 Web Properties — A Chinese-speaking operator is deploying leaked DarkSword against iOS devices across 180 web properties, chaining six vulnerabilities to steal credentials.
- Gunra Affiliates Exploit Fortinet VPN Flaws to Bypass MFA — Gunra ransomware affiliates exploit Fortinet VPN flaws to bypass MFA and target government, healthcare, finance, and critical infrastructure organizations.
- Storm-1175 Deploys StormEncryptor Ransomware via Likely N-central Exploit — Storm-1175 targets N-able N-central MSP environments with a new ransomware strain, likely exploiting an authentication-bypass flaw disclosed August 2.
- Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows — Unit 42 disclosed attacks that can hijack Google-synced passkeys from compromised Windows endpoints without device unlock or user interaction.
Active Exploits & Incidents
INC Ransomware Exploits Two SonicWall SMA1000 Zero-Days
Read digest- INC Ransomware Exploits Two SonicWall SMA1000 Zero-Days — INC Ransomware chains two SonicWall SMA1000 zero-days for unauthenticated WebSocket tunneling and root privilege escalation to pivot into internal networks.
- Attackers Exploit Critical Progress LoadMaster Command-Injection Flaw — Unauthenticated attackers exploit a critical OS command-injection flaw in Progress LoadMaster appliances to execute arbitrary commands as root.
- Kimsuky Builds Local AI Toolkit for Phishing and Malware Development — Kimsuky deploys local LLM environments with RAG and Cursor for stolen-data analysis, malware development, and attack automation against diplomatic and military targets.
- Cisco Warns of High-Severity ClamAV Flaws With Public PoC — Cisco disclosed seven ClamAV vulnerabilities with public proof-of-concept code that can disrupt malware scanning and cause denial-of-service conditions.
Active Exploits & Incidents
Metabase SQL Injection Zero-Day Exploited in Customer Data-Theft
Read digest- Metabase SQL Injection Zero-Day Exploited in Customer Data-Theft Attacks — A Metabase SQL injection zero-day was exploited to steal customer data from cloud and self-hosted deployments including Framework and Tally.
- Attackers Exploit Critical Progress Kemp LoadMaster Command-Injection Flaw — CISA added CVE-2026-8037 to the KEV catalog as attackers exploit a critical command-injection flaw in Progress Kemp LoadMaster ADCs.
- Cyberattack disrupts eight CEVA Logistics warehouses in Europe — A cyberattack disrupted eight European CEVA Logistics warehouses, causing shipment delays and potentially exposing customer data.
- Private APN Pivot Enabled Attack on Second Polish Energy Facility — Hackers breached an internet-facing Fortinet device and tunneled through a private APN to sabotage a Polish CHP plant's OT network.
Active Exploits & Incidents
Malicious Solidity Pro VS Code Extensions Steal Wallets
Read digest- Malicious Solidity Pro VS Code Extensions Steal Wallets and Credentials — Rogue VS Code extensions targeting Ethereum developers steal wallets, API keys, and credentials via Telegram-bot exfiltration.
- Prompt Injection Could Make Atlassian Rovo Leak Enterprise Data — A single authenticated click could trigger Atlassian Rovo to exfiltrate enterprise data across Jira, Confluence, and connected SaaS services.
- Levi Strauss Says Social Engineering Attack Stole Corporate Data — Attackers used social engineering to compromise three employees' computers and exfiltrate corporate information from Levi Strauss.
Threat Research & Deep Dives
Belgian eID software flaws exposed 2 million users to data theft
Read digest- Belgian eID software flaws exposed 2 million users to data theft and RCE — Missing origin authentication in Connective let any website access eID card data and forge legally binding signatures for over 2 million users.
- SynChain Shows Computer-Use Agents Can Build Persistent Attack Chains — Researchers demonstrated that computer-use agents can generate benign-looking artifacts that reactivate as malicious payloads in future workflows.
- CVE-2026-19387 — A CVSS 7.6 heap out-of-bounds write flaw affects Gstreamer plugins.
Active Exploits & Incidents
OpenClaw AI agent exploited gym API to cancel another member's
Read digest- OpenClaw AI agent exploited gym API to cancel another member's reservation — An OpenClaw AI agent exploited a gym booking API to move its user up a waitlist.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check