Security Intel Feed
Cyber Hose
Page 35 of 52
Active Exploits & Incidents
Attackers Exploit Critical Command Injection Flaw in Arista VeloCloud
Read digest- Attackers Exploit Critical Command Injection Flaw in Arista VeloCloud Orchestrator — CVE-2026-16812 allows remote OS command injection in Arista VeloCloud Orchestrator, leading to full compromise and active exploitation.
- CISA Warns of Active Exploitation of Fortinet FortiOS Vulnerability CVE-2025-68686 — Fortinet FortiOS vulnerability CVE-2025-68686 is actively exploited to expose sensitive information via symlink persistence bypass.
- Origin Energy Data Breach Exposes Personal Data of 900,000 Australians — Data breach at Origin Energy exposed personal data of 900,000 customers, with ransom threats reported but unconfirmed.
- Operation STANDOFF Uses GitHub Redirects to Mask Russian Cybercrime Campaign — Russian cybercrime campaign Operation STANDOFF uses GitHub redirects to deliver multi-malware payloads and evade detection.
- DCSync Attack Enables Silent Theft of Active Directory Password Hashes — DCSync attacks allow stealthy theft of Active Directory password hashes by impersonating domain controllers using replication rights.
Threat Research & Deep Dives
Europol Launches Project COMPASS to Combat Teen Hacker Network
Read digest- Europol Launches Project COMPASS to Combat Teen Hacker Network Exploiting Minors — Europol's Project COMPASS disrupts a decentralized teen hacker network involved in cybercrime, extortion, and violent offenses.
- New SPORE attack extracts private memory from isolated LLM agents via tool interfaces — Researchers reveal a novel attack extracting private data from long-term memory in LLM agents, risking user privacy in multi-user setups.
Threat Research & Deep Dives
Autonomous AI Agent Hermes Used in Espionage Attack on Thai Ministry
Read digest- Autonomous AI Agent Hermes Used in Espionage Attack on Thai Ministry of Finance — Attackers leveraged the open-source Hermes AI agent in unrestricted mode to conduct espionage on Thailand's Ministry of Finance.
Active Exploits & Incidents
New Certighost PoC exploit enables attackers to hijack Windows domains
Read digest- New Certighost PoC exploit enables attackers to hijack Windows domains — The exploit targets Windows Active Directory Certificate Services to allow low-privileged users to impersonate Domain Controllers and perform privileged AD operations.
- Confused Deputy Flaws Persist in Google Cloud and Microsoft Azure — Confused deputy vulnerabilities in major cloud platforms enable attackers to bypass access controls and escalate privileges to admin levels.
- New AI attack reconstructs typed text from keyboard sounds with up to 99% accuracy — Researchers developed an AI method that reconstructs typed text from acoustic keystroke sounds with high accuracy using unsupervised audio analysis and Transformer models.
Threat Research & Deep Dives
Critical OS Command Injection in Arista VeloCloud Orchestrator On-Prem
Read digest- Critical OS Command Injection in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812) — CVE-2026-16812 allows remote OS command execution and compromises confidentiality, integrity, and availability of the orchestrator.
Active Exploits & Incidents
Dysphoria IoT Botnet Uses Blockchain C2 and Victim Relays After
Read digest- Dysphoria IoT Botnet Uses Blockchain C2 and Victim Relays After JackSkid Takedown — The Dysphoria IoT botnet employs blockchain-based name services and victim relay meshes to evade takedown and infect over 200,000 devices.
- phpMyFAQ before 4.1.6 vulnerable to remote code execution via configuration API — Authenticated admins can exploit a remote code execution flaw in phpMyFAQ versions before 4.1.6 by uploading malicious ZIP attachments.
- SiYuan before v3.7.2 vulnerable to stored XSS leading to RCE via title-img attribute — Stored XSS in SiYuan before v3.7.2 allows editors to execute arbitrary code with full Node.js access in Electron renderer.
- SiYuan Desktop before v3.7.2 vulnerable to reflected XSS leading to RCE via siyuan protocol — Reflected XSS in SiYuan Desktop before v3.7.2 enables remote code execution without privileges or user interaction.
Active Exploits & Incidents
Hacked Public Wi-Fi Gateways Steal Microsoft 365 Corporate Credentials
Read digest- Hacked Public Wi-Fi Gateways Used to Steal Microsoft 365 Corporate Credentials — Attackers compromise SOHO Wi-Fi gateways at public venues to intercept Microsoft 365 credentials via DNS redirection.
- Windows WalletService Flaw Lets Standard Users Escalate to SYSTEM Privileges — A local privilege escalation vulnerability in Windows WalletService allows code execution as SYSTEM without admin rights.
- Anubis Ransomware Hits Coca-Cola's Fairlife, Causing Data Breach and Production Halt — Anubis ransomware encrypted systems and exfiltrated 1 TB of data, halting production at four Fairlife facilities.
- Critical RCE Vulnerability in Fastjson Java Library Actively Exploited Since July 2026 — CVE-2026-16723 enables unauthenticated remote code execution in Fastjson 1.x, actively exploited across multiple sectors.
Active Exploits & Incidents
Ransomware Gangs Exploit VPN and Firewall Flaws in Palo Alto
Read digest- Ransomware Gangs Exploit VPN and Firewall Flaws in Palo Alto, Fortinet, Citrix, Check Point — Ransomware operators exploit authentication bypass and credential harvesting vulnerabilities in major VPN and firewall appliances.
- DentaQuest Data Breach in May 2026 Potentially Affects Over 23 Million People — Hackers stole sensitive personal and dental health information from DentaQuest, impacting millions.
- East Asian-linked TELESHIM malware abuses Telegram for C2 in Middle East govt attacks — New malware campaign uses Telegram API for command-and-control to evade detection in Middle East government attacks.
- SparkKitty malware steals crypto wallet seed phrases from iOS and Android photos — Malware uses OCR to steal cryptocurrency wallet seed phrases from mobile device photos.
- BlueNoroff Hijacks Trusted Telegram Accounts to Spread ClickFix Malware via Fake Zoom Calls — Threat actor hijacks Telegram accounts to deliver malware via fake video call invites targeting crypto firms.
Threat Research & Deep Dives
Researchers Boot Jailbroken iOS 27 on iPhone 11 Pro Using usbliter8
Read digest- Researchers Boot Jailbroken iOS 27 on iPhone 11 Pro Using usbliter8 Exploit — The exploit requires physical access and specialized hardware to bypass iOS security, disabling critical services.
- New JSON RCE Bug Threatens Java Ecosystem — A critical remote code execution vulnerability in JSON parsing threatens Java applications, though details remain scarce.
- PyPI Blocks File Uploads on Releases Older Than 14 Days to Prevent Package Poisoning — PyPI now blocks file uploads on old releases to prevent supply-chain attacks exploiting compromised maintainer tokens.
Active Exploits & Incidents
Critical AgentForger Flaw Lets Phishing Links Deploy Rogue ChatGPT
Read digest- Critical AgentForger Flaw Lets Phishing Links Deploy Rogue ChatGPT Workspace Agents — Phishing links exploit URL parameters to auto-create malicious ChatGPT Workspace Agents that exfiltrate data and steal credentials.
- PEAR Ransomware Group Breaches MCBS, Exposes Data of 1.2 Million Individuals — PEAR ransomware group stole 3 TB of sensitive data from MCBS, impacting over 1.2 million people including healthcare organizations.
- Eight High-Severity Vulnerabilities Found in NodeBB Versions Before 4.14.0 — Critical stored XSS and authorization bypass flaws affect millions of NodeBB forum users prior to version 4.14.0, patched responsibly.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check