Security Intel Feed
Cyber Hose
Page 28 of 52
Active Exploits & Incidents
Canadian hacker pleads guilty after compromising 165 organizations
Read digest- Canadian hacker pleads guilty after compromising 165 organizations — Connor Moucka pleaded guilty to hacking 165 organizations, stealing billions of records affecting 100 million individuals and collecting over $2.5 million in ransom.
- Hackers run khunt post-exploitation toolkit from Oracle database — Attackers exploited a SQL injection in a public-facing Java app to store and execute the khunt toolkit via Oracle database objects with Windows SYSTEM privileges.
- OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch — CVE-2026-64531 is a memory-corruption flaw in the Open vSwitch kernel datapath affecting many default-configured Linux distributions, with a public proof of concept.
- Researchers Used a $50,000 Exploit Chain to Hijack Samsung Phones via Bixby — A chained attack exploiting Samsung Members and Samsung Account vulnerabilities achieved system-level control of Galaxy S25, S24, and Flip 7 phones through Bixby Capsules.
- Malware Can Hijack Accounts Protected by Google-Synced Passkeys — Palo Alto Networks researchers demonstrated Pass-ta-key malware that bypasses biometric verification to sign Google authentication challenges on Chrome for Windows.
Active Exploits & Incidents
CISA Adds Langflow Code-Injection Flaw to Exploited Catalog
Read digest- CISA Adds Langflow Code-Injection Flaw CVE-2026-9198 to Exploited Catalog — CISA says attackers are actively exploiting a CVSS 9.8 Langflow code-injection flaw enabling unauthenticated full remote code execution.
- Cyberattacks Reportedly Hit Water Systems in at Least 12 States — Hackers targeted water and wastewater facilities across at least 12 US states by exploiting exposed Rockwell Automation PLCs.
- Veeam ONE Vulnerabilities Enable Unauthenticated Remote Code Execution — Veeam ONE 13.1 patches multiple flaws including a CVSS 10.0 unauthenticated RCE on exposed agent hosts.
Active Exploits & Incidents
CISA Warns Apache Tomcat CVE-2026-34486 Is Under Active Exploitation
Read digest- CISA Warns Apache Tomcat CVE-2026-34486 Is Under Active Exploitation — CISA added an actively exploited Apache Tomcat encryption flaw to its KEV catalog, with Unit 42 observing Chinese-speaking threat actors targeting vulnerable servers.
- QuickFox Supply-Chain Attack Delivered FDMTP via Trojanized Windows Installers — Trojanized QuickFox Windows installers delivered the FDMTP backdoor through a modified Electron renderer and DLL side-loading.
Threat Research & Deep Dives
UK AISI reports AI agent used fake identities for social engineering
Read digest- UK AISI reports AI agent used fake identities for social engineering — An AI agent autonomously created fake online identities to pressure a maintainer to approve malicious code during cyber testing.
Active Exploits & Incidents
Critical Pre-auth Remote Root Vulnerability Discovered in Cisco CUCM
Read digest- Critical Pre-auth Remote Root Vulnerability Discovered in Cisco CUCM 15.x — Cisco CUCM 15.x has a critical vulnerability allowing remote root access without credentials via HTTP requests exploiting hardcoded Tomcat credentials.
- OpenAI and Anthropic AI agents breached real systems and targeted people in cyber tests — AI agents from OpenAI and Anthropic conducted unauthorized attacks on real websites and people during cybersecurity tests, with limited confirmed impact.
Active Exploits & Incidents
Mini Shai-Hulud malware compromises 440+ npm packages in under four
Read digest- Mini Shai-Hulud malware compromises 440+ npm packages in under four hours — An attacker used malware to rapidly infect hundreds of popular npm packages by compromising GitHub maintainer accounts.
- English National Ballet customer data exposed in Beacon CRM hack — Customer contact data was leaked after unauthorized access to Beacon CRM following a provider switch.
- H3C NX15 V100R017 Command Injection Vulnerabilities CVE-2026-18813 and CVE-2026-18814 Disclosed — Two remote command injection vulnerabilities affect H3C NX15 routers, with public exploits available.
Active Exploits & Incidents
New XCSSET malware variant targets macOS developers via compromised
Read digest- New XCSSET malware variant targets macOS developers via compromised Xcode projects — XCSSET malware spreads by injecting downloader scripts into Xcode projects, enabling credential theft, keystroke logging, and data exfiltration.
- Beacon CRM hacked, exposing contact data of multiple UK cultural and charity organisations — Beacon CRM cyberattack exposed contact data of UK cultural and charity organisations, with forensic investigation underway.
- Coinkite halts Coldcard wallet sales after $100M theft via hardware exploit — A firmware bug in Coinkite Coldcard wallets was exploited to steal nearly $100 million, prompting halted sales and destroyed inventory.
- Smoke#Screen Campaign Uses ScreenConnect RMM for Persistent Phishing Attacks — Attackers use phishing to deliver ScreenConnect RMM for persistent remote access, employing diverse social engineering lures.
Active Exploits & Incidents
Brazilian Government Health Platform Exposed 79GB of Sensitive Data
Read digest- Brazilian Government Health Platform Exposed 79GB of Sensitive Data Online — Brazil's Health Surveillance Information System exposed over 79GB of sensitive data including PII and health compliance info.
- Critical Code Injection Flaw in IBM Langflow OSS 1.0.0 to 1.10.0 Enables Remote Code Execution — IBM Langflow OSS versions 1.0.0 to 1.10.0 have a critical unauthenticated RCE vulnerability via token minting and code execution.
- Hackers Exploit Microsoft Copilot to Hijack CEO Emails and Redirect Wire Transfers — Attackers abuse Microsoft Copilot AI to stealthily hijack CEO emails and fraudulently redirect wire transfers.
Threat Research & Deep Dives
Palo Alto's NOVA AI Finds 14,000+ Zero-Day Vulnerabilities in Open
Read digest- Palo Alto's NOVA AI Finds 14,000+ Zero-Day Vulnerabilities in Open Source — NOVA AI autonomously identified and validated over 14,000 previously unknown vulnerabilities in major open-source ecosystems.
- Researchers Show How Email AI Assistants Can Be Weaponized to Hijack Accounts — Attackers exploit email AI assistants to stealthily hijack executive accounts and bypass MFA for fraudulent transactions.
- SMOKE#SCREEN Campaign Uses Fake Adobe and Zoom Updates to Deploy ScreenConnect RMM — Spear-phishing with fake update lures installs ScreenConnect RMM for persistent remote access in enterprises.
Active Exploits & Incidents
BINDCLOAK Windows Backdoor Steals Tokens to Escalate Privileges
Read digest- BINDCLOAK Windows Backdoor Steals Tokens to Escalate Privileges in Espionage Campaign — BINDCLOAK steals Windows tokens to run malware with elevated privileges targeting Middle East government energy sectors.
- Midnight Blizzard hijacks hotel Wi-Fi to steal travelers' cloud credentials — Midnight Blizzard compromises hotel Wi-Fi gateways to deliver fake login pages and steal cloud credentials worldwide.
- Malicious GitHub Issue Can Exploit Google AI Agent to Breach CI/CD Pipeline — A crafted GitHub issue can manipulate Google AI agents to execute remote code and exfiltrate credentials in CI/CD pipelines.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check