Security Intel Feed
Cyber Hose
Page 43 of 52
Vendor Bulletins & Advisories
White House Launches AI-Driven Gold Eagle Initiative for Cyber
Read digest- White House Launches AI-Driven Gold Eagle Initiative for Cyber Vulnerability Coordination — The initiative centralizes and accelerates vulnerability coordination across critical infrastructure, government agencies, and private sector partners using advanced AI.
Vulnerabilities & CVEs
New wp2shell WordPress Core RCE Flaw
Read digest- New wp2shell WordPress Core RCE Flaw — Critical unauthenticated remote code execution in WordPress core affects versions 6.9 and 7.0 prior to 6.9.5/7.0.2 and requires immediate patching.
- Inc Ransomware Exploits SonicWall SMA Zero-Days — New ransomware campaign chains two SonicWall SMA zero-days to gain root access on mobile access appliances.
- Abbott Laboratories Investigates Two Cyber Incidents Amid Extortion Claims — Abbott Labs confirms unauthorized access and data theft in legacy systems and LabCentral portal with extortion threats.
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT — Checkmarx researchers uncovered a supply chain attack using blockchain-based command-and-control infrastructure.
Vulnerabilities & CVEs
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
Read digest- Fresh SharePoint Vulnerability Exploited Soon After Disclosure — Critical RCE CVE-2026-58644 in Microsoft SharePoint Server is actively exploited and requires urgent patching.
- Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei — Nichirei halted systems due to a cyberattack and is restoring operations amid a wave of sector attacks.
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files — ACR Stealer continues to exfiltrate browser passwords and Microsoft 365 files via command execution.
- New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage — Kaspersky discovered GoSerpent espionage malware targeting Southeast Asian government and diplomatic entities.
Active Exploits & Incidents
No relevant cyber threat items detected in this update
Read digest- No relevant cyber threat items detected in this update — No new cyber threat intelligence items were identified in this update across 63 monitored sources.
Vulnerabilities & CVEs
h2o HTTP/2 State Amplification Vulnerability CVE-2026-54340
Read digest- h2o HTTP/2 State Amplification Vulnerability CVE-2026-54340 — CVE-2026-54340 combines HPACK decompression amplification with Slowloris-style vectors to enable amplified DoS attacks on h2o HTTP server.
- h2o musl libc Stack Overflow CVE-2026-44453 — A stack overflow triggered by alloca calls in h2o HTTP server can cause denial of service in affected versions.
- h2o Heap Overrun Vulnerability CVE-2026-44452 — A heap overrun triggered by zero-length SNI extension in h2o HTTP server may lead to crashes or code execution.
- AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report — Unit 42 analyzes AI-driven attack automation and incident response trends observed in 2026, providing key insights for SOC teams.
Vulnerabilities & CVEs
Multiple DoS Vulnerabilities in Quicly Affecting HTTP/3 Servers
Read digest- Multiple DoS Vulnerabilities in Quicly Affecting HTTP/3 Servers — Quicly, used in HTTP/3 servers, suffers multiple denial-of-service flaws causing connection corruption and exhaustion.
- Jupyter Enterprise Gateway Kubernetes Manifest Injection — Untrusted input in Jinja2 templates enables Kubernetes manifest injection and potential remote code execution.
- Agentic AI Is Untamable: Ask the Right Security Questions — Emerging agentic AI systems introduce novel security risks requiring new organizational security strategies.
Active Exploits & Incidents
Coca-Cola Fairlife Subsidiary Hit by Ransomware
Read digest- Coca-Cola Fairlife Subsidiary Hit by Ransomware — A ransomware attack has disrupted production at Coca-Cola’s Fairlife dairy operations across the US, causing temporary suspension of product manufacturing.
- ClickLock macOS Malware Forces Password Disclosure — New macOS malware kills visible processes to coerce users into re-entering passwords, enabling credential theft.
- CVE-2026-53410: Zoom Clients for Windows TOCTOU Race Condition — A TOCTOU race condition in Zoom Clients on Windows allows local users to escalate privileges; patching is advised.
- Anubis Ransomware: Emerging RaaS Threat Targeting Healthcare — Anubis ransomware-as-a-service campaigns target healthcare with new tactics, increasing operational impact.
Active Exploits & Incidents
Millions of Shark Vacuums Vulnerable to Remote Code Execution
Read digest- No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE — Millions of Shark robotic vacuums contain remote code execution vulnerabilities, exposing IoT devices to full compromise.
- HelloNet campaign — new malicious modules launched through the ViPNet update system — Targeted attacks against large Russian organizations use the ViPNet update mechanism to deploy malicious modules.
- VU#326070: SGLang Pickle Deserialization RCE (CVE-2026-14890) — SGLang framework has a critical pickle deserialization flaw enabling remote code execution with no patch yet.
- Google IdP Universal Account Takeover via Device Code Flow Hijacking — Google’s device authorization grant is vulnerable to a confused deputy attack enabling invisible account takeovers.
Active Exploits & Incidents
Massive Supply Chain Attack Hits Nichirei Logistics, Japan
Read digest- Massive Supply Chain Attack Hits Nichirei Logistics, Japan — A cyberattack on Nichirei has escalated into a widespread supply chain incident impacting grocery stores nationwide.
- Scattered Spider TfL Hackers Sentenced to 5.5 Years — UK’s National Crime Agency sentenced members of Scattered Spider for the largest UK cybercrime against Transport for London.
- HCL DFXServer Broken Authentication (CVE-2026-35147) — Critical broken authentication flaw allows attackers to bypass user verification on specific HCL DFXServer API endpoints.
- ASUS bsitf.sys Arbitrary Physical Memory Mapping 0-day (CVE-2026-13585) — Public PoC released for a zero-day allowing privilege escalation on affected ASUS devices via physical memory mapping.
Active Exploits & Incidents
CISA orders feds to patch actively exploited Oracle flaw by Saturday
Read digest- CISA orders feds to patch actively exploited Oracle flaw by Saturday — CISA mandates federal agencies patch a critical Oracle E-Business Suite vulnerability actively exploited in the wild.
- Russian hackers trojanize WebEx, Zoom apps to push Starland malware — Russian threat actor UAT-11795 deploys Starland RAT via trojanized collaboration apps to steal credentials and cryptocurrency.
- New Spirals ransomware encrypts victim network in under 24 hours — Spirals ransomware group completes full network encryption in less than 24 hours, highlighting urgent detection needs.
- Spring Security Authorization Server Dynamic Client Registration endpoints privilege bypass (CVE-2026-22752) — Critical authentication bypass affects Spring Authorization Server versions 7.0.0 through 7.0.4 and 1.5.0+, risking identity compromise.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check