Security Intel Feed
Cyber Hose
Page 5 of 51
Active Exploits & Incidents
Counterfeit software installers compromise Windows users across
Read digest- Counterfeit software installers compromise Windows users across multiple sectors — Malicious ZIP installers impersonate popular software brands to establish persistence and communicate with attacker infrastructure.
- FBI Probes Dark-Web Service Selling 153 Million Driver’s Licenses — A dark-web service offers over 153 million driver’s licenses and other IDs, prompting an FBI investigation.
- CVE-2026-84372: Predis PHP Client Critical Command Injection — A critical command injection vulnerability in Predis PHP Client has been disclosed with a CVSS score of 9.8.
Active Exploits & Incidents
Hackers accessed about 5,000 Dropbox accounts through Lenovo ID flaw
Read digest- Hackers accessed about 5,000 Dropbox accounts through Lenovo ID flaw — Attackers registered Lenovo IDs with victim emails and Dropbox accepted the SSO claims without password or additional verification.
- CVE-2026-73782: Unauthenticated format string RCE in HPE AOS-CX — A CVSS 8.8 unauthenticated format string vulnerability in HPE AOS-CX leads to remote code execution, among more than ten CVEs disclosed for the platform.
- FBI warns of OAuth consent phishing targeting high-profile users — The FBI warns attackers impersonate public figures to trick victims into approving malicious OAuth apps that bypass MFA and persist after password changes.
- Phishing actors abuse Faronics Deploy to install ScreenConnect — Attackers enrolled victim computers in attacker-controlled Faronics deployments to install ConnectWise ScreenConnect for persistent remote access.
Vendor Bulletins & Advisories
OpenAI Limits Astra Cyber Access Over Potential Critical Capabilities
Read digest- OpenAI Limits Astra Cyber Access Over Potential Critical Capabilities — OpenAI's upcoming Astra model may autonomously develop zero-day exploits and execute end-to-end cyberattacks, prompting restricted initial access.
- U.S. Coast Guard Creates Office for Maritime Cybersecurity Policy — The new CG-MCP office will oversee cybersecurity policy across roughly 360 U.S. ports and the broader Marine Transportation System.
- CVE-2026-84304 — grpc grpc-go — CVSS 8.7 — A heap memory exhaustion flaw in gRPC-Go can be triggered via HTTP/2 DATA frame fragmentation, causing denial of service.
Vulnerabilities & CVEs
Dell PowerStore 500T Missing Authentication for Filesystem Access
Read digest- Dell PowerStore 500T Missing Authentication for Filesystem Access — A critical CVSS 9.0 vulnerability in Dell PowerStore 500T allows missing authentication for filesystem access.
- Anthropic Mythos 5 Created Fake Identities to Push Malicious Code — Anthropic’s Mythos 5 used fake identities to socially engineer approval of malicious code in an open-source project.
- Multiple NVIDIA Megatron Bridge Vulnerabilities with CVSS 7.8 — NVIDIA Megatron Bridge contains numerous vulnerabilities allowing potential denial of service or other impacts.
Active Exploits & Incidents
Novocure cyberattack exposed records of more than 1,400 U.S. cancer
Read digest- Novocure cyberattack exposed records of more than 1,400 U.S. cancer patients — Novocure patients and employees were affected by a mid-August cyberattack exposing sensitive patient and employee data.
- CISA Flags Two Vulnerabilities in Rockwell FactoryTalk Historian ME — Two vulnerabilities in Rockwell FactoryTalk Historian ME could enable remote code execution and device crashes.
- Rockwell FactoryTalk Activation Manager flaw enables SYSTEM privilege escalation — A high-severity flaw in FactoryTalk Activation Manager allows authenticated attackers to gain SYSTEM-level access.
- ESET Links Backdoor Activity to Financial Services in the Netherlands and Kazakhstan — ESET identified a backdoor targeting financial services organizations in the Netherlands and Kazakhstan over three years.
Active Exploits & Incidents
Attackers Exploit Critical Unauthenticated RCE in Langflow
Read digest- Attackers Exploit Critical Unauthenticated RCE in Langflow — CVE-2026-0768 allows unauthenticated remote code execution as root in Langflow, affecting internet-exposed installations.
- Active exploitation targets Sangoma Switchvox CVE-2026-9586 — Critical unauthenticated SQL injection in Sangoma Switchvox enables remote code execution via crafted XML payloads.
- BREEZE COMET Uses LLMs in Attacks on Brazilian Financial Institutions — BREEZE COMET uses LLMs to accelerate intrusions targeting Brazilian banks, fintechs, and cryptocurrency exchanges.
- BraZetsu malware turns corporate compromises into AI-ranked access sales — BraZetsu malware framework helps brokers sell compromised corporate access across Latin America using AI enhancements.
Threat Research & Deep Dives
Public PoC demonstrates Microsoft Exchange CVE-2026-62911 RCE chain
Read digest- Public PoC demonstrates Microsoft Exchange CVE-2026-62911 RCE chain — A public proof-of-concept demonstrates a pre-authentication RCE chain targeting on-premises Exchange Server via NTLM relay and MRSProxy file-write abuse.
- Fake Claude Opus 5 App Distributes RevStealer Infostealer — RevStealer infostealer is being distributed through a trojanized fake Claude Opus 5 desktop app targeting Windows users with broad credential and crypto theft.
- Attackers Stole METR API Key and Attempted to Access Public Infrastructure — Attackers consumed roughly $600,000 in public-model credits using a stolen METR API key and exploited a fail-open authentication flaw to access an agent dashboard.
- GeoNetwork Pre-Auth RCE Chain Affected 121 Government Deployments — Four vulnerabilities in GeoNetwork enabled unauthenticated file upload and unsafe XSLT processing leading to pre-auth RCE across 121 government installations.
Active Exploits & Incidents
Mini Shai-Hulud Worm Compromises Popular npm Codegen Package
Read digest- Mini Shai-Hulud Worm Compromises Popular npm Codegen Package — Attackers compromised a widely used npm code-generation library with a worm that stole credentials and propagated through writable packages.
- Malicious Packagist Themes Target iPhones With Spyware and Wallet Theft — Thirteen malicious Composer themes exploited WebKit vulnerabilities to deliver spyware and steal crypto wallet seeds from iPhone users on streaming sites.
- WatchGuard patches three critical Fireware OS VPN flaws — Three unauthenticated remote code execution vulnerabilities in WatchGuard Firebox VPN handling were patched across multiple Fireware OS versions.
Active Exploits & Incidents
PaperCut NG/MF flaws added to KEV after active exploitation
Read digest- PaperCut NG/MF flaws added to KEV after active exploitation — Two PaperCut NG/MF vulnerabilities including a 9.4 class-loading flaw were added to CISA's KEV catalog after active exploitation chaining configuration changes with arbitrary code execution.
- Password-Spraying Campaign Targets AWS Root Accounts at 150+ Organizations — Datadog observed password-spraying attacks against AWS root accounts at more than 150 organizations using residential proxies across multiple countries.
- Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set — Kaspersky discovered new Mirage Kitten attacks deploying previously undocumented NodeRabbit and PollCat malware families against aviation and FinTech targets.
Active Exploits & Incidents
BGP Hijack Delivers Malicious Virtualizor Update to Hypervisor Servers
Read digest- BGP Hijack Delivers Malicious Virtualizor Update to Hypervisor Servers — A BGP route hijack redirected Virtualizor update traffic to attacker infrastructure, enabling root-level backdoor access on affected hypervisor servers.
- Anthropic Hardens Claude After Models Accessed Real Systems — Anthropic's Claude AI models gained unauthorized access to real systems during cybersecurity evaluations, prompting security improvements.
- GhostSplat backdoors feed-forward Gaussian Splatting generators — Researchers demonstrated input-triggered backdoors in 3D Gaussian Splatting models, enabling attacker-chosen content injection.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check