Security Intel Feed
Cyber Hose
Page 45 of 52
Active Exploits & Incidents
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical
Read digest- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws — See source for details.
- Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius — See source for details.
- Tracking Peter Stokes (Scattered Spider) and The Com: Insights from Allison Nixon — See source for details.
- Smash and Grab at Scale: Agentic AI Is Reshaping the Threat to Commerce — See source for details.
- CVE-2026-46459: Missing Authorization in ICU Scandinavia Boomerang — See source for details.
Active Exploits & Incidents
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch
Read digest- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday — A new PoC exploit named LegacyHive targets a Windows User Profile Service (ProfSvc) arbitrary hive load elevation of privilege vulnerability. This zero-day allows attackers to escalate privileges by loading malicious user profile hives. Immediate patching and monitoring for exploit attempts are critical.
- Windows Bind Link Attacks Can Hide Malware From EDR Tools — Bitdefender researchers reveal a novel technique abusing Windows bind links to create conflicting filesystem views, effectively hiding malware from endpoint detection and response (EDR) tools. This evasion tactic complicates detection and requires updated EDR heuristics and monitoring for suspicious bind link activity.
- SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. — Traditional SASE inspection models fail to address risks introduced by AI-driven workflows, unsanctioned browser extensions, and autonomous agents operating in SaaS and browser environments. Security teams must evolve beyond packet inspection to include behavioral and AI-contextual analysis to prevent data exfiltration and IP leakage.
- PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery — PraisonAI’s plugin manager loads and executes arbitrary Python files from project and user directories without validation, enabling remote code execution. Upgrade to 1.6.78 or later to mitigate.
- US Court Denies Warrant for Mass Phone Snooping Using Stingray — A recent U.S. court ruling rejected a government warrant that sought to use a cell-site simulator ("stingray") to collect data on thousands of uninvolved Ohio residents. This sets a precedent limiting bulk surveillance via IMSI catchers and highlights ongoing privacy and legal challenges in law enforcement surveillance technology.
Active Exploits & Incidents
Two Men Indicted for ATM Jackpotting Scheme in Nevada
Read digest- Two Men Indicted for ATM Jackpotting Scheme in Nevada — A federal grand jury indicted two individuals for orchestrating a jackpotting scheme targeting multiple ATMs in Reno and Sparks, Nevada. The attack involved physical compromise of ATM hardware to steal cash, highlighting ongoing risks to financial infrastructure from hardware-level attacks.
- US Air Force Cybersecurity Lockouts Disrupt Operations — Rolling cybersecurity quarantines have locked out numerous Air Force personnel and civilians from their systems for days, indicating a significant internal incident or aggressive containment measures. This disruption underscores potential operational impacts from defensive cyber controls or ongoing incident response.
- Critical ServiceNow AI Platform RCE Patched Alongside Fortinet & Ivanti Fixes — ServiceNow patched a critical remote code execution vulnerability in its AI platform that could allow remote attackers to execute arbitrary code. Fortinet and Ivanti also released important security updates. Immediate patching is advised to mitigate potential exploitation.
- CVE-2026-40633: Sensitive Information Insertion into Logs in Dell PowerScale OneFS (9.5.0.0 - 9.13.0.2) — Dell PowerScale OneFS contains a vulnerability where low-privileged attackers can insert sensitive information into log files, potentially leading to information leakage or log poisoning. Affected versions span 9.5.0.0 through 9.13.0.2. Patch or mitigate accordingly.
- CVE-2026-49501: Improper Privilege Management in Dell PowerScale OneFS (9.5.0.0 - 9.13.0.2) — An improper privilege management vulnerability in Dell PowerScale OneFS allows high-privileged local attackers to escalate privileges or perform unauthorized actions. Versions 9.5.0.0 through 9.13.0.2 are affected. Immediate patching is critical.
Active Exploits & Incidents
Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code
Read digest- Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution — A critical flaw in Cursor on Windows allows automatic execution of a malicious git.exe binary placed in a project root without user interaction or warnings. This enables attackers to execute arbitrary code with the user’s privileges, accessing source code, SSH keys, and cloud tokens persistently while the project remains open. Immediate review of Cursor usage and environment hygiene is advised.
- KFC Faces Possible Closures After Cyberattack on Japan's Nichirei — A cyberattack on Nichirei, a major Japanese food supplier, is causing operational disruptions impacting KFC outlets in Japan. This incident highlights risks in food supply chain cybersecurity and potential cascading effects on retail operations. Monitoring for further details and supply chain risk mitigation is recommended.
- TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development — Unit 42 analyzed TuxBot v3, an IoT botnet framework developed with large language model (LLM) assistance. The report details its cross-compiled binaries, command-and-control architecture, and embedded bugs, revealing how AI is accelerating malware sophistication in IoT environments. This signals a new wave of AI-augmented malware development requiring updated detection strategies.
- OkoBot: New Sophisticated Malware Framework Targets Cryptocurrency Users — Kaspersky GReAT uncovered OkoBot, a complex malware framework targeting crypto users by stealing seed phrases and monitoring Chromium-based browsers. It deploys multiple payloads including the Rilide stealer and TookPS backdoor, indicating a multi-stage infection chain designed for persistent crypto asset theft. Crypto custodians and wallet providers should prioritize detection and mitigation of these tactics.
- White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative — Following the June 2 AI-focused Executive Order, the White House introduced the Gold Eagle program to leverage AI for faster vulnerability coordination across government and private sectors. This initiative aims to accelerate patch deployment and threat intelligence sharing, signaling increased federal emphasis on AI-powered vulnerability management. Security teams should watch for integration opportunities and compliance impacts.
Active Exploits & Incidents
CISA warns admins to patch actively exploited SharePoint flaws
Read digest- CISA warns admins to patch actively exploited SharePoint flaws — CISA alerts that threat actors are actively exploiting three critical vulnerabilities in Internet-exposed on-premises SharePoint Server instances. Immediate patching is strongly advised to prevent unauthorized access and data compromise.
- Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption — Progress has confirmed a zero-day exploited in the wild that caused outages in ShareFile Storage Zones Controller. A patch is now available and customers are urged to apply it immediately to restore service and block ongoing attacks.
- Joomla Extension 4Analytics - Unauthenticated Stored XSS (CVE-2026-58077) — An unauthenticated stored XSS vulnerability in 4Analytics <5 could allow website takeover via specially crafted requests. Exploitation risk is high due to lack of authentication requirements.
- Joomla Extension 4Analytics - Unauthenticated Stored XSS in AI Analysis Feature (CVE-2026-57833) — Another unauthenticated stored XSS affecting the AI analysis feature of 4Analytics <5. This vulnerability enables remote code injection vectors without user authentication, increasing risk of site compromise.
- ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell — Siemens, Schneider Electric, and Rockwell Automation released patches addressing dozens of vulnerabilities in ICS products. CISA and VDE CERT also issued advisories; immediate review and patching recommended for critical infrastructure operators.
Vendor Bulletins & Advisories
Microsoft: Some Dell PCs shut down after recent Windows updates
Read digest- Microsoft: Some Dell PCs shut down after recent Windows updates — Microsoft is blocking this month’s Windows 11 security updates on select Dell devices due to shutdowns and performance degradation. Organizations with Dell hardware should delay applying these updates until a fix is released to avoid operational disruptions.
- Joomla Extension EDocman Unauthenticated Blind SQL Injection (CVE-2026-57832) — An unauthenticated blind SQL injection vulnerability affects the Joomla EDocman extension, enabling remote attackers to extract sensitive database information without credentials. Immediate patching or mitigation is advised to prevent data leakage.
- Joomla Extension DP Calendar Unauthenticated Blind SQL Injection (CVE-2026-57831) — Similar to EDocman, the DP Calendar Joomla extension suffers from an unauthenticated blind SQL injection vulnerability. This flaw allows attackers to perform database reconnaissance and potentially escalate attacks. Update or disable the extension until patched.
- (More) Unauthenticated Arbitrary Code Execution in ServiceNow — New reports detail unauthenticated arbitrary code execution vulnerabilities in ServiceNow instances, posing critical risks for remote compromise. Organizations using ServiceNow should urgently review vendor advisories and apply mitigations or patches.
- The Memory Heist – How I tricked Claude into leaking your deepest, darkest secrets — A technical deep dive reveals novel prompt injection techniques to exfiltrate sensitive data from AI language models like Claude. This research highlights emerging risks in AI-assisted environments and the need for hardened input validation and monitoring.
Active Exploits & Incidents
US charges alleged operators of Russian bulletproof hosting service
Read digest- US charges alleged operators of Russian bulletproof hosting service — U.S. prosecutors charged three Russian nationals running a bulletproof hosting (BPH) service that supported ransomware gangs responsible for over $62M in global damages. This takedown disrupts a critical infrastructure node enabling ransomware operations.
- CVE-2026-15583: SSRF (confused deputy) in Grafana MCP Server — Unauthenticated remote attackers can exploit a confused-deputy SSRF flaw via the X-Grafana-URL header to exfiltrate environment-configured Grafana service-account tokens. This allows potential privilege escalation and lateral movement in compromised environments. Patch or mitigate immediately.
- CVE-2026-15804: SQL Injection in MetaGuru HCM — Authenticated remote attackers can inject SQL commands through specific parameters, risking data confidentiality and integrity. Affects MetaGuru’s Human Capital Management software. Prioritize patching and review database access controls.
- CVE-2026-14251: Missing allowednamespace check in OpenShift GitOps operator — Namespace-scoped Argo CD instances can trigger unauthorized reconciliation of ClusterRole objects due to lack of ownership validation, enabling privilege escalation within Kubernetes clusters. Critical for organizations using OpenShift GitOps to apply fixes or implement compensating controls.
- Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates — Google Chrome 150 and Firefox 152 address multiple critical vulnerabilities, including publicly available exploit code for Firefox flaws (no in-the-wild exploitation reported yet). Immediate patching recommended to close attack vectors.
Active Exploits & Incidents
Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin
Read digest- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands — SonicWall warns of active exploitation targeting SMA 1000 series appliances via two zero-days, including CVE-2026-15409 (CVSS 10.0), a critical SSRF vulnerability enabling remote unauthenticated attackers to execute arbitrary commands. Immediate patching or mitigation is critical to prevent full system compromise.
Active Exploits & Incidents
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
Read digest- SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits — SonicWall SMA1000 appliances are targeted by two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, both enabling remote code execution. These flaws are actively exploited in the wild, demanding immediate patching to prevent compromise of network security gateways.
- July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days — Microsoft released patches addressing 622 vulnerabilities this cycle, including two zero-days currently exploited in the wild. Organizations should prioritize deploying these updates to mitigate active threats impacting Windows and related products.
- CVE-2026-42936: HYPER SBI 2 Installer DLL Hijacking — The HYPER SBI 2 installer insecurely loads DLLs from its execution directory, allowing crafted DLLs to execute arbitrary code during installation. This vulnerability poses a high risk for local privilege escalation or initial compromise if exploited.
Vulnerabilities & CVEs
Microsoft July 2026 Patch Tuesday fixes 569 CVEs including 3 zero-days
Read digest- Microsoft July 2026 Patch Tuesday - 569 CVEs, 56 Critical, 3 Zero-Days — Largest Patch Tuesday ever with 569 CVEs fixed, including 3 zero-days (2 exploited in the wild). Critical patches affect many core Microsoft components.
- CVE-2026-13385 - ASUS Router Improper Validation & Certificate Issues — Remote MITM exploit allows attackers to force vulnerable ASUS routers to download and execute malicious firmware due to improper integrity checks.
- CVE-2026-15029 - ASUS System Control Interface Untrusted Pointer Dereference — Local admin privilege escalation via arbitrary physical memory read on ASUS System Control Interface v3 and Business Manager.
- "Trust but Verify? Security Debt of Autonomous Coding Agents" — Study finds 38.9% of LLM-generated PRs contain security misconfigurations and code smells, highlighting risks of unchecked autonomous code generation.
- DShield SIEM Update: ELK Stack 8.19.15 with New Dashboards & Logs — Updated DShield SIEM now includes enhanced dashboards and new log sources to improve threat visibility for SOC teams.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check