Security Intel Feed
Cyber Hose
Page 49 of 52
Vendor Bulletins & Advisories
NIST issues remote-access security guidance for water utilities
Read digest- NIST offers security guidance for water utilities using remote-access tools — Targeted recommendations address the water sector's exposure to unauthorized access and operational disruption through remote-access technologies.
- As cyber risk evolves, the insurance industry tightens guardrails — Insurers are linking coverage eligibility to detailed security controls and incident-response capability, raising the bar for executives.
Vendor Bulletins & Advisories
Linode ships default-deny firewalls for cloud workloads
Read digest- Linode interfaces and default firewall now generally available — New network interfaces plus a default-deny firewall raise the baseline security posture for cloud workloads and simplify firewall management.
- The four elevations of effective fraud prevention — IPQS outlines four strategic layers for defending accounts and ecosystems — not just transactions — to improve detection and cut false positives.
- Your AI cost model stops at the token price; the bill doesn't — Nearly 80% of AI production costs come from inference workloads — a budgeting reality for teams running AI-driven detection.
Active Exploits & Incidents
Lantronix serial-to-IP converter flaw exploited in OT attacks
Read digest- Lantronix serial-to-IP converter flaw actively exploited — Attackers are exploiting CVE-2025-67038 for remote code execution in campaigns targeting industrial networks, following the April BRIDGE:BREAK disclosure.
- Gaslight macOS malware uses prompt injection to evade AI analysis — The Rust-based implant embeds prompt-injection payloads that make AI-driven malware analysis tools abort or refuse analysis.
- Prompt injection attacks exploit LLM role confusion — New academic work shows role tags are a flawed security boundary — innocuous text can subtly shift model state, making prompt injection persistent.
- GitLab patches 13 vulnerabilities including code execution flaws — GitLab CE/EE updates fix 13 flaws, three rated high severity, covering remote code execution and sensitive data leaks.
- Kaspersky: SMBs face rising threats from fake AI tools — The 2026 SMB threat report tracks an uptick in attacks using fake AI tools alongside traditional phishing and data theft.
Active Exploits & Incidents
CISA warns of max-severity Ubiquiti flaws exploited in attacks
Read digest- CISA warns of max-severity Ubiquiti flaws exploited in attacks — Active exploitation of critical UniFi OS and Lantronix flaws lets unauthenticated remote attackers execute commands and take over accounts in enterprise and ISP environments.
- Cordyceps CI/CD flaws expose 300+ GitHub repos to supply-chain attacks — The workflow vulnerability lets unauthenticated attackers hijack build pipelines in repos belonging to Microsoft, Google and Apache, exposing millions of downstream users.
- Spyware embeds forbidden text to discourage AI analysis — Malware authors are stuffing politically sensitive text into JavaScript comments to trip policy filters and derail LLM-based scanners.
- NIST drafts updated IoT product security guidance — The SP 800-213 Revision 1 draft updates IoT cybersecurity guidelines for federal agencies; public feedback is open.
- BeyondTrust and LastPass impacted by Klue-Salesforce incident — Over a dozen Klue customers confirm data theft from compromised Salesforce instances, spotlighting third-party SaaS integration risk.
Active Exploits & Incidents
Fake AI agent skill passed security scans and reached 26,000 agents
Read digest- Fake AI agent skill passed security scans and reached 26,000 agents — Security firm AIR's benign proof-of-concept bypassed multiple popular scanners and spread via a skill marketplace and Instagram ads to ~26,000 agents, exposing gaps in AI skill vetting.
- Trump order sets 2030 deadline for federal post-quantum migration — US federal agencies must migrate high-value assets to post-quantum cryptography by end of 2030, with digital signatures due by 2031.
- Scattered Spider hackers plead guilty on day 1 of trial — Two key members admitted their role in the August 2024 Transport for London attack — early pleas that may yield intelligence on the group's TTPs.
Active Exploits & Incidents
Klue supply chain attack threatens hundreds of Salesforce customers
Read digest- Klue investigating supply chain attack targeting Salesforce integrations — The compromise potentially impacts hundreds of enterprise customers including prominent cybersecurity firms, with customer data exposure suspected.
- Data exposure flaws threaten Dify AI platform used by 1 million apps — Multi-tenant isolation flaws could let attackers read other tenants' private chats and documents and reach internal APIs across a massive dependent ecosystem.
- New deadlines set for post-quantum cryptography adoption — A White House executive order accelerates PQC standards adoption across federal agencies and contractors and funds quantum-defense research.
- Scattered Spider members plead guilty to Transport for London hack — Two members of the group admitted guilt for the 2024 breach of TfL systems, underscoring risks to critical infrastructure from financially motivated crews.
- Five Eyes warn of looming AI-fueled cyber threats — The intelligence alliance expects advanced AI models to enable markedly more sophisticated attacks within months.
Active Exploits & Incidents
LastPass confirms data breach in Klue supply chain attack
Read digest- LastPass confirms data breach in Klue supply chain attack — Hackers accessed LastPass customer data via OAuth tokens stolen from its Salesforce environment in the Klue supply-chain compromise earlier this month.
- Microsoft June Patch Tuesday: 198 CVEs including 3 zero-days — The largest Patch Tuesday ever fixes 32 critical CVEs across .NET, Active Directory, Azure and Copilot Chat; prioritize the zero-day patches.
- FFmpeg PixelSmash flaw enables RCE via crafted media files — A critical libavcodec bug lets attackers run arbitrary code on video players, media servers and NAS appliances by sending malicious media files.
- GitHub updates actions/checkout to block Pwn Request attacks — The patch prevents abuse of the pull_request_target workflow trigger that could execute malicious code with full workflow privileges.
- Hacker hijacks Brazil's national alert system — False emergency messages sent to millions undermine public trust and expose weak access controls in critical alerting infrastructure.
Lesser-Known / Under-Reported
Mythos has found thousands of critical bugs, Risky Business reports
Read digest- Risky Bulletin: Mythos has found thousands of critical bugs — Anthropic's Mythos security tool reportedly uncovered thousands of critical vulnerabilities across diverse software, alongside news of Dutch raids on bulletproof hosters.
- Boards want cyber risk in dollars, not CVE counts — CYE's three-step framework translates cyber risk into financial terms via attack-path mapping and business-impact quantification.
Threat Research & Deep Dives
Prompt Overflow attack bypasses LLM guardrail input filtering
Read digest- Prompt Overflow: what the guardrail inspects is not what the model infers — Guardrail models inspect smaller input windows than the LLMs behind them, enabling a novel attack that slips past input filtering for prompt injection.
- PoisonForge: targeted poisoning of instruction-tuned LLMs — With as few as 10 poisoned examples per 1,000 fine-tuning samples, most tested models showed over 70% attack success — a new AI supply-chain vector.
- Split inference leaks: reconstructing LLM inputs from activations — High-fidelity input reconstruction attacks defeat split-inference privacy architectures even with noise-injection defenses applied.
- The C-suite loves shadow AI — 65% of senior decision-makers use unapproved AI tools — more than double the rate of junior employees — a growing executive-level insider risk.
- Are frontier LLMs ready for cybersecurity? — Benchmarks of six leading LLMs show 10-50% false-positive rates in vulnerability detection, cautioning against overreliance on unspecialized models for security testing.
Lesser-Known / Under-Reported
PROMISE debuts AI-optimized enterprise storage at COMPUTEX 2026
Read digest- PROMISE Technology brings sustainability focus to AI storage — The AI-optimized enterprise storage portfolio targets AI workloads with scalable expansion and energy efficiency, touching data-center resilience.
- Most Singaporeans know about LPAs, but only 1 in 3 have made one — An SMU study highlights a legal-preparedness gap with implications for digital asset and identity management in aging populations.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check