Security Intel Feed
Cyber Hose
Page 46 of 52
Vulnerabilities & CVEs
CVE-2026-13385 - ASUS Router Improper Validation & Certificate Issues
Read digest- CVE-2026-13385 - ASUS Router Improper Validation & Certificate Issues — Remote MITM attackers can force vulnerable ASUS routers to download and execute malicious payloads due to improper integrity check and certificate validation. Immediate patching or network segmentation advised.
- CVE-2026-15029 - ASUS System Control Interface Untrusted Pointer Dereference — Local admin privilege required; allows arbitrary physical memory read/write, risking system compromise on ASUS devices running System Control Interface v3 and Business Manager. Monitor for privilege escalation attempts.
- CVE-2026-15030 - ASUS System Control Interface Out-of-Bounds Read — Local admin can read beyond intended memory boundaries, exposing sensitive firmware data. Patch ASUS affected components promptly.
- CVE-2026-13585 - ASUS System Control Interface Resource Allocation & Info Leak — Local attacker can exhaust resources without throttling and leak sensitive info due to improper cleanup in ASUS System Control Interface driver and Business Manager. Risk of DoS and data leakage.
- CVE-2026-8920 - Aura Wallpaper Service Improper Channel Restriction & File Path Control — Local user can perform unauthorized file operations via crafted IPC messages, enabling potential privilege escalation or data tampering. Patch or restrict access to Aura Wallpaper Service.
Threat Research & Deep Dives
Cross-Cutting Security Analysis of LLM-Generated Code via Metamorphic
Read digest- Cross-Cutting Security Analysis of LLM-Generated Code via Metamorphic Testing and Association Rule Mining — A new framework combining metamorphic testing and association rule mining detects security vulnerabilities in LLM-generated code across multiple CWE categories (SQLi, XSS, command injection, path traversal, hard-coded creds, weak crypto, memory errors). Analysis of 3,700 code snippets reveals co-occurring weaknesses linked to prompt-level risk factors, highlighting systemic risks in AI-assisted coding.
- Antiproof: Synthesizing Vulnerability Detectors and Proofs of Exploitability — Antiproof introduces a neuro-symbolic system that synthesizes static vulnerability detectors with executable proof-of-exploit oracles, achieving 97% recall on benchmark datasets and improving detection recall by over 60 points compared to prior methods. This approach enables scalable, validated vulnerability discovery with automatic exploit confirmation.
- Trust but Verify? Uncovering the Security Debt of Autonomous Coding Agents — A large-scale study of 16,112 file changes from 4,022 autonomous agent-generated PRs reveals 38.9% contain security misconfigurations and code smells, exposing significant security debt in AI-driven software development. The work uses an LLM-based judge plus manual review to classify risks, underscoring urgent need for security controls in autonomous coding workflows.
- On the Security Implications of PQC in TLS: Handshake Exhaustion and IDS Degradation — Empirical testing shows PQC-enabled TLS 1.3 servers suffer prolonged high CPU load under handshake exhaustion DDoS attacks, exacerbating denial-of-service impact. The increased handshake complexity also degrades IDS detection efficacy, raising concerns about operational security trade-offs in early PQC deployment.
- When Binaries Talk Back: Representation-Confusion Attacks on LLM-Assisted Reverse Engineering — This study identifies Representation-Confusion Attacks (RARE) where attacker-crafted binaries manipulate LLM-assisted reverse engineering pipelines by misrepresenting data as instructions or evidence, causing false trust in analysis outputs. The paper introduces RARE-Bench and RARE-Guard, revealing new attack vectors against AI-powered RE tools.
Active Exploits & Incidents
CyberPulse Digest — July 15, 2026
Read digestSonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exp...
Active Exploits & Incidents
Progress confirms ShareFile zero-day behind Storage Zone shutdown
Read digest- Progress confirms ShareFile zero-day behind Storage Zone shutdown — A high-severity zero-day exploited in the wild forced the emergency shutdown of ShareFile Storage Zone Controllers; security updates are out and immediate patching is critical.
- Seven severe VMware Avi Load Balancer vulnerabilities patched — The flaws enable authentication bypass, RCE, privilege escalation and directory traversal; patch to prevent lateral movement and takeover.
- ClickFix attack ecosystem expands, evading AV/EDR — The attack vector is now available for rent at scale and bypasses traditional defenses; YARA rules are currently the best detection method.
- AWS WAF Bot Control learns to authenticate legitimate AI agent traffic — The new capability distinguishes legitimate AI-driven bot traffic from malicious actors in multi-tenant environments.
- Cursor code editor executes local git.exe files blindly — The editor runs git.exe binaries found inside source repos, a supply-chain risk for developer environments.
Active Exploits & Incidents
SureForms flaw lets attackers rewrite payment amounts on WordPress
Read digest- SureForms unauthenticated payment amount bypass — CVE-2026-11567 in the WordPress form plugin lets attackers manipulate payment amounts on forms without authentication — critical for ecommerce sites.
- WP 2FA account takeover via 2FA setup email binding — CVE-2026-12988 allows attackers with partial access to hijack accounts by binding two-factor authentication to an attacker-controlled email.
- AI Security Report 2026: from attack assistant to autonomous operator — Check Point documents AI's evolution toward fully automated cyberattacks and the new TTPs accelerating threat actor capability.
- Keras path traversal via symlink validation bypass — CVE-2026-12482 lets malicious tar archives bypass safe-extraction checks in the widely used ML framework, risking arbitrary file writes.
- Distributed Denial of Science: indirect data poisoning of AI systems — Researchers warn that poisoning public datasets can make autonomous AI research agents unknowingly propagate scientific fraud at scale.
Active Exploits & Incidents
Cisco Catalyst SD-WAN vulnerabilities under active exploitation
Read digest- Cisco SD-WAN exploitation — Critical authentication bypass flaws in Cisco Catalyst SD-WAN Controller and Manager (CVE-2026-20182) are under active exploitation by threat actors including UAT-8616; CISA mandates immediate remediation.
- Dirty Frag Linux LPE — Public exploit code is available for a chained Linux kernel privilege escalation (CVE-2026-43284, CVE-2026-43500) affecting multiple distros; patches are pending but expected imminently.
- a 9.8 Drupal SQLi — An unauthenticated, remotely exploitable SQL injection in Drupal's database abstraction layer (CVE-2026-9082, CVSS 9.8) affects PostgreSQL sites; patches are out across six supported branches.
- a record Patch Tuesday — Microsoft's June 2026 Patch Tuesday shipped 198 CVEs, 32 critical and 3 actively exploited zero-days — the largest release to date.
- npm/PyPI supply-chain worms — The Mini Shai-Hulud campaign compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations to steal developer and cloud credentials.
Active Exploits & Incidents
Accenture confirms breach after hacker claims source code theft
Read digest- Accenture confirms data breach after hacker claims source code theft — The consultancy confirms theft of source code and encryption keys; it says the incident is contained, but client confidentiality and IP risk remain.
- Adalo database API enables cross-app user data extraction — CVE-2026-10706 lets authenticated users extract full user records across all 1M+ apps on the no-code platform — no tenant isolation and no current remediation.
- HalluSquatting could trick AI coding assistants into installing botnet malware — Attackers pre-register package names that AI assistants hallucinate, delivering malware when the tools fetch dependencies.
- Protecting Microsoft at AI speed: how SFI proactively hardens the cloud — Microsoft details its Secure Future Initiative for continuously evaluating and hardening cloud services against evolving threats.
- Fake Paysafe and Skrill SDKs on npm and PyPI steal credentials — Malicious packages impersonating payment SDKs are actively stealing developer and user credentials; audit dependencies and block them.
Vulnerabilities & CVEs
GhostLock: 15-year-old Linux flaw enables root on most distros
Read digest- 15-year-old GhostLock flaw enables root and container escape on most Linux distros — GhostLock (CVE-2026-43499) lets any logged-in user escalate to root and escape containers on virtually all mainstream distros shipped since 2011.
- CISA orders feds to prioritize patching Langflow auth bypass — The actively exploited authentication bypass in the visual AI agent framework enables unauthorized access in AI deployment environments.
- CISA orders feds to patch max-severity ColdFusion flaw by Friday — The actively exploited CVE-2026-48282 (CVSS 10.0) allows arbitrary code execution via path traversal.
- Ubiquiti warns of new max-severity UniFi OS vulnerability — Patches cover seven critical UniFi OS flaws including a remotely exploitable command injection enabling device takeover.
- DHS IG investigates forced CISA reassignments — The probe into personnel reassignments raises agency-stability concerns; the bulletin also flags remotely disableable Hoymiles solar panel systems.
Active Exploits & Incidents
Critical Gitea auth bypass under active exploitation
Read digest- Critical Gitea flaw under active exploitation — Attackers are exploiting the CVSS 9.8 authentication bypass CVE-2026-20896, gaining unauthorized access to repositories and secrets via a single HTTP header.
- Highly critical SQL injection in Drupal core — The unauthenticated CVSS 9.8 SQLi on PostgreSQL-backed Drupal sites is drawing exploitation attempts; patches cover six supported branches.
- RedWing MaaS packages Android bank fraud as a Telegram rental — The ~$300/month malware-as-a-service lets low-skill criminals hijack phones, steal banking credentials and intercept OTPs.
- Microsoft June Patch Tuesday: 198 CVEs including 3 zero-days — The largest Patch Tuesday ever fixes 32 critical CVEs across .NET, ASP.NET Core, Active Directory, Azure and Copilot Chat.
- Hidden backdoor in Tenda router firmware grants admin access — Multiple firmware versions ship an authentication backdoor to the admin web panel; update or isolate affected devices.
Threat Research & Deep Dives
Kaspersky maps the Q1 2026 industrial automation threat landscape
Read digest- Threat landscape for industrial automation systems, Q1 2026 — Kaspersky breaks down attack types, threat actor origins and impacted regions targeting ICS/SCADA and OT environments.
- Keyfactor scores $1 billion+ investment for AI and post-quantum security — The strategic growth funding targets identity sprawl — machine identities outnumbering humans — with post-quantum cryptography and AI-driven automation.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check