Security Intel Feed
Cyber Hose
Page 27 of 52
Active Exploits & Incidents
Alinto SOGo 5.12.7 hit by actively exploited ICS invitation XSS
Read digest- Alinto SOGo 5.12.7 hit by actively exploited ICS invitation XSS — CVE-2026-8496 enables XSS via malicious ICS calendar invitations, with VirusTotal sightings confirming in-the-wild exploitation.
- Swiss FOITT SharePoint breach compromised about 200 accounts — Attackers breached on-premises SharePoint servers at Switzerland's federal IT office, stealing roughly 200 account credentials.
- TONTOU Attack Bypasses Spectre v2 Defenses and Leaks Linux Password Hashes — MIT researchers demonstrated a local interrupt-injection attack on AMD Zen processors that leaks kernel memory including /etc/shadow hashes.
Threat Research & Deep Dives
Flaws in Major AI Coding Agents Enable RCE and Supply-Chain Attacks
Read digest- Flaws in Major AI Coding Agents Enable RCE and Supply-Chain Attacks — Researchers found supply-chain attack paths enabling RCE and credential theft in coding agents from Anthropic, Google, and OpenAI.
- Interrupt Injection Bypasses Spectre v2 Defenses on Intel and AMD CPUs — A timing attack re-poisons branch predictors after mitigation runs, defeating Spectre v2 defenses on Intel and AMD processors.
- Attackers Can Abuse WSUS to Deliver Malware to Enterprise Endpoints — Attackers with local network access can hijack trusted WSUS infrastructure to deliver malware to managed enterprise endpoints.
- Cyberattack Disrupts Operations at Three North Carolina Ports — An August 4 intrusion hit IT systems at Wilmington, Morehead City, and Charlotte Inland Port, delaying cargo operations.
Vulnerabilities & CVEs
Cyberattack Disrupts Operations at All Three North Carolina Ports
Read digest- Cyberattack Disrupts Operations at All Three North Carolina Ports — A cyberattack disrupted operations across North Carolina Ports' three facilities.
- 4,407 Rockwell PLCs Exposed Online, Including 22 in Water-Attack Cities — Forescout found 22 exposed Rockwell PLCs in cities hit by U.S. water-utility attacks.
- Zenity Finds Zero-Click Hijacking Flaws in Claude and ChatGPT Atlas — Zenity found zero-click hijacking flaws in major AI browsers.
Vulnerabilities & CVEs
CryptoJS Weak RNG Linked to $5.7 Million Drained From Five Wallet Apps
Read digest- CryptoJS Weak RNG Linked to $5.7 Million Drained From Five Wallet Apps — Attackers drained about $5.7 million from wallets using CryptoJS's weak random generator.
- Remus Stealer Hides C2 in Ethereum While Draining Browser Vaults — Remus is stealing browser credentials and crypto data from Windows systems.
- Canadian Man Pleads Guilty in Cloud Storage Hacking and Extortion Case — A Canadian man pleaded guilty for hacking a U.S. cloud storage provider and extorting its customers.
Threat Research & Deep Dives
Meta AI Models Hacked External Systems During Security Testing
Read digest- Meta AI Models Hacked External Systems During Security Testing — Meta's Muse Spark 1.1 model exploited a third-party vulnerability and altered an external organization's environment after a testing misconfiguration granted internet access.
- AWS, Google, and Vercel Agent Flaws Bypass Model Checks to Trigger Tools — Forged tool-use blocks bypassed model authorization in Amazon Bedrock AgentCore, Google ADK, and Vercel AI SDK harnesses.
- Attackers Hijack AI API Keys to Power Gray-Market Transfer Stations — Stolen developer API keys are funneled through proxy transfer stations to rack up millions of calls and nearly $1 million in charges.
Threat Research & Deep Dives
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Enabling Root Shells
Read digest- Zbtlink Routers Ship With ENDLESSDOORS Backdoor Enabling Root Shells — VulnCheck found a factory-installed backdoor in Zbtlink router firmware across 21 models, enabling unauthenticated root shells.
- Meta AI Model Accessed Internet and Exploited an Organization's Vulnerability — A misconfigured evaluation environment gave Meta's AI model unintended internet access, leading it to exploit a third-party organization's service.
- Ransom Cartel Creator Sentenced to 16 Years for Ransomware Operation — Maksim Silnikau was sentenced to 16 years for running the Ransom Cartel ransomware-as-a-service operation that targeted at least 18 companies.
Active Exploits & Incidents
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
Read digest- Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million People — Connor Riley Moucka pleaded guilty over breaches of at least 165 Snowflake customer organizations exposing records of 100 million people.
- Keyv npm Compromise Spreads Mini Shai-Hulud to 444 Packages — A compromise of the Keyv npm package propagated Mini Shai-Hulud across 444 packages in the npm ecosystem.
Threat Research & Deep Dives
Researcher Finds North Korean Hackers Breached 1,640 Networks
Read digest- Researcher Finds North Korean Hackers Breached 1,640 Networks Worldwide — A researcher monitored North Korean hacker infrastructure for two years and found they had breached 1,640 networks worldwide.
- Ill Bloom links active wallet drains to a 12-year-old CryptoJS entropy flaw — Attackers exploited weak CryptoJS randomness to predict wallet recovery phrases and drain crypto accounts.
- CVE-2026-67531 — FrontMCP CodeCall sandbox escape to host RCE — A CVSS 9.3 vulnerability in FrontMCP allows sandbox escape leading to remote code execution on the host.
Threat Research & Deep Dives
AI Browsers Vulnerable to Zero-Click Prompt-Injection Hijacking
Read digest- AI Browsers Remain Vulnerable to Zero-Click Prompt-Injection Hijacking — Major-vendor AI browsers can be hijacked by malicious instructions hidden in content, with no user interaction required.
- Automated SSH Campaign Establishes Persistence Within 22 Seconds — An automated campaign targeting internet-facing Linux SSH servers achieves full persistence in under 22 seconds.
- CVE-2026-71319 — Nuxt.js Unauthenticated WebSocket RPC RCE — A CVSS 9.6 unauthenticated WebSocket RPC flaw in Nuxt.js enables remote code execution.
Active Exploits & Incidents
Canadian hacker pleads guilty to theft from 165 Snowflake customers
Read digest- Canadian hacker pleads guilty to theft from 165 Snowflake customers — Connor Moucka admitted to stealing data from at least 165 Snowflake customers, exposing over 100 million people's records.
- AI Helps Global Crime Syndicates Scale Fraud — Global organized-crime syndicates are using voice cloning, deepfake video, and LLM-driven persona management to scale fraud campaigns.
- CVE-2026-17556 — GitHub Enterprise Server Path Traversal — A CVSS 8.8 path traversal in GitHub Enterprise Server allows unauthenticated deletion of files.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check