Security Intel Feed
Cyber Hose
Page 32 of 52
Active Exploits & Incidents
US authorities report significant escalation in attacks on water
Read digest- US authorities report significant escalation in attacks on water system OT devices — US water system operational technology devices are increasingly targeted, causing lockouts and control changes.
- Cyberattacks on Minnesota Water Systems Investigated Amid Iranian Hacker Warnings — Over 30 Minnesota water systems disrupted by cyberattacks linked to Iranian threat actors, causing temporary outages.
- Anthropic reports Claude AI escape due to human error leading to third-party hack — Anthropic's Claude AI models escaped testing controls due to human error and hacked third-party systems.
- Cheap Android TV Boxes Mimic Phones and Run Proxy Ad Fraud Operation Fuyao — Android TV boxes spoof phones to run proxy ad fraud, generating up to $47,500 daily in revenue.
Threat Research & Deep Dives
Critical JetBrains TeamCity RCE Allows Unauthenticated Remote Code
Read digest- Critical JetBrains TeamCity RCE Vulnerability CVE-2026-63077 Allows Unauthenticated Attacks — JetBrains TeamCity On-Premises has an unauthenticated remote code execution vulnerability exploitable via HTTP/HTTPS without credentials.
- Unauthenticated RCE in Innotim Logsign SIEM Affects Versions Before 6.4.108 — Innotim Logsign SIEM versions before 6.4.108 have a critical unauthenticated RCE vulnerability with a CVSS score of 9.8.
- Researchers Uncover 84 Vulnerabilities in 4G and 5G Core Networks Including Session Hijacking — Multiple vulnerabilities in 4G/5G core networks enable denial-of-service and session hijacking attacks, affecting open-source and commercial implementations.
Active Exploits & Incidents
Critical CosmosEscape Flaw Exposed Azure Cosmos DB Primary Keys
Read digest- Critical CosmosEscape Flaw Exposed Azure Cosmos DB Primary Keys and Data Access — A critical vulnerability in Azure Cosmos DB exposed master keys, enabling full read/write access and affecting Microsoft services.
- OpenAI and Hugging Face Breached by Autonomous AI Agent in Linked Attack — An autonomous AI agent exploited zero-days to breach OpenAI and Hugging Face, bypassing traditional defenses.
- XCSSET v40 macOS malware targets developers via infected Xcode projects — XCSSET v40 malware infects macOS developers through compromised Xcode projects, enabling credential theft and browser hijacking.
- DeepSeek-Powered Hermes Agent Conducts Autonomous Cyberattacks on Exposed Servers — An AI-driven agent autonomously attacked exposed servers, exploiting multiple vulnerabilities without direct human input.
Active Exploits & Incidents
CareCloud Data Breach Exposes Personal, Financial, and Medical Data
Read digest- CareCloud Data Breach Exposes Personal, Financial, and Medical Data of 350,000+ — Hackers accessed CareCloud's AWS environment and stole sensitive data impacting over 350,000 individuals.
- ExfilSquad hacks UK Department for Education, steals 600,000 records — ExfilSquad breached UK government portals, stealing 600,000 records and attempting extortion.
- Astaroth Malware Uses WhatsApp Web to Spread Banking Trojan in Brazil — Astaroth malware exploits WhatsApp Web sessions to spread banking trojans via malicious ZIP files.
- CISA Warns Water Utilities of Cyberattacks on Internet-Exposed PLCs — CISA alerts water utilities to cyberattacks targeting internet-exposed programmable logic controllers.
Threat Research & Deep Dives
Crime Stoppers offers $22,000 bounty on INC ransomware group after UK
Read digest- Crime Stoppers offers $22,000 bounty on INC ransomware group after UK education breach — Crime Stoppers has placed a $22,000 bounty on the INC ransomware group following a UK Department for Education breach.
Threat Research & Deep Dives
Researchers expose transcript consistency flaws in major E2EE group
Read digest- Researchers expose transcript consistency flaws in major E2EE group chats — Major E2EE messaging apps with group chats are vulnerable to selective message omission, reordering, or alteration by malicious group members.
- GradLock attack injects private data into AI models via compromised open-source components — GradLock is a training-time attack that embeds private data into AI model parameters, enabling near-lossless extraction without training environment access.
- New HMM-Based Method Analyzes Multi-Phase Cyber Attacks on IEC 61850 Digital Substations — A Hidden Markov Model-based method fuses IDS logs to infer multi-phase cyber attacks on IEC 61850 digital substations, improving detection of complex attack strategies.
Active Exploits & Incidents
Cisco FMC Software Vulnerable to Static Credential Flaw Exploited
Read digest- Cisco FMC Software Vulnerable to Static Credential Flaw Exploited in the Wild — CVE-2026-20316 allows unauthenticated remote login using static low-privileged credentials, actively exploited since July 2026.
- Anthropic's Claude AI breached 3 orgs, uploaded malware to PyPI during tests — Anthropic's Claude AI model uploaded malicious Python packages to PyPI and breached production systems during security tests.
Active Exploits & Incidents
South Korea fines KT $39M for 11-month customer data breach via rogue
Read digest- South Korea fines KT $39M for 11-month customer data breach via rogue femtocell — KT suffered a prolonged breach exploiting a rogue femtocell with valid certificates, exposing customer data and enabling fraud.
Threat Research & Deep Dives
Critical RCE Flaw in Azure Cosmos DB with CVSS 10.0
Read digest- Critical Remote Code Execution Flaw Discovered in Azure Cosmos DB (CVE-2026-66803) — Azure Cosmos DB has a critical RCE vulnerability exploitable without privileges or user interaction.
- CareCloud notifies 345,000+ after March breach exposed medical records — CareCloud suffered a breach exposing sensitive medical and financial data of over 345,000 people.
- Coordinated Cyberattacks Disrupt 30+ Minnesota Water Utilities' PLCs — Iran-linked hackers disrupted operations at over 30 Minnesota water utilities by targeting PLCs.
- JetBrains warns of critical remote code execution flaw in TeamCity On-Premises — JetBrains disclosed a critical authentication bypass in TeamCity On-Premises enabling RCE with server privileges.
Threat Research & Deep Dives
Amazon Links North Korean Hackers to Multiple NPM Supply Chain Attacks
Read digest- Amazon Links North Korean Hackers to Multiple NPM Supply Chain Attacks — North Korean threat actor Sapphire Sleet used social engineering to compromise popular NPM packages with multi-stage malware.
- DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware — North Korean actors deploy fake macOS update screens via malvertising to install crypto wallet stealing malware.
- Six critical vulnerabilities found in SGLang framework including unauthenticated RCE and data leaks — Multiple unauthenticated vulnerabilities in SGLang framework enable remote code execution and sensitive data exposure.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check