Security Intel Feed
Cyber Hose
Page 47 of 52
Threat Research & Deep Dives
Kaspersky maps the Q1 2026 industrial automation threat landscape
Read digest- Threat landscape for industrial automation systems, Q1 2026 — Kaspersky breaks down attack types, threat actor origins and impacted regions targeting ICS/SCADA and OT environments.
- Keyfactor scores $1 billion+ investment for AI and post-quantum security — The strategic growth funding targets identity sprawl — machine identities outnumbering humans — with post-quantum cryptography and AI-driven automation.
Vulnerabilities & CVEs
16-year-old Linux KVM flaw lets guest VMs escape to the host
Read digest- 16-year-old Linux KVM flaw lets guest VMs escape to host — Januscape (CVE-2026-53359), a use-after-free in KVM's shadow MMU code on Intel and AMD x86, lets a guest VM corrupt host kernel memory; a public PoC panics the host.
- Iran-linked hackers use new Cavern C2 framework against Israeli organizations — An MOIS-affiliated group is deploying the previously undocumented modular framework against Israeli IT providers and government sectors.
- Threat actors probe critical Gitea Docker flaw 13 days after disclosure — CVE-2026-20896 (CVSS 9.8) lets attackers bypass authentication in Gitea Docker images by spoofing the X-WEBAUTH-USER header.
- Armored Likho APT targets government and electric power entities — The financially motivated APT blends espionage and theft using modular RATs and info stealers.
- Hidden authentication backdoor found in Tenda router firmware — CERT/CC reports multiple Tenda firmware versions ship a hidden admin backdoor (CVE-2026-11405) that bypasses password verification for full device control.
Active Exploits & Incidents
EU official's phone infected with Pegasus spyware
Read digest- Risky Bulletin: EU official's phone infected with Pegasus — A European MP's phone was compromised with Pegasus spyware; the bulletin also covers Android cutting PIN guesses from 1,800 to 20 and Alibaba banning Claude at work.
- Opera GX flaw let malicious sites auto-install data-stealing mods — Malicious websites could silently install extensions that exfiltrate page data — researchers reconstructed a signed-in Gmail address with no user interaction. Now patched.
- TrojPix leaks data from air-gapped systems via video cable emissions — Researchers encoded data into imperceptible pixel changes whose video-cable radio emissions can be decoded by nearby receivers.
- SkillCloak lets malicious AI agent skills evade static scanners — The self-extracting packing technique evades static scanning of malicious AI coding agent add-ons with over 90% success; a runtime checker catches most evasions.
- QuimaRAT: cross-platform Java RAT sold as a service — The malware-as-a-service targets Windows, Linux and macOS with tiered subscriptions from $150/month.
Vendor Bulletins & Advisories
Flipper Zero firmware development leans on its community
Read digest- Flipper Zero firmware development continues with community help — Flipper Devices is shifting to a reduced internal team with more community contributions — a change that may affect the pace and security posture of future firmware releases.
Active Exploits & Incidents
JadePuffer ransomware used AI agent to automate entire attack
Read digest- JadePuffer ransomware used AI agent to automate entire attack — The first known ransomware campaign fully orchestrated by an LLM agent automated reconnaissance, lateral movement and payload deployment without human operators.
Vulnerabilities & CVEs
Bad Epoll Linux kernel flaw lets unprivileged users gain root
Read digest- Bad Epoll Linux kernel flaw lets unprivileged users gain root — CVE-2026-46242 (CVSS 9.1) gives local unprivileged users full root control on Linux desktops, servers and Android devices; a patch is available.
- NetNut proxy network disrupted, 2 million infected devices cut off — The Google-coordinated takedown dismantled a residential proxy network built on compromised Android devices, smart TVs and streaming boxes.
- Avalon malware framework packs CrownX ransomware capabilities — The modular framework combines credential theft, lateral movement, remote access, recovery disruption and ransomware into one phishing-delivered chain.
- North Korea-linked npm packages mimic Rollup polyfills — Malicious packages impersonating Rollup polyfill tooling enable remote access and exfiltration of developer secrets.
- ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit — The phishing-as-a-service platform lowers the barrier for M365 credential-harvesting campaigns against enterprise cloud environments.
Active Exploits & Incidents
Medtronic data breach impacts 3.8 million people
Read digest- Medtronic data breach impacts 3.8 million people — The April breach tied to the ShinyHunters extortion group exposed personal and medical data of over 3.8 million individuals.
- Critical Cursor AI editor flaws could lead to OS-level remote code execution — The DuneSlide vulnerabilities enable zero-click prompt injection that escapes sandboxing and executes arbitrary OS-level code; no CVE IDs published yet.
- Armored Likho APT's covert BusySnake Stealer campaign — The APT targets organizations in Russia, Kazakhstan and Brazil with spear-phishing, AI-generated loaders and a new Python-based stealer.
- PamStealer uses fake Maccy sites to steal Mac login passwords — The macOS stealer impersonates the Maccy clipboard manager and abuses PAM checks to harvest login credentials — a novel macOS theft vector.
- Alleged Scattered Spider hacker extradited to US — The 19-year-old is allegedly linked to a group behind 100+ intrusions and over $100M in ransom payments.
Active Exploits & Incidents
New CitrixBleed flaw exploited immediately after disclosure
Read digest- New CitrixBleed vulnerability exploited immediately after public disclosure — Attackers are using public PoC code to leak arbitrary memory from NetScaler appliances via HTTP responses; patch or mitigate immediately.
- FBI seizes NetNut proxy platform and Popa botnet — Hundreds of domains tied to the ~2M-device residential proxy network were seized, with Google and Lumen degrading the proxy pool by millions of devices.
- The Gentlemen ransomware: what you need to know — A profile of the gang's aggressive tactics and evolving extortion methods to aid detection and response planning.
- Akamai launches Cloud Pulse Alerts for real-time observability — The tool provides immediate alerting on anomalous cloud activity for security monitoring and incident response.
- Most cybersecurity workers have been told to conceal a breach — Bitdefender's report finds widespread pressure on security professionals to hide incidents, pointing to cultural and resource strain.
Active Exploits & Incidents
SharePoint RCE added to CISA KEV after active exploitation
Read digest- SharePoint RCE CVE-2026-45659 added to CISA KEV — The CVSS 8.8 deserialization flaw in SharePoint Server is confirmed exploited in the wild; urgent patching is required across supported versions.
- AI agent exploits Langflow RCE to automate database ransomware attack — Sysdig's JADEPUFFER finding appears to be the first fully AI-driven ransomware attack — automated exploitation, credential theft, lateral movement and encryption.
- FortiBleed credential theft linked to INC and Lynx ransomware — Stolen FortiGate credentials are fueling follow-on intrusions and ransomware deployment, with operators observed negotiating payments.
- ChocoPoC RAT targets vulnerability researchers via fake PoC repos — Fake Python PoC exploit repositories on GitHub deliver credential theft, cookie capture and remote shell access to researchers who run them.
- Medtronic notifies customers impacted by ShinyHunters breach — The medical device maker confirmed personal customer data was exposed to parties linked to the ShinyHunters group.
Active Exploits & Incidents
Oracle E-Business Suite flaw under immediate threat
Read digest- Critical flaw in Oracle E-Business Suite is under immediate threat — Active exploitation of the Oracle Payments flaw is being observed, urging immediate patching and monitoring of payment processing environments.
- Critical Cursor flaws let prompt injection escape sandbox — Two CVSS 9.8 vulnerabilities in the Cursor AI code editor allow prompt injection to break sandbox restrictions and run arbitrary commands without user interaction.
- Unpatched Argo CD flaw could let attackers take over Kubernetes clusters — An unauthenticated code execution flaw in the repo-server component has no patch or CVE yet; restrict network access to the internal port.
- VEIL#DROP malware chain uses Blogger to deliver PureLogs stealer — The multi-stage campaign pairs social engineering with Blogger-hosted pages, seeded via spear-phishing and drive-by compromises.
- Microsoft adds Teams controls to block unauthorized AI bots — New admin policies require organizer approval for external AI bots joining meetings — worth enabling in sensitive environments.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check