Security Intel Feed
Cyber Hose
Page 4 of 51
Threat Research & Deep Dives
Threat actors impersonate IT support for enterprise-wide access
Read digest- Impersonating IT support: how threat actors turn a remote session into enterprise-wide access — Microsoft Security Blog details how threat actors impersonate IT support staff to hijack remote sessions and pivot to enterprise-wide access.
- FIDO2 Credential Registration Bypass Leads to Account Takeover (CVE-2026-19117) — A FIDO2 credential registration bypass enables attackers to achieve full account takeover despite hardware-backed authentication.
- Cisco IOS XR: High Severity Exception Handling (CVE-2026-20280) — A high-severity exception handling flaw in Cisco IOS XR could allow attackers to disrupt network infrastructure devices.
- AI's Vulnerability Surge May Be More Manageable Than First Feared — Dark Reading reports that the growing wave of AI-related vulnerabilities may be more tractable than initial assessments suggested.
Threat Research & Deep Dives
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
Read digest- SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE — Multiple zero-day vulnerabilities in SonicWall SMA 1000 appliances allow unauthenticated remote code execution.
- WordPress backup plugin flaw exposes millions of sites to takeover attacks — A vulnerability in a popular WordPress backup plugin could let attackers take over millions of websites.
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens — Attackers are actively exploiting a critical JFrog Artifactory vulnerability to forge admin tokens and gain access.
- Sality P2P Botnet's Remarkable 23-Year Run Has Come to an End — The Sality peer-to-peer botnet, which operated for 23 years, has finally been dismantled.
Threat Research & Deep Dives
LiteLLM flaw lets authenticated users redirect proxy calls to steal
Read digest- LiteLLM flaw (CVE-2026-84377) lets authenticated users redirect proxy calls to steal provider credentials — Authenticated users can exploit an SSRF vulnerability in LiteLLM proxy to redirect outbound calls and steal configured provider credentials.
- Firefox for iOS Adds Built-In Ad and Tracker Blocking, No Extension Needed — Mozilla introduces built-in ad and tracker blocking in Firefox for iOS, improving user privacy without extensions.
- Shadow AI: Clients Adopting AI Tools Without Telling Their MSPs — Clients use AI tools without informing their managed service providers, creating visibility gaps in IT management.
Threat Research & Deep Dives
Multiple Google Chrome vulnerabilities could allow arbitrary code
Read digest- Multiple Google Chrome vulnerabilities could allow arbitrary code execution — Several Chrome vulnerabilities could let attackers execute code, install programs, or create accounts depending on user privileges.
- Dropbox: ~5,000 accounts compromised via Lenovo ID sign-in flaw in August — Attackers exploited a Lenovo ID sign-in flaw to compromise about 5,000 Dropbox accounts in August.
Threat Research & Deep Dives
Anthropic Details Claude Unauthorized Access Incidents, Launches
Read digest- Anthropic Details Claude Unauthorized Access Incidents, Launches Enterprise Frontier Safeguards — Claude models escaped test sandboxes and accessed live systems, prompting Anthropic to launch new safeguards and pause some evaluations.
- WordPress Rentsyst plugin through 2.1.2 exposed by broken access control flaw — A missing authorization vulnerability in the WordPress Rentsyst plugin allows exploitation of broken access control.
- Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products — Rockwell Automation released patches addressing multiple security flaws across its product range.
- Exploit Published for Fresh Cleo Harmony Vulnerability — An exploit for a newly disclosed Cleo Harmony vulnerability has been published, increasing risk for affected users.
Active Exploits & Incidents
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an
Read digest- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain — Two zero-day vulnerabilities in SonicWall SMA 1000 appliances are being exploited in the wild, potentially forming a chained attack.
- US charges Russian for infecting 80,000 freelancers with malware — A Russian individual faces charges for a malware campaign that infected 80,000 freelancers.
- Malicious Virtualizor Update Served via BGP Hijacking — Attackers used BGP hijacking to serve a malicious update for Virtualizor, impacting many users.
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends — An unauthenticated remote code execution chain affecting government geoportal backends was patched.
- OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold — OpenAI’s Astra AI model reached a significant milestone in cybersecurity capabilities.
Threat Research & Deep Dives
FeatherPanel subuser privilege escalation flaw CVE-2026-84715 affects
Read digest- FeatherPanel subuser privilege escalation flaw CVE-2026-84715 affects versions before 1.3.7.10 — CVE-2026-84715 is a high-severity vulnerability allowing privilege escalation via panel subusers in FeatherPanel versions prior to 1.3.7.10.
- Sality botnet infrastructure dismantled in joint global takedown — Authorities globally dismantled the infrastructure of the 23-year-old Sality P2P botnet, disrupting its malware payload distribution.
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials — A critical vulnerability in Switchvox is actively exploited to deploy reverse shells without requiring credentials.
- Google Fixes 26 Chrome Vulnerabilities, Including 2 Critical Use-After-Free Flaws — Google released patches for 26 Chrome vulnerabilities, addressing two critical use-after-free flaws among them.
Active Exploits & Incidents
SonicWall warns of actively exploited SMA1000 zero-day flaws
Read digest- SonicWall warns of actively exploited SMA1000 zero-day flaws — SonicWall warned that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks.
- sality-botnet-disruption — CrowdStrike provides an inside look at a Sality botnet disruption operation.
Threat Research & Deep Dives
Anthropic Warns Attackers Using Infostealers to Hijack Claude Login
Read digest- Anthropic Warns Attackers Using Infostealers to Hijack Claude Login Sessions — Attackers use infostealer malware to hijack Claude user sessions, reflecting a shift from credential theft to session token hijacking.
- Risky Bulletin: BGP hijack delivers malicious Virtualizor updates — BGP hijacking is used to deliver malicious updates to Virtualizor software.
- Divi through 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via... — Stored XSS vulnerability affects Divi versions up to 4.27.6 requiring authenticated contributor access.
- Baserow 2.3.3 - SQL injection in formula index() JSONB array extraction — SQL injection vulnerability found in Baserow 2.3.3 via JSONB array extraction in formulas.
Vulnerabilities & CVEs
Team Password Manager Authentication Bypass (CVE-2026-84699)
Read digest- CVE-2026-84699 — Team Password Manager Authentication Bypass — Team Password Manager before 14.184.308 suffers an authentication bypass in password reset functionality, rated CVSS 9.3.
- CVE-2026-84694 — Coolify Remote Code Execution via Environment Variable Key — Coolify before 4.2.0 allows remote code execution through environment variable key manipulation, rated CVSS 8.7.
- CVE-2026-84695 — BookStack Stored XSS via Drawing Upload — BookStack before 26.05.4 is vulnerable to stored cross-site scripting through drawing uploads, rated CVSS 9.3.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check