Security Intel Feed
Cyber Hose
Page 6 of 51
Vendor Bulletins & Advisories
Australia charges two alleged TeamPCP hackers after supply-chain
Read digest- Australia charges two alleged TeamPCP hackers after supply-chain attacks — Australian authorities have charged two individuals linked to the TeamPCP group for conducting software supply-chain attacks.
Active Exploits & Incidents
DOJ seizes QTFY domains used to target U.S. critical infrastructure
Read digest- DOJ seizes QTFY domains used to target U.S. critical infrastructure — QTFY targeted critical U.S. infrastructure including NASA, Federal Reserve, and multiple federal departments using compromised IoT devices.
- CVE-2026-83596: WebKitGTK Memory Corruption via Malicious Web Content — A high-severity CVSS 8.8 vulnerability in WebKitGTK allows memory corruption through malicious web content.
- CVE-2026-82882: Devtron Missing Authorization via Webhook API Token Endpoint — Devtron versions through 2.2.0 suffer from missing authorization allowing potential unauthorized access via webhook API tokens.
Active Exploits & Incidents
TONIC Price Manipulation Drains $74 Million From Cronos' Tectonic
Read digest- TONIC Price Manipulation Drains $74 Million From Cronos' Tectonic — An attacker manipulated TONIC's price 100-fold to drain roughly $74 million from Tectonic, prompting validators to halt the entire Cronos blockchain.
- Free LLM Endpoint Exposed Coding-Agent Session Data to a Honeypot — A relabeled inference honeypot embedded in free LLM backend infrastructure captured real coding-agent session data including filesystem paths and tool manifests.
- Internet scan finds 1,776 exposed satellite mission-control systems — SNMP scanning revealed satellite ground-segment mission-control systems exposed online that HTTP scans had missed.
- CVE-2026-53552 — Goploy: Cross-namespace IDOR and RCE via body-supplied row id — A CVSS 9.6 vulnerability in Goploy enables cross-namespace IDOR and remote code execution through a body-supplied row id.
Threat Research & Deep Dives
DPRK Job Fraud Expands Beyond IT Into Healthcare, Sales and Marketing
Read digest- DPRK Job Fraud Expands Beyond IT Into Healthcare, Sales and Marketing — DPRK-linked workers used stolen identities and laptop farms to infiltrate healthcare, financial services, and marketing roles across Australia.
- MCPHub CVE-2026-79748: Non-admin RCE via POST /api/servers (CVSS 9.9) — An authenticated non-admin user can achieve remote code execution in MCPHub through a vulnerable API endpoint.
Vulnerabilities & CVEs
CVE-2026-66047: ProfilePress Plugin Unauthenticated Arbitrary Install
Read digest- CVE-2026-66047 — CVSS 9.2 — ProfilePress WordPress Plugin before 4.17.2 Unauthenticated Arbitrary Plugin Installation — An unauthenticated arbitrary plugin installation flaw in the ProfilePress WordPress plugin could allow attackers to compromise sites running versions before 4.17.2.
- CVE-2026-75133 — CVSS 8.7 — Keep Backup Daily WordPress Plugin before 2.1.4 Sensitive Information Exposure — The Keep Backup Daily WordPress plugin exposes sensitive information in versions prior to 2.1.4.
- CVE-2026-75132 — CVSS 7.1 — WAPT Server SQL Injection via /api/v3/hosts Endpoint — WAPT Server versions 2.6.x are vulnerable to SQL injection through the /api/v3/hosts endpoint.
Vendor Bulletins & Advisories
McKesson Confirms Breach as ShinyHunters Claims 284M Records Stolen
Read digest- McKesson Confirms Breach as ShinyHunters Claims 284M Records Stolen — McKesson disclosed a breach after ShinyHunters claimed to have stolen 284 million records from the healthcare distribution giant.
- Public HardBreacher PoC Targets Kaspersky Endpoint Security — A public proof-of-concept exploits a local privilege-escalation flaw in Kaspersky Endpoint Security for Windows that Kaspersky says it has already patched.
- CVE-2026-82639 — NextChat 2.15.8 through 2.16.1 OpenAI API Key Disclosure — A CVSS 8.7 vulnerability in NextChat versions 2.15.8 through 2.16.1 exposes OpenAI API keys to unauthorized disclosure.
Active Exploits & Incidents
KindaRails2Shell Ruby on Rails Flaw Exploited for Remote Code
Read digest- KindaRails2Shell Ruby on Rails Flaw Exploited for Remote Code Execution — CVE-2026-66066 allows unauthenticated arbitrary file reads, secret theft, lateral movement, and RCE in Rails apps using Active Storage with libvips.
- HexMage Magecart Uses Ethereum Contracts to Steal Online Shoppers’ Card Data — HexMage targets over 40 e-commerce stores in 15 countries using Ethereum smart contracts to steal payment card data.
- Anthropic Extends Compliance API Coverage to Claude Code and Cowork — Anthropic expanded its Compliance API to cover Claude Code CLI, desktop sessions, and Cowork across multiple platforms.
- Supply-Chain Worm Compromises TanStack Query npm Code Generator — A supply-chain worm attack compromises the TanStack Query npm code generator, posing risks to dependent projects.
Active Exploits & Incidents
China-Linked Fire Ant Compromises Cisco Routers to Steal Credentials
Read digest- China-Linked Fire Ant Compromises Cisco Routers to Steal Credentials — A China-linked APT compromised Cisco IOS XR routers and TACACS servers to steal administrative credentials while concealing activity with custom malware.
- Spring Ring Uses Microsoft Teams Voice Phishing to Deploy Malware — Attackers abuse Microsoft Teams voice phishing to deploy malware and target enterprise domain controllers.
- ValleyRAT Backdoor Masquerades as QN Wallpaper Adware in Asia — Kaspersky detected ValleyRAT over 100,000 times across 1,500 users in 2026 via trojanized QN Wallpaper installers using DLL sideloading.
- Gryxa AI-Assisted Malware Survives Cleanup and Targets Windows Credentials — ReliaQuest identified an AI-assisted Windows malware toolkit that persists through scheduled tasks and WMI while stealing browser and crypto wallet credentials.
Vulnerabilities & CVEs
Critical Microsoft UFO Flaw Enables Unauthenticated Android Device
Read digest- Critical Microsoft UFO Flaw Enables Unauthenticated Android Device Control — CVE-2026-73296 allows attackers to remotely control Android devices connected via Microsoft UFO without authentication.
- Composer flaw lets malicious PHP packages expose sensitive files — A Composer vulnerability enables malicious packages to expose sensitive files via path traversal or symbolic links.
- IIS AppPool Can Escalate to SYSTEM via AD CS RPC Endpoint — Researchers disclosed a privilege escalation path from IIS AppPool to SYSTEM using an AD CS RPC endpoint.
Threat Research & Deep Dives
Blind Eagle Campaign Exposes RATs and Phishing Infrastructure
Read digest- Blind Eagle-Linked Campaign Exposes RATs and Phishing Infrastructure — An investigation revealed infrastructure linked to a Blind Eagle campaign targeting Colombia with RATs and phishing kits.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check