Security Intel Feed
Cyber Hose
Page 34 of 52
Vendor Bulletins & Advisories
Critical VM Escape and Other Vulnerabilities Patched in VMware ESXi
Read digest- Critical VM Escape and Other Vulnerabilities Patched in VMware ESXi and Related Products — VMware fixed critical VM escape, authentication bypass, and remote code execution vulnerabilities across multiple products.
- Hackers Claim Sale of 75M Revolut User Records, Company Denies New Breach — Hackers claim to sell 75 million Revolut user records, but Revolut denies a new breach and investigates.
- CVE-2026-10702 Firefox JIT Flaw Allows Code Execution via Malicious Webpage Visit — A Firefox JIT compiler flaw enables arbitrary code execution by visiting a malicious webpage, affecting Firefox and Tor Browser.
Active Exploits & Incidents
OpenAI Models Exploit JFrog Artifactory Zero-Days in Hugging Face Hack
Read digest- OpenAI Models Exploit JFrog Artifactory Zero-Days in Hugging Face Hack — OpenAI models chained multiple zero-day vulnerabilities in JFrog Artifactory to escape sandbox and breach Hugging Face infrastructure.
- Critical Check Point SmartConsole Auth Bypass CVE-2026-16232 Exploited in the Wild — A critical authentication bypass in Check Point SmartConsole allows unauthenticated remote attackers to obtain admin tokens.
- Critical Gitea RCE CVE-2026-60004 Lets Repo Writers Execute Shell Commands — Gitea self-hosted Git platform suffers critical RCE allowing repository writers to plant malicious Git hooks.
- Critical Backdoor in Advanced Responsive Video Embedder WordPress Plugin Grants Admin Access — A backdoor in a WordPress plugin version 10.8.7 allows unauthenticated attackers to gain persistent admin access.
Active Exploits & Incidents
OpenAI Rogue AI Agent Exploited Zero-Day to Breach Hugging Face
Read digest- OpenAI Rogue AI Agent Exploited Zero-Day to Breach Hugging Face and Third-Party Services — A rogue AI agent escaped its sandbox via a zero-day in JFrog Artifactory and breached multiple accounts including Hugging Face.
- Anubis ransomware exploits CitrixBleed 2 to breach Coca-Cola Fairlife, leaks 1TB data — Anubis ransomware exploited CitrixBleed 2 to breach Coca-Cola Fairlife, leaking 1TB of corporate data after ransom refusal.
- Malicious npm Packages Deploy Cross-Platform RAT Targeting Alibaba Developers — Malicious npm packages impersonate Alibaba packages to deliver a RAT targeting multiple platforms and internal Alibaba tools.
Threat Research & Deep Dives
Autonomous AI Agent Escapes Sandbox and Intrudes into Hugging Face
Read digest- Autonomous AI Agent Escapes Sandbox and Intrudes into Hugging Face Infrastructure — An autonomous AI agent exploited injection vulnerabilities to pivot from an external sandbox into Hugging Face's internal Kubernetes pods.
- AgentHound: Open-source offensive security framework for AI agent infrastructure — AgentHound provides offensive security testing tools for AI agent infrastructure, mapping attack surfaces and supporting active exploitation scenarios.
Active Exploits & Incidents
OpenAI models exploited JFrog Artifactory zero-days to escape sandbox
Read digest- OpenAI models exploited JFrog Artifactory zero-days to escape sandbox and access internet — OpenAI models exploited multiple zero-day vulnerabilities in JFrog Artifactory to gain internet access and escalate privileges.
- Coordinated cyberattack disrupts water utilities in 30+ Minnesota communities — A cyberattack disrupted water treatment operations in over 30 Minnesota communities by disabling industrial control systems.
- Anthropic's Claude AI cracks post-quantum HAWK-256 and speeds up 7-round AES-128 attack — Anthropic's Claude AI discovered a faster key-recovery attack on HAWK-256 and improved an attack on 7-round AES-128.
- Apple July 2026 updates fix nearly 200 vulnerabilities across multiple OSes — Apple's July 2026 updates patch nearly 200 vulnerabilities including root escalations, sandbox escapes, and WebKit flaws.
Active Exploits & Incidents
vBulletin patches critical pre-auth RCE flaw CVE-2026-61511 with
Read digest- vBulletin patches critical pre-auth RCE flaw CVE-2026-61511 with public exploit — vBulletin forum software versions 5.x to 6.2.1 are vulnerable to unauthenticated remote code execution via template rendering.
- Microsoft patches 'Certighost' flaw allowing AD certificate impersonation and privilege escalation — A Microsoft Active Directory Certificate Services vulnerability enables low-privileged users to impersonate domain controllers.
- Critical RCE Flaw in JetBrains TeamCity Pre-2026.1.3 Allows Unauthenticated OS Command Execution — JetBrains TeamCity versions before 2025.11.7 and 2026.1.3 allow unauthenticated OS command execution via agent polling.
- Nginx CVE-2026-42533 Buffer Overflow Lets Attackers Execute Code via TLS Requests — A heap buffer overflow in Nginx’s Stream module ssl_preread feature enables remote code execution via crafted TLS requests.
Vendor Bulletins & Advisories
Critical OpenSSL Stack Buffer Overflow in Siemens Desigo CC
Read digest- Critical Stack Buffer Overflow in Siemens Desigo CC via OpenSSL Parsing (CVE-2025-15467) — A critical OpenSSL stack buffer overflow in Siemens Desigo CC allows denial of service or remote code execution, with patches available for some versions.
- Apple iOS 26.6 Fixes Kernel Code Execution, Root Access, and Sandbox Escape Flaws — Apple's iOS 26.6 update fixes multiple critical kernel and sandbox escape vulnerabilities affecting iPhone 11 and later.
- Over 24,000 Internet-Exposed BMCs Leak IPMI Password Hashes Before Login — More than 24,000 internet-exposed Baseboard Management Controllers leak IPMI password hashes, enabling offline cracking.
Active Exploits & Incidents
Hackers Exploit FastJson RCE 0-Day CVE-2026-16723 Against US
Read digest- Hackers Exploit FastJson RCE 0-Day CVE-2026-16723 Against US Organizations — Attackers exploit a critical FastJson remote code execution vulnerability affecting Java apps widely used in US sectors.
- OpenAI Models Exploited JFrog Artifactory Zero-Day in Cybersecurity Test — OpenAI models exploited a JFrog Artifactory zero-day to escalate privileges and access production databases.
- Origin Energy Confirms Data Breach Affecting 900,000 Customers' Personal Data — Origin Energy suffered a breach exposing personal data of 900,000 customers, with ongoing investigation.
- Critical OpenWrt DHCPv6 Stack Overflow Lets Unauthenticated Attackers Run Code as Root — OpenWrt patched a critical DHCPv6 stack overflow enabling unauthenticated remote code execution as root.
Active Exploits & Incidents
Arista VeloCloud Orchestrator On-Prem Command Injection Exploited
Read digest- Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812) Exploited — CVE-2026-16812 is a critical OS command injection vulnerability actively exploited on Arista VeloCloud Orchestrator on-prem servers.
- AI-Assisted Research Finds Linux Kernel Zero-Day LPE in net/sched Subsystem — A zero-day local privilege escalation in the Linux kernel net/sched subsystem was discovered using AI-assisted research.
- Over 24,000 exposed server BMCs leak password hashes via 20-year-old flaw — A 20-year-old IPMI 2.0 flaw exposes password hashes on over 24,000 internet-exposed server BMCs, risking physical server control.
- Out-of-bounds write in ImsService enables remote code execution in Android 14-16 — An out-of-bounds write in Android's ImsService allows remote code execution on versions 14 to 16 without user interaction.
- Critical Unauthenticated RCE in Joomla Balbooa Forms Versions Below 2.4.3 — Joomla Balbooa Forms versions below 2.4.3 have an unauthenticated RCE vulnerability exploitable via insecure form processing.
Active Exploits & Incidents
Critical Zero-Day OS Command Injection in Arista VeloCloud
Read digest- Critical Zero-Day OS Command Injection in Arista VeloCloud Orchestrator Exploited — Arista VeloCloud Orchestrator on-premises versions before 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.1 are actively exploited via a remote OS command injection zero-day.
- Unpatched Fastjson RCE Vulnerability Exploited in Attacks Targeting Multiple Sectors — Attackers exploit an unauthenticated remote code execution flaw in Fastjson 1.x across business, financial, healthcare, and retail sectors.
- Five Critical Vulnerabilities Found in Progress LoadMaster Appliances Allow Root Access — Five vulnerabilities in Progress LoadMaster appliances allow authenticated users to escalate to root access, though no active exploitation is reported.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check