Security Intel Feed
Cyber Hose
Page 30 of 52
Active Exploits & Incidents
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE
Read digest- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS — A Chinese threat actor uses a leaked exploit kit to deliver malware stealing credentials from Apple iOS devices.
- PNLD Breach Exposes UK Police and Government Contact Details on Dark Web — A breach of the Police National Legal Database exposed contact details of UK police and government personnel on the dark web.
- Hackers breach Liechtenstein beneficial owners register, data of 31,000 entities stolen — Hackers illegally accessed and copied data from Liechtenstein's beneficial owners register affecting 31,000 entities.
Active Exploits & Incidents
SonicWall SMA 1000 VPNs Face Zero-Click Root Compromise
Read digest- SonicWall SMA 1000 VPNs Face Zero-Click Root Compromise — Two vulnerabilities allow attackers to bypass restrictions and gain root access on SonicWall SMA 1000 series VPN appliances.
- Russian APT Midnight Blizzard hacks public Wi-Fi gateways to steal Microsoft credentials — Russian state-sponsored hackers target public Wi-Fi to steal Microsoft 365 credentials using adversary-in-the-middle attacks.
- Thermo Fisher Patches High-Severity Flaw Allowing Nearly Undetectable DNA File Tampering — A flaw in Applied Biosystems software allowed tampering with DNA data files before analysis, now patched with digital signatures.
Active Exploits & Incidents
Critical Auth Bypass in N-able N-central Enables Remote Admin Takeover
Read digest- Critical Auth Bypass in N-able N-central Enables Remote Admin Takeover, Patch Issued — Attackers exploited an authentication bypass in N-able N-central to gain full admin access, affecting both cloud and on-premises deployments.
- Three High-Severity Flaws in Hugging Face Diffusers Enable Arbitrary Code Execution — Multiple vulnerabilities in Hugging Face Diffusers allow arbitrary code execution via malicious model repositories.
- MacSync macOS Stealer Uses Fake Claude Guide to Harvest Passwords and Crypto Wallets — MacSync malware targets macOS users with a fake Claude AI guide to steal credentials, wallets, and install persistent access.
Threat Research & Deep Dives
Coldcard Bitcoin Wallet Hacked for $70M; Russia Behind Hotel WiFi
Read digest- Coldcard Bitcoin Wallet Hacked for $70M; Russia Behind Recent Hotel WiFi Attacks — Coldcard Bitcoin hardware wallets were compromised, causing a $70 million theft, with Russia identified as the attacker in recent hotel WiFi breaches.
Vulnerabilities & CVEs
No new critical vulnerabilities reported in this cycle
Read digest- No new critical vulnerabilities reported in this cycle — This digest covers 20 CVEs without scores and no new critical exploits or advisories this cycle.
Vulnerabilities & CVEs
Incomplete Patch Leads to Administrative Account Takeover
Read digest- Incomplete Patch Leads to Administrative Account Takeover — Two incomplete patches have resulted in administrative account takeover vulnerabilities that must be addressed immediately.
Active Exploits & Incidents
UK Government Investments agency suffers data breach exposing
Read digest- UK Government Investments agency suffers data breach exposing officials' details — Sensitive data and contact details of 51 officials were publicly accessible for about 40 hours due to policy failure.
- Family phones compromised to send abusive messages via WhatsApp and SMS — Multiple family members' phones on iOS and Android were compromised to impersonate and send abusive messages.
- Israel Thwarts Iranian Cyberattacks Targeting Water Infrastructure — Israel prevented cyberattacks on water infrastructure attributed to Iranian state-backed actors.
- Facebook Malvertising Campaign Uses C2 Infrastructure for Attacks — A malvertising campaign on Facebook uses command and control servers to deliver payloads to users.
Vulnerabilities & CVEs
Critical SQL Injection in PyAthena 3.35.4 with CVSS 9.8
Read digest- Critical SQL Injection in PyAthena 3.35.4 with CVSS 9.8 — CVE-2026-65321 allows SQL injection via DefaultParameterFormatter in PyAthena 3.35.4, affecting DELETE and CTAS queries.
- Path Traversal in huggingface/transformers with CVSS 7.1 — A path traversal vulnerability affects huggingface/transformers, potentially exposing sensitive files.
- Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser — Zephyr OCPP 1.6 suffers an out-of-bounds read in its RPC message parser, risking memory corruption.
Threat Research & Deep Dives
Google Chrome to block New Tab hijacker extensions on unmanaged
Read digest- Google Chrome to block New Tab hijacker extensions by default on unmanaged devices — Google Chrome plans to block policy-installed hijacker extensions on unmanaged consumer devices to prevent malware abuse and repeated installation attempts.
Threat Research & Deep Dives
Claude AI Breach, Cisco Firewall 0-Day, VMware Auth Bypass, and AI
Read digest- Claude AI Breach, Cisco Firewall 0-Day, VMware Auth Bypass, and AI Cyberattack Highlights — Multiple critical vulnerabilities and breaches impacted AI systems, Cisco firewalls, VMware, and enterprise networks.
- ArcadeDB before 26.7.3 vulnerable to authentication bypass via MCP transport — ArcadeDB versions before 26.7.3 allow authentication bypass in MCP HTTP transport, enabling arbitrary writes and schema changes.
- ArcadeDB before 26.7.3 vulnerable to privilege escalation via JavaScript triggers — ArcadeDB versions before 26.7.3 allow privilege escalation through JavaScript triggers, enabling creation of server-wide admin users.
- TIGTA finds 100+ critical vulnerabilities in IRS contractor handling tax data — TIGTA discovered over 100 critical vulnerabilities in an IRS contractor's physical and digital security supporting tax data digitization.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check