Security Intel Feed
Cyber Hose
Page 48 of 52
Active Exploits & Incidents
81 million password-spray attempts hammer Azure CLI accounts
Read digest- Massive password spray campaign targeting Azure CLI — Over 81 million login attempts from IPv6 ranges tied to hosting provider LSHIY LLC compromised at least 78 Microsoft accounts; enforce MFA and monitor Azure CLI access.
- Google patches 382 Chrome vulnerabilities — The massive batch includes 15 critical and 67 high-severity flaws whose exploitation could lead to arbitrary code execution; update immediately.
- Phantom squatting uses AI-hallucinated domains for phishing — Unit 42 found attackers pre-registering non-existent domains that AI tools hallucinate, boosting phishing success while evading domain monitoring.
- Risky Bulletin: researcher drops giant cache of zero-days — An anonymous researcher publicly released a large zero-day cache, raising exploitation risk; the bulletin also covers a sensitive DHS network breach.
- Dawnguard raises $6.3M for security architecture automation — The funding backs automated secure cloud architecture design — more evidence of demand for automated posture management.
Active Exploits & Incidents
Langflow RCE exploited to deploy Monero miners on AI endpoints
Read digest- Langflow RCE exploited to deploy Monero miner on exposed AI endpoints — Threat actors are actively exploiting the unauthenticated RCE CVE-2026-33017 (CVSS 9.3) to mine cryptocurrency on exposed Langflow AI infrastructure.
- GuardFall exposes AI coding agents to decades-old shell injection — The bypass circumvents safety checks in 10 of 11 popular open-source AI coding agents, exposing AI development workflows to remote code execution.
- Microsoft warns poisoned MCP tool descriptions can make AI agents leak data — Attackers can poison AI agent tool descriptions to exfiltrate sensitive company data without triggering alarms, turning trusted agents into covert loss vectors.
- Securing AI agents: when AI tools move from reading to acting — Microsoft's guidance covers detection, containment and prevention for MCP tool-poisoning attacks that hijack AI agents.
- Fake Perplexity extension on Chrome Web Store tracked searches — The impersonating extension intercepted search traffic and collected browsing data; audit installed AI-related plugins.
Active Exploits & Incidents
Nissan among 100+ organizations hit in Oracle PeopleSoft hack
Read digest- Nissan employee data breached in Oracle PeopleSoft hack — A campaign exploiting Oracle PeopleSoft vulnerabilities has compromised employee data at Nissan, one of over 100 affected organizations.
- Windows BlueHammer privilege escalation exploited by ransomware groups — CISA confirms ransomware operators are leveraging the Microsoft Defender privilege escalation zero-day in ongoing campaigns.
- BioShocking attack tricks AI browsers into leaking user credentials — LayerX showed that framing interactions as games convinces AI browsers — ChatGPT Atlas, Perplexity Comet, Claude — to disclose user credentials.
- Kali Linux 2026.2 released with 9 new tools — The release adds nine pentesting tools plus NetHunter improvements for mobile and embedded device testing.
- Quantifind raises $200M for AI-native risk intelligence — The funding accelerates global expansion of localized AI-driven risk intelligence — another signal of investment in AI security analytics.
Active Exploits & Incidents
Hackers post Oracle PeopleSoft breach data from US insurance body
Read digest- Insurance body confirms hackers posted Oracle PeopleSoft breach data — The NAIC confirmed breach data was posted by threat actors, and some ratings agencies suspended data feeds as a precaution.
- Malicious Perplexity Chrome extension intercepted searches — The impersonating extension silently logged search queries and address-bar input through attacker-controlled servers before Google removed it.
- New Claude Code attack hijacks developer machines via benign-looking repos — Researchers demonstrated reverse shells executed via indirect prompts hidden in seemingly harmless code repositories.
- DirtyClone Linux kernel flaw enables local privilege escalation — The new kernel vulnerability raises the risk of full system compromise and headlines a week of AI-malware tricks and infostealers.
- Microsoft extends Windows Server 2022 hotpatching until October 2027 — Hotpatching support now runs a year past mainstream support, extending the low-downtime security update window.
Vulnerabilities & CVEs
Critical libssh2 flaw lets malicious SSH servers hijack clients
Read digest- Public PoC released for critical libssh2 client-side SSH flaw — CVE-2026-55200 (CVSS 9.2) lets malicious or compromised SSH servers execute code on connecting clients without interaction; all versions up to 1.11.1 are affected.
- Hijacked npm and Go packages use VS Code tasks to deploy infostealer — The cross-platform Python infostealer bypasses npm lifecycle scripts, likely to evade npm v12 hardening — a sophisticated developer-ecosystem compromise.
- The Gentlemen are knocking: custom backdoors and evolving tactics — Kaspersky details new TTPs, custom backdoors and a new ransomware variant from The Gentlemen RaaS group.
- OpenAI unveils GPT-5.6 Sol as its most advanced cybersecurity AI — The cybersecurity-focused model matches rivals like Mythos Preview while using a third of the output tokens.
- US offers $10 million bounty for Russian state hackers — The bounty targets UNC5792 and UNC4221, who attack US officials and military personnel through evolving messaging-app exploits.
Active Exploits & Incidents
Data breach exposes up to 14.2 million email logins at six ISPs
Read digest- Data breach exposes up to 14.2 million email logins at six ISPs — Threat actors exfiltrated up to 14.2M email credentials from a system KDDI shares with five other major Japanese ISPs — prime fuel for credential stuffing and targeted phishing.
Vendor Bulletins & Advisories
YARA-X 1.18 and 1.19 sharpen rule matching for threat hunters
Read digest- YARA-X 1.18.0 and 1.19.0 released — The releases bring three improvements and two bugfixes that enhance rule-matching performance and stability for malware detection and threat hunting.
Threat Research & Deep Dives
Clean GitHub repo tricks AI coding agents into running malware
Read digest- Clean GitHub repo tricks AI coding agents into running malware — A seemingly clean repository executes hidden payloads when cloned and set up by AI coding assistants — undetectable by scanners, AI review or human review.
- Russian intelligence used fake support texts to steal messaging credentials — The SSU and FBI uncovered an ongoing campaign phishing government officials, military personnel and activists across Ukraine, Europe and the US.
Active Exploits & Incidents
CISA sets urgent deadline for exploited Cisco Unified CM flaw
Read digest- CISA sets urgent deadline to fix Cisco flaw exploited in attacks — Federal agencies must patch a critical, actively exploited Cisco Unified Communications Manager Server flaw by Sunday to avert remote code execution and takeover.
- More Klue breach victims identified as hackers get hacked — Roughly 24 companies have now disclosed impacts from the Klue-Salesforce breach, involving credential theft and lateral movement through SaaS integrations.
- Unit 42 threat brief: mitigating large-scale credential attacks — Recent credential stuffing and brute-force campaigns are targeting security vendors' devices; the brief covers MFA enforcement, anomaly detection and hygiene.
- FCC requires emergency-alert distributors to secure their systems — The FCC moves from recommending to mandating cybersecurity protocols for emergency-alert distributors after a decade-old hacking campaign.
- Amazon Q flaw enabled cloud credential theft via malicious repositories — AWS patched a flaw that let attackers steal cloud credentials by injecting malicious code into repositories, risking lateral movement in cloud environments.
Vulnerabilities & CVEs
Critical Chrome flaws allow arbitrary code execution
Read digest- Multiple Chrome vulnerabilities allow arbitrary code execution — The most severe of several critical Chrome flaws enables code execution in the logged-in user's context, with privilege escalation and persistence possible.
- Russia used Cellebrite on jailed activist's iPhone months after sales cutoff — Citizen Lab links forensic traces on activist Andrey Pivovarov's phone to Russian authorities' use of Cellebrite UFED after sales officially ceased.
- Google details Turla's new STOCKSTAY backdoor — The Russian APT's new .NET backdoor targets Ukrainian government and military entities plus organizations tied to Italian foreign policy.
- First-ever exploitation of PTC Windchill vulnerability in the wild — CISA added the remote code execution flaw CVE-2026-12569 to its KEV catalog after confirmed active exploitation.
- $3 million reportedly stolen in Polymarket hack — A third-party vendor compromise let attackers drain roughly $3M from user accounts on the decentralized prediction market.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check