Security Intel Feed
Cyber Hose
Page 41 of 52
Active Exploits & Incidents
Ernst & Young Data Breach Exposes Personal and Financial Client
Read digest- Ernst & Young Data Breach Exposes Personal and Financial Client Information — A breach of a third-party IT support platform led to exposure of sensitive client data including SSNs and tax documents.
- OpenSSL silently fixes HollowByte DoS vulnerability causing memory exhaustion — OpenSSL patched a denial-of-service flaw that exhausts server memory via crafted handshake payloads.
- CVE-2026-14440: Cloudflare’s CAA flaw looks impractical for criminals — Cloudflare's CAA vulnerability has limited exploitability but could be risky if attackers control the network.
Active Exploits & Incidents
WP2Shell WordPress Vulnerabilities CVE-2026-60137 and CVE-2026-63030
Read digest- WP2Shell WordPress Vulnerabilities CVE-2026-60137 and CVE-2026-63030 Exploited in the Wild — Two critical WordPress vulnerabilities allow unauthenticated attackers to chain exploits and fully control sites.
- Critical ServiceNow CVE-2026-6875 code execution flaw now actively exploited — A critical remote code execution flaw in ServiceNow AI Platform is being exploited days after patch release.
- Hugging Face Breached in Autonomous AI-Driven Attack on Production Infrastructure — Hugging Face suffered a breach from an autonomous AI attack targeting internal datasets and credentials.
- Korean National Diplomatic Academy Hacked for 10 Months — The National Diplomatic Academy in Korea was compromised and accessed for about 10 months.
Active Exploits & Incidents
Exploit brokers pay $500,000 for a WordPress RCE found using GPT5.6 AI
Read digest- Exploit brokers pay $500,000 for a WordPress RCE found using GPT5.6 AI — Exploit brokers are paying $500,000 for a zero-day WordPress RCE discovered using GPT5.6 AI with pre-auth remote code execution.
- Google Chrome 150 Update Fixes Seven Critical Memory Safety Vulnerabilities — Google patched seven critical and high-severity memory safety bugs in Chrome 150 across multiple platforms.
Active Exploits & Incidents
WP2Shell WordPress Vulnerabilities CVE-2026-60137 and CVE-2026-63030
Read digest- WP2Shell WordPress Vulnerabilities CVE-2026-60137 and CVE-2026-63030 Exploited in the Wild — Attackers exploit two critical WordPress flaws allowing unauthenticated remote code execution on stock installs.
- Hugging Face Breached by Autonomous AI Agent Exploiting Code Execution Flaws — An autonomous AI agent exploited code execution vulnerabilities to breach Hugging Face's infrastructure and steal credentials.
- SleeperGem Supply Chain Attack Uses Malicious RubyGems to Target Developers — Malicious RubyGems packages infected developer machines to establish persistence and attempt privilege escalation.
- Hacker wipes entire Romanian land registry database — A hacker erased Romania's entire land registry database with no disclosed attack details.
Threat Research & Deep Dives
FLINT fingerprints federated learning models via 5G PHY-layer side
Read digest- FLINT fingerprints federated learning models via 5G PHY-layer side channels — FLINT exploits 5G physical layer metadata to classify federated learning model architectures with high accuracy.
- KASS framework enables executable attack synthesis and simulation for smart contracts — KASS generates and simulates executable smart contract exploits, validating 9 of 11 real-world CVEs.
- Researchers demonstrate natural backdoor attacks on speech recognition models — Natural sounds can stealthily trigger backdoor attacks on speech recognition models with near 100% success.
Threat Research & Deep Dives
Critical WordPress Core RCE Vulnerabilities CVE-2026-63030
Read digest- Critical WordPress Core RCE Vulnerabilities CVE-2026-63030 and CVE-2026-60137 Disclosed — Two unauthenticated WordPress core vulnerabilities enable remote code execution and rogue admin access on default installs.
- Meshtastic GitHub repo vulnerable to arbitrary code execution via pull_request_target — Meshtastic's CI workflow flaw allows attacker code execution with repository secrets and elevated tokens.
Threat Research & Deep Dives
Critical NGINX Heap Buffer Overflow CVE-2026-42533 Enables RCE
Read digest- Critical NGINX Heap Buffer Overflow Vulnerability CVE-2026-42533 Allows Remote Code Execution — A heap overflow in NGINX core and related products can cause crashes and remote code execution under certain conditions.
Vulnerabilities & CVEs
Unsafe Deserialization Vulnerability in Keras TorchModuleWrapper
Read digest- Unsafe Deserialization Vulnerability in Keras TorchModuleWrapper — CVE-2026-12484 is a CVSS 7.8 unsafe deserialization flaw in keras.layers.TorchModuleWrapper.from_config that could allow remote code execution.
Active Exploits & Incidents
Hackers abuse ViPNet update mechanism to target Russian government
Read digest- Hackers abuse ViPNet update mechanism to target Russian government agencies — Attackers use ViPNet's legitimate update process to sideload malware targeting Russian government and critical infrastructure.
- Hikvision cameras targeted by scans probing Intelligent Security API endpoints — Scans probe Hikvision cameras' ISAPI endpoints to identify devices for potential brute force attacks.
Active Exploits & Incidents
SonicWall SMA 1000 VPN Zero-Days Exploited Pre-Disclosure for Root
Read digest- SonicWall SMA 1000 VPN Zero-Days Exploited Pre-Disclosure for Root Access — Threat actors exploited two zero-day vulnerabilities in SonicWall SMA 1000 VPN appliances to gain root access before patches were available.
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware — Russian group UAC-0145 delivers malware to Ukrainian users via fake CAPTCHA prompts on compromised websites.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check