Security Intel Feed
Cyber Hose
Page 37 of 52
Threat Research & Deep Dives
Researcher Publishes RCE PoC for GitLab 18.11.3 Allowing
Read digest- Researcher Publishes RCE PoC for GitLab 18.11.3 Allowing Authenticated Command Execution — A PoC for remote code execution exploits GitLab's Oj JSON parser bug, requiring only authenticated user access.
- Rockwell patches four high-severity code execution flaws in Arena Simulation software — Rockwell Automation fixed four critical memory corruption vulnerabilities in Arena Simulation software.
Threat Research & Deep Dives
Knot Resolver before 6.4.1 vulnerable to remote code execution
Read digest- Knot Resolver before 6.4.1 vulnerable to remote code execution via heap buffer overflow — A heap-based buffer overflow in Knot Resolver's DNS-over-QUIC receive path allows remote code execution without privileges.
- Redis before 8.8.0 vulnerable to RCE via RESTORE command due to double free bug — Redis versions before 8.8.0 allow remote code execution via a RESTORE command exploit requiring authentication.
Active Exploits & Incidents
Hermes AI agent automates post-exploitation in Thai Finance Ministry
Read digest- Hermes AI agent automates post-exploitation in Thai Finance Ministry attack — Attackers used an open-source AI agent to automate privilege escalation and reconnaissance inside Thailand's Ministry of Finance.
- OnTrac discloses customer data breach after network hack in March 2026 — OnTrac suffered a network breach exposing customer personal data across 35 U.S. states.
- Botnets continue growing rapidly despite multiple takedowns, says Lumen Black Lotus Labs — Botnets leveraging residential proxy networks keep expanding globally, evading detection and rebounding quickly.
- Syscall-layer security tools miss network DoS attacks on blockchain P2P nodes — Syscall-level tools cannot detect network resource exhaustion attacks on blockchain nodes, leaving operators vulnerable.
Active Exploits & Incidents
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Read digest- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts — Attackers modify DNS on compromised hotel Wi-Fi gateways to redirect Microsoft 365 login traffic and steal credentials, bypassing MFA.
- Microweber CMS 2.0.20 vulnerable to server-side template injection allowing OS command execution — Microweber CMS 2.0.20 and earlier have a server-side template injection vulnerability exploitable by authenticated admins to execute OS commands.
Active Exploits & Incidents
Zero-day vulnerability in Check Point SmartConsole actively exploited
Read digest- Zero-day vulnerability in Check Point SmartConsole actively exploited — CVE-2026-16232 allows attackers to bypass authentication and make unauthorized security changes in Check Point SmartConsole.
- Default Azure Automation Setting Enables Cross-Tenant Identity Takeover — A default Azure Automation configuration flaw enables attackers to seize identities across Azure tenants.
- North Korean BlueNoroff uses Zoom, Teams phishing kit to profile crypto wallets before malware — BlueNoroff targets crypto sector employees with phishing kits impersonating Zoom and Teams to deliver malware.
- Certighost Exploit Lets Low-Privileged AD Users Impersonate Domain Controllers — Low-privileged AD users can exploit Certighost to impersonate Domain Controllers and perform DCSync attacks.
Active Exploits & Incidents
Bing Images SVG Flaws Allowed Remote Code Execution as SYSTEM
Read digest- Bing Images SVG Flaws Allowed Remote Code Execution as SYSTEM on Microsoft Servers — Crafted SVG files submitted to Bing Images enabled remote code execution as SYSTEM on Microsoft servers.
- Critical ChatGPT AgentForger Flaw Allowed Rogue AI Agents via Phishing Link — A phishing link could deploy rogue AI agents inside ChatGPT Workspace via a CSRF vulnerability.
- Chick-fil-A confirms credential stuffing breach impacting over 13,000 customers — Credential stuffing attack compromised over 13,000 Chick-fil-A One loyalty program customer accounts.
- Vatican's Official Prayer App Exposes 700K+ Users' Personal Data via API Leak — An unsecured API endpoint leaked personal data of over 700,000 users of the Vatican's official prayer app.
Active Exploits & Incidents
Clop ransomware exploits PTC Windchill and FlexPLM in data theft
Read digest- Clop ransomware exploits PTC Windchill and FlexPLM in data theft attacks — Clop ransomware gang exploits critical unsafe deserialization flaw CVE-2026-12569 in PTC PLM platforms to steal sensitive product data and extort victims.
- UAC-0099 group uses fake Notepad++ plugin to deliver MATCHBOIL.V2 malware — Russia-aligned UAC-0099 group deploys MATCHBOIL.V2 malware via fake Notepad++ plugin distributed through phishing emails.
- Western agencies warn of Russian hacks targeting Zimbra email servers since 2025 — Russian APT Laundry Bear exploits stored XSS zero-day in Zimbra servers to harvest credentials and 2FA codes for espionage.
Active Exploits & Incidents
Data Breach Hits Australian Energy Giant Origin, 2 Million Records
Read digest- Data Breach Hits Australian Energy Giant Origin, 2 Million Customer Records Stolen — Origin Energy confirmed a breach exposing millions of customers' personal and partial payment data with ransom threats.
- CVE-2026-46331 enables escape from Anthropic Claude Cowork local VM sandbox on macOS — A vulnerability in Anthropic Claude Cowork on macOS allows VM sandbox escape to access host filesystem and credentials.
Vulnerabilities & CVEs
Critical RCE Vulnerability Found in Microsoft M365 Copilot
Read digest- Critical RCE Vulnerability Found in Microsoft M365 Copilot — Microsoft M365 Copilot suffers a critical remote code execution vulnerability via deserialization of untrusted data, requiring low privileges.
- Critical Heap-Based Buffer Overflow in Microsoft Account Enables Remote Code Execution — A heap-based buffer overflow in Microsoft Account allows unauthorized remote code execution with no user interaction.
- Azure API Management suffers high-severity remote code execution flaw CVE-2026-35425 — Azure API Management has a remote code execution vulnerability exploitable by authorized users with high privileges.
Threat Research & Deep Dives
Multiple high-severity memory corruption flaws in Google Chrome
Read digest- Multiple high-severity memory corruption flaws in Google Chrome before 150.0.7871.186 — Google Chrome before 150.0.7871.186 contains use-after-free and out-of-bounds write flaws that allow remote code execution via crafted HTML pages.
- CVE-2026-42933 — Unintended Proxy or Intermediary in Panduit IntraVUE — A critical CVSS 10.0 vulnerability in Panduit IntraVUE allows unintended proxy or intermediary behavior.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check