Security Intel Feed
Cyber Hose
Page 26 of 52
Threat Research & Deep Dives
Atlassian Rovo Can Exfiltrate Jira/Confluence via Prompt Injection
Read digest- Atlassian Rovo Can Exfiltrate Jira and Confluence Data via Prompt Injection — PromptArmor found that Atlassian Rovo can exfiltrate accessible enterprise data through indirect prompt injection.
- DEF CON Talk Shows How Arbitrary File Writes Can Become RCE — Researchers presented techniques for turning arbitrary file writes into remote code execution in web apps and distroless containers.
- CSS Attacks Break Webmail Boundaries to Steal Passwords and Tokens — PortSwigger details how CSS-based attacks can break webmail boundaries to steal passwords and tokens.
- CVE-2026-16258 — Ajax Search Lite Unauthenticated PHP Object Injection — A CVSS 9.8 unauthenticated PHP object injection flaw affects Ajax Search Lite before version 4.14.5.
Active Exploits & Incidents
Metabase SQL Injection Zero-Day Exploited to Breach Customer Instances
Read digest- Metabase SQL Injection Zero-Day Exploited to Breach Customer Instances — A critical unauthenticated SQL injection flaw with CVSS 10.0 affects Metabase Cloud and self-hosted deployments, enabling admin access and data theft.
- CISA Adds Progress Kemp LoadMaster Flaw to KEV After 792 Exploit Attempts — A CVSS 9.6 command injection flaw in Progress Kemp LoadMaster is actively exploited and added to CISA's KEV catalog.
- Attackers Exploit N-able N-central Authentication Bypass to Reach Managed Systems — Attackers bypassed an N-central auth fix to gain administrative access and reached managed endpoints via the Take Control feature.
Vulnerabilities & CVEs
CVE-2026-8798: Unbounded CPU entropy instruction retry flaw
Read digest- CVE-2026-8798: Unbounded CPU entropy instruction retry flaw — A CVSS 8.7 flaw where a native entropy source retries CPU entropy instructions without limit.
- CVE-2026-48026: lakeFS stored XSS in markdown previews — lakeFS is vulnerable to stored XSS in rendered markdown previews via raw HTML.
- CVE-2026-48120: Kakoune RCE via autorestore backup filename injection — Kakoune has a critical RCE via autorestore backup filename injection.
Vulnerabilities & CVEs
OpenYak unauthenticated CSRF chain enables remote code execution
Read digest- CVE-2026-46409 — OpenYak local API: unauthenticated CSRF chain leads to Remote Code Execution — A CVSS 9.6 unauthenticated CSRF chain in the OpenYak local API enables remote code execution.
- CVE-2026-47243 — Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs — A CVSS 9.2 guest-to-host escape in Kata Containers runtime-rs via virtiofs could allow container breakout.
- CVE-2026-50540 — Kata Containers: Config Path Annotation Arbitrary File Loading — A CVSS 9.6 arbitrary file loading flaw in Kata Containers via config path annotation could lead to code execution.
Active Exploits & Incidents
Flooding Dropper campaign spreads 846 malicious npm packages
Read digest- Flooding Dropper campaign spreads 846 malicious npm packages — A campaign distributed 846 malicious npm packages delivering cross-platform malware targeting developers and CI/CD environments.
- Unlimited Technology Systems breach affects 3.8 million people — A healthcare software provider disclosed a breach exposing SSNs, diagnoses, and identity documents for 3,803,750 individuals.
- tl;dv Firebase flaw exposed 181,874 meeting records and live call IDs — A Firebase misconfiguration exposed meeting metadata across 35,003 email domains including government agencies and universities.
- ClickFix Attacks Deliver macOS Stealer Capable of Draining Crypto Wallets — ClickFix attacks deliver a Go-based macOS stealer that harvests browser credentials, iCloud Keychain data, and cryptocurrency wallets.
Active Exploits & Incidents
Levi Strauss says social engineering attack stole corporate data
Read digest- Levi Strauss says social engineering attack stole corporate data — Hackers stole corporate information after compromising three employee computers via social engineering.
- Cyberattack disrupts gate operations at North Carolina's three ports — A cyberattack disrupted IT systems and gate operations at all three North Carolina port facilities.
- Attackers Abuse Commercial EDR Tools as Ransomware Trojan Horses — Ransomware groups are increasingly disabling commercial EDR tools before encrypting victim systems.
- stb TrueType library heap overflow affects versions through 1.26 — A heap buffer overflow in the stb TrueType font parser can be triggered by malformed font files.
Active Exploits & Incidents
ChainDrop worm poisoned 444 npm packages to steal developer
Read digest- ChainDrop worm poisoned 444 npm packages to steal developer credentials — ChainDrop compromised hundreds of npm packages with a self-propagating credential stealer targeting developers and CI/CD environments.
- HTTP Terminator Finds New Desync Techniques and Apache Traffic Server Zero-Day — PortSwigger reported new HTTP desync techniques and an Apache Traffic Server zero-day affecting banks, governments, and airports.
- AI Coding-Agent Workflows Exposed CI Secrets to Zero-Privilege GitHub Issues — Zero-privilege GitHub issues could compromise Claude Code, Gemini CLI, and Codex workflows to steal CI credentials.
- Greatness AiTM Campaign Hijacks Microsoft 365 Accounts for Payroll Intelligence — Greatness phishing campaigns hijack Microsoft 365 accounts across multiple countries to target payroll and finance data.
Vendor Bulletins & Advisories
Microsoft and Apple Patch Critical and High-Severity Security Flaws
Read digest- Microsoft and Apple Patch Critical and High-Severity Security Flaws — Microsoft patched multiple CVSS 10.0 vulnerabilities across Active Directory, Azure, Entra, SharePoint and Teams, while Apple fixed a Screen Sharing auth bypass.
- Enterprise Java flaws enable pre-auth RCE in Bonita BPM and Apache OFBiz — Researchers disclosed 12 flaws across four enterprise Java platforms including pre-authentication RCE chains in Bonita BPM and Apache OFBiz.
- UNC6671 Hijacks Microsoft 365 Sessions for Automated Data Theft — UNC6671 targets financial services and enterprise organizations by posing as IT helpdesks to steal M365 and Okta session tokens.
- TeamPCP Linked to Redis Attacks Since 2020 and Supply-Chain Campaigns — New analysis connects TeamPCP's Redis infrastructure attacks to later software supply-chain compromises dating back to 2020.
Active Exploits & Incidents
N-central Zero-Day Let Attackers Control Servers and Managed Devices
Read digest- N-central Zero-Day Let Attackers Control Servers and Managed Devices — Attackers exploited a zero-day in N-able N-central to gain unauthenticated administrative access and pivot to domain controllers and backup servers.
- SMOKE#SCREEN campaign uses fake updates to deploy ScreenConnect RMM — Threat actors use fake Zoom and Adobe updates to silently install legitimate ScreenConnect agents for persistent remote access on Windows and macOS.
- CVE-2026-56162 — Azure SQL Database Elevation of Privilege — A CVSS 10.0 elevation-of-privilege vulnerability in Azure SQL Database stems from improper authentication.
Threat Research & Deep Dives
More Than 4,400 Rockwell PLCs Exposed Online, 22 in Attack-Hit Cities
Read digest- More Than 4,400 Rockwell PLCs Exposed Online, Including 22 in Attack-Hit Cities — Forescout identified 4,407 exposed Rockwell controllers worldwide, including 22 in cities hit by recent water-system attacks.
- UNC6671 vishing attacks target hedge funds and private-equity firms — UNC6671 spoofed corporate help desks to steal credentials and session cookies from major financial firms via adversary-in-the-middle phishing.
- Zbtlink routers ship with an embedded backdoor enabling remote root shells — VulnCheck found the Endlessdoors implant in over 20 Zbtlink router models with an estimated 100,000-plus deployed units worldwide.
- Researcher Claims Proof-of-Concept Control of ChatGPT Secure Sandbox — A researcher demonstrated C2-style influence over ChatGPT's isolated sandbox using an attack chain shown at Black Hat USA 2026.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check