Security Intel Feed
Cyber Hose
Page 3 of 51
Threat Research & Deep Dives
Microsoft Entra ID Elevation of Privilege Vulnerability
Read digest- Microsoft Entra ID Elevation of Privilege Vulnerability — An authentication bypass in Microsoft Entra ID could allow elevation of privilege across widely deployed identity infrastructure.
- Path traversal in Plesk 18.0.79.9 and earlier — A path traversal vulnerability affects Plesk hosting control panel versions 18.0.79.9 and earlier and certain 18.0.80 builds.
- Azure Cosmos DB Spoofing Vulnerability — An authorization bypass through user-controlled key in Azure Cosmos DB could enable spoofing attacks.
- MOOS-IvP Critical RCE via Buffer Overflows (CVE-2026-85437) — Critical remote code execution flaws via buffer overflows were disclosed in the MOOS-IvP autonomy project.
Threat Research & Deep Dives
Attackers exploit zero-days in consistently besieged SonicWall product
Read digest- Attackers exploit zero-days in consistently besieged SonicWall product — Active exploitation of zero-day vulnerabilities in SonicWall's SMA1000 product poses an immediate threat to organizations using the widely deployed appliance.
- French hospital fined €500,000 after breach exposes data of 727,000 — A French hospital was fined half a million euros after a breach compromised the personal data of over 727,000 patients.
- Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help — A newly disclosed Microsoft Exchange vulnerability prompts urgent guidance for administrators on mitigation and protection strategies.
Vendor Bulletins & Advisories
Chrome DevTools use-after-free enables sandbox escape
Read digest- Chrome DevTools use-after-free (CVE-2026-85042) allows sandbox-escape code execution, fixed in 152.0.7977.82 — A use-after-free in Chrome DevTools permits sandbox-escape code execution and is patched in Chrome 152.0.7977.82.
- Coder's registry infrastructure compromised to push malicious modules — Attackers compromised package registry infrastructure to distribute malicious modules to downstream consumers.
- python-jose HS256 Token Forgery (CVE-2026-85394) — A flaw in python-jose allows HS256 JWT token forgery, potentially enabling authentication bypass in affected applications.
- GeoNetwork Critical RCE via XSLT Processor Misconfiguration (CVE-2026-58400) — An XSLT processor misconfiguration in GeoNetwork enables remote code execution on vulnerable deployments.
Vulnerabilities & CVEs
WordPress WPKoi Templates for Elementor plugin vulnerable
Read digest- WordPress WPKoi Templates for Elementor plugin through 3.7.2 vulnerable to DOM-based XSS (CVE-2026-85302) — A DOM-based cross-site scripting vulnerability affects all versions through 3.7.2 of the WPKoi Templates for Elementor plugin, impacting WordPress sites using this popular addon.
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root — A critical remote code execution vulnerability in Cisco Nexus 9000 switches allows unauthenticated attackers to execute code as root.
- HPE patches critical ArubaOS-CX remote code execution flaw — HPE has released a patch for a critical remote code execution vulnerability in ArubaOS-CX network operating system.
- Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data — A breach in Thomson Reuters court software potentially exposed sensitive personal data including Social Security Numbers.
Threat Research & Deep Dives
Three High-Severity HP Easy Start Flaws Allow Privilege Escalation on
Read digest- Three High-Severity HP Easy Start Flaws Allow Privilege Escalation on macOS — Three vulnerabilities in HP Easy Start for macOS let attackers escalate privileges by interfering with printer software installation.
- Microsoft says KB5120998 Windows update resets desktop settings — Microsoft confirms that a recent Windows update resets user desktop settings unexpectedly.
- HiddenLayer Raises $100 Million for AI Runtime Security — HiddenLayer secures $100 million funding to advance AI runtime security technologies.
- 'Breeze Comet' Tears Into Brazilian & Global Financial Systems — The 'Breeze Comet' threat actor targets financial systems in Brazil and worldwide.
Vulnerabilities & CVEs
Over 3 Million WordPress Sites Affected by Migration Plugin
Read digest- Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability — CVE-2026-19949 in servmask All-in-One WP Migration plugin has a CVSS score of 8.8 and affects millions of WordPress sites.
- Plex Warns Users to Patch Security Vulnerabilities Immediately — Plex issued an advisory urging users to update due to multiple security vulnerabilities.
- Node.js Runtime Abused as Malware Launcher — Research reveals attackers abusing Node.js runtime environments to launch malware.
- AI Tool Use Targeting Latin American Organizations — Palo Alto Unit 42 reports on attackers leveraging AI tools against Latin American organizations.
Threat Research & Deep Dives
VPNs Called Biggest OT Backdoor as Experts Push VPN-less Access
Read digest- VPNs Called Biggest OT Backdoor as Experts Push VPN-less Brokered Remote Access for Plants — Industry experts argue VPNs are the primary breach path into OT plant networks and advocate replacing them with brokered, VPN-less remote access.
- Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code — A vulnerability in widely deployed Cisco Nexus 9000 switches could allow remote attackers to execute malicious code.
- The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours — A ransomware group is disabling EDR and backup tools before encrypting networks within a 24-hour window.
- Submariner Critical RCE via CRD Injection (CVE-2026-66786) — A critical remote code execution vulnerability in Submariner is exploitable via CRD injection.
- Malicious Apache Modules Turn Trusted Government Websites Into Stealth Phishing Proxies — Attackers are using malicious Apache modules to covertly turn trusted government websites into phishing proxies.
Threat Research & Deep Dives
CISA Adds Seven Actively Exploited Flaws to KEV Including SonicWall
Read digest- CISA Adds Seven Actively Exploited Flaws to KEV, Including SonicWall, Sangoma, JFrog, and LiteLLM Bugs — CISA added seven actively exploited vulnerabilities to its KEV catalog impacting widely used products with severe risks.
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon — A proof-of-concept for privilege escalation in CrowdStrike Falcon was released by a security researcher.
- CISA Warns of SonicWall SMA1000 Vulnerabilities Actively Exploited in Attacks — CISA issues warnings about SonicWall SMA1000 vulnerabilities currently exploited in the wild.
- Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability — A zero-day privilege escalation vulnerability in CrowdStrike Falcon was claimed by a security researcher.
Threat Research & Deep Dives
Claude AI Now Controls Your macOS and Windows Computer
Read digest- Claude AI Now Controls Your macOS and Windows Computer in the Background — Claude AI can now operate macOS and Windows systems in the background, raising significant security and privacy considerations for users.
- Srsly Risky Biz: China's botnets are worth disrupting — Risky Business News examines why disrupting China's botnet infrastructure is a worthwhile strategic effort for defenders.
- TOTOLINK CP450 cstecgi.cgi buffer overflow — A buffer overflow vulnerability in TOTOLINK CP450's cstecgi.cgi endpoint could allow remote attackers to execute arbitrary code.
- ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection — CVE-2026-85040 describes an OS command injection flaw in CRMEB's scheduled task feature via the save eval endpoint.
Vulnerabilities & CVEs
Critical CVE-2026-84325 in Google Chrome with CVSS 9.8
Read digest- Critical CVE-2026-84325 in Google Chrome with CVSS 9.8 — An improper input validation vulnerability in Google Chrome prior to 152.0.797 allows critical exploitation.
- Use after free in Dawn in Google Chrome on Android (CVE-2026-84333) — A high severity use after free flaw in Chrome's Dawn component on Android affects versions before 152.0.7977.75.
- Twitter password recovery attack reported — A new attack targeting Twitter's password recovery process has been observed and reported on Mastodon.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check