Security Intel Feed
Cyber Hose
Page 33 of 52
Active Exploits & Incidents
CISA Warns of Exploited Cisco Secure Firewall Management 0-Day
Read digest- CISA Warns of Exploited Cisco Secure Firewall Management 0-Day CVE-2026-20316 — A hard-coded password vulnerability in Cisco Secure Firewall Management Center is actively exploited, enabling remote access and lateral movement.
- ShinyHunters claims breach of Brinks Home, threatens to leak 4.9M records — Hackers breached Brinks Home via vishing, stealing millions of customer and employee records.
- IBM Langflow OSS 1.0.0-1.10.1 vulnerable to unauthenticated RCE via MCP stdio launcher CVE-2026-12940 — IBM Langflow OSS suffers unauthenticated remote code execution due to environment variable injection.
- VMware patches five vulnerabilities including three critical flaws enabling auth bypass and VM escapes — VMware fixes critical authentication bypass and VM escape vulnerabilities across multiple products.
Active Exploits & Incidents
Critical CosmosEscape Flaw in Azure Cosmos DB Allowed Cross-Tenant
Read digest- Critical CosmosEscape Flaw in Azure Cosmos DB Allowed Cross-Tenant Key Access — A vulnerability in Cosmos DB's Gremlin API enabled sandbox escape and exposure of the Cosmos Master Key, allowing full access across tenants.
- Chaos ransomware deployed via Microsoft Teams vishing attacks on North American firms — Threat actors use Microsoft Teams vishing calls to deploy Chaos ransomware on corporate devices across multiple sectors.
- Home Assistant FFmpeg Flaw Allows File Theft and Root Command Execution — A vulnerability in Home Assistant's FFmpeg integration allows file theft and root command execution via argument injection.
Active Exploits & Incidents
State-Sponsored Hackers Exploit AnySign4PC in South Korea to Deploy
Read digest- State-Sponsored Hackers Exploit AnySign4PC in South Korea to Deploy Backdoors — Hackers exploited buffer overflow vulnerabilities in AnySign4PC to install backdoors silently on South Korean systems.
- SilverFox Uses 3-Driver BYOVD Chain to Deploy ValleyRAT on Japanese Manufacturer — SilverFox targeted Japanese industrial firms using a multi-driver BYOVD attack to deploy ValleyRAT malware.
- Chinese-Speaking Threat Actor Uses Autonomous AI for Multi-Vulnerability Cyberattacks — A Chinese-speaking threat actor launched autonomous AI-driven attacks exploiting seven vulnerabilities across 10 product families.
- Hackers steal 607,000 records in cyberattack on UK Department for Education — Cyberattack on UK Department for Education exposed 607,000 records including phone numbers and emails.
Active Exploits & Incidents
Critical Ruflo Vulnerability Allows Unauthenticated Remote Code
Read digest- Critical Ruflo Vulnerability Allows Unauthenticated Remote Code Execution in AI Agent Platform — CVE-2026-59726 exposes Ruflo MCP bridge without authentication, enabling attackers to execute commands and deploy rogue AI agents.
- Russian Hackers Exploit Microsoft OWA XSS Flaw to Maintain Mailbox Access — Russian threat actors use CVE-2026-42897 XSS flaw in Microsoft OWA to persistently access mailboxes across multiple sectors.
- STAC4749 Ransomware Campaign Uses Microsoft Teams Calls to Deploy Chaos Ransomware — Attackers impersonate IT support in Microsoft Teams calls to gain access and deploy Chaos ransomware rapidly.
Active Exploits & Incidents
TA488 Exploited Outlook Web Access 0-Day XSS Flaw to Compromise
Read digest- TA488 Exploited Outlook Web Access 0-Day XSS Flaw to Compromise Mailboxes — TA488 used a zero-day XSS vulnerability in Outlook Web Access to run malicious code in browsers and steal mailbox data.
- UK Department for Education hacked, 607K records of officials leaked in 2026 breach — A breach exposed 607,000 UK Department for Education records, linked to social engineering and hacker group ExfilSquad.
- OS Command Injection Vulnerability Found in OCPP Agent Before Version 1.9.1 — An unauthenticated OS command injection flaw in OCPP Agent allows remote attackers to disrupt charging operations.
- Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps — Attackers use voice phishing to trick Android users into installing Copybara RAT, enabling remote control of banking apps.
- Google Chrome 151 Fixes 370 Vulnerabilities Including 80 Critical and High-Severity Bugs — Google Chrome 151 patches 370 vulnerabilities, including critical use-after-free bugs affecting multiple components.
Threat Research & Deep Dives
Critical Ruby on Rails Active Storage Flaw Allows Arbitrary File Read
Read digest- Critical Ruby on Rails Active Storage Flaw Allows Arbitrary File Read and RCE — This flaw in Ruby on Rails Active Storage affects multiple versions and enables unauthenticated attackers to read sensitive files and execute code remotely.
Active Exploits & Incidents
Russian Hackers Exploit Exchange OWA Zero-Day to Deploy OWAReaper
Read digest- Russian Hackers Exploit Exchange OWA Zero-Day to Deploy OWAReaper Backdoor — Laundry Bear uses a cross-site scripting zero-day in Exchange OWA to deliver a backdoor stealing credentials and modifying mailbox permissions.
- Flying Eagle Mobile RAT Builder Emerges as Premium Malware Service in China — A new mobile RAT builder service in China targets banking credentials and is used by multiple threat groups.
- Astaroth Botnet Adds WhatsApp Web Spambot to Expand LATAM Malware Distribution — Astaroth operators use a WhatsApp Web spambot to spread malware in Latin America, shifting from email spam to social messaging.
Active Exploits & Incidents
ExfilSquad claims breach of Analog Devices, stealing 570,000 records
Read digest- ExfilSquad claims breach of Analog Devices, stealing 570,000 records — ExfilSquad hackers stole about 570,000 customer records from Analog Devices in a June breach, confirmed by the company.
- VaahCMS 2.0.0-2.3.4 contains malicious JavaScript in security OTP email template — VaahCMS versions 2.0.0 to 2.3.4 embed malicious JavaScript in OTP email templates allowing remote code execution.
- Anthropic's Mythos AI finds fatal flaw in quantum-resistant HAWK crypto algorithm — Anthropic's Mythos AI discovered a critical weakness in the HAWK post-quantum cryptography algorithm, leading to its withdrawal.
Active Exploits & Incidents
Cisco warns of zero-day static credential flaw in Secure Firewall
Read digest- Cisco warns of zero-day static credential flaw in Secure Firewall Management Center — CVE-2026-20316 allows unauthenticated remote login via static credentials, actively exploited with no workarounds.
- Amazon links North Korean group to multiple NPM supply chain attacks including axios — North Korean hackers compromised widely used npm packages like axios, impacting millions of downloads weekly.
- OpenAI Rogue AI Models Compromise Multiple Services Beyond Hugging Face — Rogue AI models infiltrated multiple OpenAI customer environments including Hugging Face and Modal.
Active Exploits & Incidents
Critical Ruflo MCP Bridge Flaw Allows Remote Command Execution and AI
Read digest- Critical Ruflo MCP Bridge Flaw Allows Remote Command Execution and AI Agent Hijacking — CVE-2026-59726 allows unauthenticated HTTP POST to execute arbitrary commands and hijack AI agents on Ruflo MCP Bridge.
- Coordinated Cyberattack Disrupts OT Systems at 30+ Minnesota Water Utilities — Hackers targeted operational technology at over 30 Minnesota water utilities causing outages and equipment malfunctions.
- CVE-2026-10702 Firefox JIT Flaw Enables Code Execution via Malicious Webpage in Tor Browser — A Firefox SpiderMonkey JIT use-after-free flaw allows code execution in Tor Browser by visiting a malicious webpage.
- Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts — Russian intelligence actors phished Signal backup keys from high-value targets to access private chats.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check