Security Intel Feed
Cyber Hose
Page 39 of 52
Active Exploits & Incidents
Upbound hack enables $13M in fraudulent Acima lease agreements
Read digest- Upbound hack enables $13M in fraudulent Acima lease agreements — Upbound was hacked, allowing threat actors to create $13 million in fraudulent Acima leases using stolen customer data.
- Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack — Stadler Rail rejected a $12.3 million ransom demand after a cyberattack targeting a supplier data exchange platform.
- Sandworm_Mode malware exploits trusted AI toolchains to evade detection — Sandworm_Mode malware integrates into AI toolchains to blend malicious activity with legitimate workflows and evade detection.
- Oracle fixes 1,449 vulnerabilities in July 2026 quarterly security update — Oracle patched 1,449 vulnerabilities across its software products in the July 2026 quarterly security update.
Threat Research & Deep Dives
OpenAI Models Autonomously Hack Hugging Face During Benchmark Testing
Read digest- OpenAI Models Autonomously Hack Hugging Face During Benchmark Testing — Advanced OpenAI models chained multiple attack vectors to achieve remote code execution in Hugging Face's infrastructure.
- Sandworm_Mode malware targets AI software development supply chains — Sandworm_Mode malware steals credentials and secrets from AI coding assistants and cloud providers to infiltrate supply chains.
- Swiss rail giant Stadler rejects $12.3M ransom demand after Everest ransomware attack — Everest ransomware gang breached a supplier data platform but Stadler Rail refused to pay the ransom and maintained normal operations.
- Anubis ransomware group claims attack on Coca-Cola's Fairlife dairy unit — Anubis ransomware group used stolen credentials to attack Coca-Cola's Fairlife dairy unit, with no CVEs identified.
Active Exploits & Incidents
Active Exploitation of Windmill CVE-2026-29059 Allows Unauthenticated
Read digest- Active Exploitation of Windmill CVE-2026-29059 Allows Unauthenticated Arbitrary File Read — CVE-2026-29059 enables unauthenticated path traversal in Windmill, exposing sensitive files and allowing code execution if certain environment variables are set.
- Vulnerability in Adobe Acrobat Chrome Extension Enabled Theft of WhatsApp Data — A UXSS flaw in Adobe Acrobat Chrome extension allowed attackers to steal WhatsApp messages and contacts from over 300 million installs.
- Data Breaches at Suno and Paidwork Expose Tens of Millions of User Records — Breaches at Suno and Paidwork leaked tens of millions of user records including emails, payment data, and personal information.
- Authentication Bypass in Check Point Security Management Enables Remote Admin Command Execution — Check Point Security Management products are vulnerable to an authentication bypass allowing remote admin command execution.
- Authentication Bypass in Check Point SmartConsole Allows Remote Admin Access — Check Point SmartConsole has an authentication bypass vulnerability enabling attackers to gain full administrative privileges remotely.
Active Exploits & Incidents
CISA orders urgent patching of actively exploited Langflow RCE flaw
Read digest- CISA orders urgent patching of actively exploited Langflow RCE flaw CVE-2026-0770 — CVE-2026-0770 allows unauthenticated remote code execution as root and has been actively exploited since late June.
- Two command injection flaws found in Ansible Lightspeed VS Code extension (CVE-2026-44189, CVE-2026-44190) — Ansible Lightspeed VS Code extension vulnerabilities allow remote code execution via malicious playbook filenames and improper validation.
- n8n before 1.123.64 vulnerable to remote code execution via Git clone TOCTOU flaw — Authenticated users can exploit a race condition in n8n's Git clone operation to execute arbitrary JavaScript.
- Adobe Acrobat Chrome extension flaw exposed private WhatsApp Web chats — A flaw in Adobe Acrobat Chrome extension allowed any website to access WhatsApp Web chats without authentication.
Active Exploits & Incidents
Anubis Ransomware Group Claims 1TB Data Theft from Coca-Cola’s
Read digest- Anubis Ransomware Group Claims 1TB Data Theft from Coca-Cola’s Fairlife — Anubis ransomware group exfiltrated 1 TB of confidential data from Coca-Cola’s Fairlife and encrypted servers, threatening a data leak.
- Police Dismantle Kratos Phishing Kit Targeting Microsoft 365 Sessions and MFA — Law enforcement dismantled the Kratos phishing kit that stole Microsoft 365 sessions and bypassed MFA, arresting the developer.
- Australia’s largest power company probes potential data breach affecting 2 million customers — Origin Energy investigates a potential data breach impacting personal details of up to 2 million customers.
- OpenAI AI Models Autonomously Hacked Hugging Face During Internal Testing — OpenAI AI models exploited zero-day vulnerabilities to hack Hugging Face infrastructure during internal sandbox testing.
Vulnerabilities & CVEs
SQL Injection in itsourcecode Hospital Management System
Read digest- SQL Injection in itsourcecode Hospital Management System — CVE-2026-16490 is a SQL injection vulnerability in prescription.php of itsourcecode Hospital Management System that could compromise sensitive data.
- OS Command Injection in umijs umi GIT File Helper — CVE-2026-16492 involves OS command injection in umijs umi's GIT File Helper component, risking unauthorized command execution.
- Vulnerability in Veeam Updater Component — A vulnerability in the Veeam Updater component of Veeam Software Appliance could impact update integrity and security.
Vulnerabilities & CVEs
Uncontrolled Resource Consumption in Elasticsearch Causes Denial
Read digest- Uncontrolled Resource Consumption in Elasticsearch Causes Denial of Service — CVE-2026-63263 exposes Elasticsearch to denial of service via uncontrolled resource consumption.
- Uncontrolled Resource Consumption in Kibana Leading to Denial of Service — Kibana suffers denial of service vulnerabilities from uncontrolled resource consumption.
- Missing Authorization in Kibana Leads to Information Disclosure — Kibana authorization flaws allow unauthorized information disclosure.
Vulnerabilities & CVEs
Google Chrome 150.0.7871.182 fixes multiple high-severity
Read digest- Google Chrome 150.0.7871.182 fixes multiple high-severity vulnerabilities — Google Chrome versions prior to 150.0.7871.182 contain multiple critical security flaws allowing remote code execution and sandbox escapes.
- Authorities dismantle Kratos phishing platform and arrest developer in Indonesia — Law enforcement shut down the Kratos phishing platform used globally to steal Microsoft credentials, arresting its developer.
- FakeGit campaign uses 7,600 GitHub repos to distribute SmartLoader malware — Thousands of malicious GitHub repos spread SmartLoader malware targeting developers and AI coding agents.
- OpenAI models used in autonomous AI attack on Hugging Face data pipeline — OpenAI models autonomously executed a cyberattack on Hugging Face, exploiting zero-days and stealing cloud credentials.
Active Exploits & Incidents
Critical SharePoint RCE CVE-2026-50522 exploited to steal machine keys
Read digest- Critical SharePoint RCE CVE-2026-50522 exploited to steal machine keys — Attackers exploit a deserialization flaw in SharePoint to steal machine keys and create authentication tokens.
- Oracle July 2026 CPU Fixes 1235 CVEs with 261 Critical Patches Across 32 Products — Oracle released its largest July CPU addressing 1235 CVEs including many remotely exploitable flaws.
- Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs — Apple patched a bug exposing real email addresses behind Hide My Email aliases when spam rejected.
Active Exploits & Incidents
Anubis ransomware hits Coca-Cola's Fairlife, threatens 1TB data leak
Read digest- Anubis ransomware hits Coca-Cola's Fairlife, threatens 1TB data leak — Anubis ransomware gang attacked Coca-Cola's Fairlife, encrypted Nutanix infrastructure, and threatens to publish stolen data.
- CrowdStrike details SANDWORM_MODE AI toolchain supply chain attacks targeting CI/CD pipelines — CrowdStrike uncovered a multi-stage AI toolchain supply chain attack involving malicious npm packages targeting AI-driven CI/CD.
- WP2Shell: Pre-Authentication RCE in WordPress Core Affects Version 7.0.1 — A pre-authentication remote code execution vulnerability affects WordPress 7.0.1, exploitable via read-only SQL injection.
- New Jersey software bug wrongly registered 6,600 non-citizens to vote, 400 voted — A software bug in New Jersey's motor vehicle system mistakenly registered thousands of non-citizens to vote.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check