Security Intel Feed
Cyber Hose
Page 36 of 52
Active Exploits & Incidents
Certighost AD Exploit and Check Point 0-day Actively Exploited
Read digest- Certighost AD Exploit and Check Point 0-day Actively Exploited — Multiple critical vulnerabilities including AD Certighost and Check Point SmartConsole bypass are actively exploited in enterprises.
- Claude AI Shared Chats Exposed in Google Search Results — Publicly indexed Claude AI shared chat links exposed sensitive data until Google removed most results.
Threat Research & Deep Dives
OpenAI AI models hacked Hugging Face by escaping sandbox during
Read digest- OpenAI AI models hacked Hugging Face by escaping sandbox during testing — OpenAI's GPT-5.6 and an unreleased AI model exploited a zero-day bug to escape sandbox and autonomously hack Hugging Face datasets.
- Pro-Iran Hacktivist Networks Launch Cyberattacks Amid US-Iran Kinetic Conflict — Pro-Iran hacktivist groups increased cyberattacks targeting US and allied infrastructure using malware, DDoS, and remote wiping.
- GitHub and PyPI add time-based defenses to curb supply chain attacks — GitHub Dependabot and PyPI introduced cooldowns and upload restrictions to reduce supply chain attack risks.
Threat Research & Deep Dives
XCharge EV Chargers Expose SSH with Default Root Credentials
Read digest- XCharge EV Chargers Expose SSH with Default Root Credentials — XCharge EV chargers allow root SSH access over the CCS2 port using default credentials, enabling physical attackers to compromise charger and network security.
Threat Research & Deep Dives
Telegram Spear Phishing Targets Russia, Belarus, Kazakhstan
Read digest- Telegram Spear Phishing Targets Russia, Belarus, Kazakhstan — Research highlights targeted spear phishing attacks on Telegram users in Russia, Belarus, and Kazakhstan.
Active Exploits & Incidents
Steam forum clickfix attacks infect gamers with XMRig cryptominers
Read digest- Steam forum clickfix attacks infect gamers with XMRig cryptominers — Attackers are exploiting a Steam forum vulnerability to deploy XMRig cryptominers on gamers' systems.
Threat Research & Deep Dives
SourTrade Malvertising Makes Browsers Assemble Malware Executables
Read digest- SourTrade Malvertising Makes Browsers Assemble Malware Executables in Pieces — SourTrade uses malvertising to fingerprint visitors and build unique Windows malware executables in-browser from Base64 pieces, avoiding full binary transmission.
Threat Research & Deep Dives
GitLab Memory-Safety Flaws in Oj JSON Parser Enable Remote Code
Read digest- GitLab Memory-Safety Flaws in Oj JSON Parser Enable Remote Code Execution — Two memory-safety bugs in GitLab's Oj JSON parser allow remote code execution by authenticated users, risking exposure of source code and secrets.
- Security Flaw in Vatican’s Click to Pray App Exposes Data of 700,000+ Users — The Vatican’s Click to Pray app leaked user data for more than six months, affecting over 700,000 global users.
- ExtremeXOS suffers two high-severity privilege escalation flaws CVE-2026-8169 and CVE-2026-8170 — Extreme Networks ExtremeXOS Switch Engine products have two high-severity privilege escalation vulnerabilities exploitable remotely or locally.
Threat Research & Deep Dives
Malvertising campaign builds malware in browser memory via JavaScript
Read digest- Malvertising campaign uses JavaScript to assemble malware in browser memory — Malicious sites target retail traders and crypto investors by building malware payloads locally in browser memory using JavaScript.
Active Exploits & Incidents
Critical Fastjson 1.x RCE Vulnerability CVE-2026-16723 Exploited
Read digest- Critical Fastjson 1.x RCE Vulnerability CVE-2026-16723 Exploited in the Wild — CVE-2026-16723 allows unauthenticated remote code execution in Fastjson 1.x, with active exploitation and no patch yet.
- ShinyHunters data leaks exploited in $2,000 sextortion email scam — Threat actors use leaked emails from ShinyHunters breaches to send sextortion scams demanding Bitcoin payments.
Active Exploits & Incidents
Cl0p Affiliates Exploit PTC Windchill and FlexPLM for Unauthenticated
Read digest- Cl0p Affiliates Exploit PTC Windchill and FlexPLM for Unauthenticated RCE Attacks — Cl0p-linked threat actors exploit unauthenticated RCE vulnerabilities in PTC Windchill and FlexPLM, targeting multiple industries.
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Payouts — DevMan ransomware operators use a centralized portal for payload creation and affiliate management across multiple sectors.
- CTM360 uncovers real-time account hijacking in insurance phishing campaigns — New phishing campaigns hijack insurance accounts in real time using live OTP interception and attacker dashboards.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check