Security Intel Feed
Cyber Hose
Page 31 of 52
Active Exploits & Incidents
Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft
Read digest- Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft in 41 Minutes — A firmware flaw in Coldcard Bitcoin hardware wallets allowed attackers to reproduce seed outputs and steal over $70 million in Bitcoin.
- Hackers Target 30+ Minnesota Water Systems in 48-Hour Cyberattack — More than 30 Minnesota water systems were hit by a disruption-focused cyberattack causing at least one plant shutdown.
Active Exploits & Incidents
Brinks Home Confirms Data Breach After ShinyHunters Steal 4.9M Records
Read digest- Brinks Home Confirms Data Breach After ShinyHunters Steal 4.9M Records — Nearly five million records were stolen from Brinks Home through unauthorized access to Salesforce and support systems.
Vendor Bulletins & Advisories
Rails patches critical Active Storage flaw with remote code execution
Read digest- Rails patches critical Active Storage flaw with remote code execution risk — A critical vulnerability in Rails Active Storage allows unauthenticated attackers to read arbitrary files and execute code remotely.
- Scope of Cyberattacks on U.S. Water Supply Expands, Linked to Iran — Cyberattacks targeting U.S. water supply infrastructure have expanded, with evidence suggesting Iranian involvement.
- Multiple high-severity vulnerabilities found in FreeRDP before version 3.29.0 — FreeRDP versions before 3.29.0 contain multiple critical flaws including heap overflows and use-after-free bugs that can cause crashes and memory corruption.
Active Exploits & Incidents
Adform Supply Chain Compromise Distributes Crypto-Stealing Clipboard
Read digest- Adform Supply Chain Compromise Distributes Crypto-Stealing Clipboard Hijacker — Attackers hijacked a JavaScript tracking script on Adform's domain to swap copied crypto wallet addresses with attacker-controlled ones.
- Amgen reports cloud data breach exposing patient health and proprietary info — Amgen suffered a cloud data breach exposing patient protected health information and proprietary corporate data.
- Ruby on Rails patches critical RCE vulnerability in Active Storage image processing — Ruby on Rails patched a critical unauthenticated remote code execution vulnerability affecting Active Storage with libvips.
Vulnerabilities & CVEs
Adobe Campaign Classic RCE Flaw CVE-2026-48449 Scores CVSS 10.0
Read digest- Adobe Campaign Classic RCE Flaw CVE-2026-48449 Scores CVSS 10.0 — A critical RCE vulnerability in Adobe Campaign Classic allows arbitrary code execution without user interaction.
- Hijacked Hotel Wi-Fi Delivers CornFlake RAT via Fake Browser Updates — Attackers hijack hotel Wi-Fi DNS to deliver CornFlake RAT via fake browser update pages, stealing credentials and spying on users.
Threat Research & Deep Dives
Adform supply chain hack steals cryptocurrency from Finnish betting
Read digest- Adform supply chain hack steals cryptocurrency from Finnish betting site — Malicious code injected via Adform's supply chain targeted cryptocurrency wallets of Veikkaus users.
Threat Research & Deep Dives
Command Injection Flaw in TP-Link Archer AXE75 OpenVPN Module
Read digest- Command Injection Flaw in TP-Link Archer AXE75 OpenVPN Module — Authenticated adjacent attackers can execute arbitrary OS commands by importing malicious VPN client configs.
Vulnerabilities & CVEs
ComfyUI 0.23.0 vulnerable to unauthenticated remote code execution
Read digest- ComfyUI 0.23.0 vulnerable to unauthenticated remote code execution — ComfyUI 0.23.0 allows unauthenticated attackers to execute arbitrary Python code via crafted pickle files.
- Critical RCE Vulnerability in sentence-transformers via Local Model Load Bypass — sentence-transformers library allows arbitrary code execution when loading local models without proper security.
- Savon Ruby SOAP Client Vulnerable to Code Execution via WSDL Operation Names (CVE-2026-53510) — Savon Ruby SOAP client versions before 2.17.2 allow remote code execution via crafted WSDL operation names.
Active Exploits & Incidents
Amgen confirms July 2026 cloud data breach exposing sensitive patient
Read digest- Amgen confirms July 2026 cloud data breach exposing sensitive patient and proprietary data — Amgen suffered a cloud data breach exposing sensitive proprietary and patient health data from AWS-hosted environments.
- Chinese-Speaking Hackers Target Central Asian Governments with OctLurk and SilkLurk Malware — Chinese-speaking hackers used OctLurk and SilkLurk backdoors to target government and critical sectors in Central Asia and Syria.
- Cyberattacks Hit Water Facilities in Seven U.S. States, Disrupting Operations — Multiple water treatment plants across seven U.S. states experienced cyberattacks disrupting their operations.
Active Exploits & Incidents
CISA warns of cyberattacks disrupting US water utilities via exposed
Read digest- CISA warns of cyberattacks disrupting US water utilities via exposed PLCs — CISA warns of increased cyberattacks targeting internet-exposed PLCs in US water utilities causing operational disruptions.
- Chinese threat actor uses DeepSeek AI for autonomous cyberattacks on exposed servers — A Chinese threat actor used DeepSeek AI to autonomously attack vulnerable servers running Langflow and n8n platforms.
- pgAdmin 4 OS command injection via MASTER_PASSWORD_HOOK username substitution (CVE-2026-17347) — pgAdmin 4's MASTER_PASSWORD_HOOK setting allows OS command injection via malicious usernames from external auth sources.
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm — Spear-phishing attack using HollowFrame loader deployed Matryoshka backdoor on law firm endpoints.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check