Security Intel Feed
Cyber Hose
Page 7 of 51
Threat Research & Deep Dives
ContextLeak Uses Malicious Tools to Exfiltrate LLM Agent Context
Read digest- ContextLeak Uses Malicious Tools to Exfiltrate LLM Agent Context — ContextLeak exploits LLM agents using external tools to leak user prompts and execution data to attackers.
- CVE-2026-77850 — Stored XSS in AshAdmin relationship typeahead — A stored cross-site scripting vulnerability in AshAdmin allows injection via unescaped label_field content.
- CVE-2026-82673 — Path traversal in AshAdmin file uploads — AshAdmin file upload feature is vulnerable to path traversal through unsanitized client filenames.
- CVE-2026-82722 — AshAdmin LiveView events atom exhaustion — Client input can exhaust server atoms in AshAdmin LiveView events, causing potential denial of service.
- CVE-2026-75757 — AshAdmin cookie reader session hijack — AshAdmin cookie reader matches names by substring, enabling session hijacking via crafted cookies.
Vulnerabilities & CVEs
CVE-2026-77956: CVSS 10.0 RCE in AshAi via prompt template evaluation
Read digest- CVE-2026-77956: CVSS 10.0 RCE in AshAi via prompt template evaluation — EEx template evaluation of prompt content in AshAi enables unauthenticated remote code execution with a perfect CVSS score.
- Critical Buffer Overflow Hits D-Link DIR-825M Firmware 1.1.8 — A buffer overflow vulnerability in D-Link DIR-825M router firmware could allow remote attackers to execute arbitrary code.
- CVE-2026-75759: CVSS 7.6 — Encrypted ID token accepted without nested signature — An OAuth/OIDC implementation flaw allows encrypted ID tokens or JARM responses to be accepted without a required nested signature.
Vulnerabilities & CVEs
Critical CVEs in D-Link DIR-825M Firmware Components
Read digest- Critical CVEs in D-Link DIR-825M Firmware Components — Two critical vulnerabilities with CVSS 8.6 impact the LTE Module Firmware and Disk Formatting Handler of D-Link DIR-825M devices.
- CVE-2026-82592 in D-Link DIR-825M Disk Formatting Handler — A critical flaw in the disk formatting handler endpoint of D-Link DIR-825M could allow exploitation.
Vulnerabilities & CVEs
Critical CVE-2026-15369 WooCommerce flaw allows unauthenticated RCE
Read digest- Critical CVE-2026-15369 WooCommerce flaw allows unauthenticated RCE — This vulnerability in WooCommerce versions through 2.2.3 enables attackers to execute code remotely without authentication.
- CRPx0 ransomware operation offers ClickFix-based RaaS — CRPx0 ransomware-as-a-service uses ClickFix stagers to steal data and cryptocurrency from targeted organizations.
Vendor Bulletins & Advisories
AVideo Flaw Exposes Stream Credentials Without Authentication
Read digest- AVideo Flaw Exposes Stream Credentials Without Authentication — An AVideo advisory discloses a flaw that exposes stream credentials without requiring authentication.
- SiYuan Before 3.8.1 Exposed to Stored XSS via Malicious Names — SiYuan versions prior to 3.8.1 are vulnerable to stored XSS triggered by malicious note names.
- CVE-2026-78699 — A CVSS 7.2 flaw allows cross-tenant access when a failed tenant rename still returns a success status.
Active Exploits & Incidents
Rhysida claims 5.79TB data theft from Berlin government systems
Read digest- Rhysida claims 5.79TB data theft from Berlin government systems — Rhysida claims it stole 5.79 TB across roughly 1.44 million files from Berlin state government departments and threatened to auction the data for 30 bitcoin.
- Infostealers hijack Claude sessions to drain users' account usage — Anthropic linked session-hijacking attacks against Claude users to multiple infostealer families including Vidar, LummaC2, RedLine, and Atomic Stealer.
- CVE-2026-82645 — CVSS 9.2 — AVideo Unauthenticated Stream Credential Disclosure via Forgeable Token — An unauthenticated credential disclosure flaw in WWBN AVideo allows attackers to forge tokens and expose stream credentials.
- 19 Chrome and Edge Extensions Found Stealing Crypto and Browser Data — Researchers identified 19 malicious browser extensions targeting cryptocurrency wallets and sensitive browser data across Chrome and Edge.
Vulnerabilities & CVEs
Critical Icollect flaws enable unauthenticated file read and SSRF
Read digest- CVE-2026-77012 — CVSS 9.3 — Icollect through 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal — Unauthenticated attackers can read arbitrary files and perform SSRF against vulnerable Icollect deployments through version 1.0.0.
- CVE-2026-76548 — CVSS 8.2 — Profile Builder before 4.0.1 - Unauthenticated Unpublished Content and Media Modification — Profile Builder versions before 4.0.1 allow unauthenticated users to modify unpublished content and media.
- CVE-2026-76586 — CVSS 7.5 — BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation — Unauthenticated attackers can manipulate booking prices in BookingPress versions 1.5.6 through 1.6.2.
Vulnerabilities & CVEs
Omnivore API Authentication Bypass in Apple Sign-In (CVE-2026-82454)
Read digest- Omnivore API Authentication Bypass in Apple Sign-In (CVE-2026-82454) — CVE-2026-82454 is a CVSS 9.3 authentication bypass affecting the Omnivore API via Apple Sign-In.
- qs.parse does not enforce arrayLimit on comma groups under bracket-push keys (CVE-2026-82562) — CVE-2026-82562 is a CVSS 6.3 vulnerability in the qs library's parsing of comma-grouped array values.
- qs.stringify throws TypeError on objects with a non-callable constructor.isBuffer (CVE-2026-82417) — CVE-2026-82417 is a CVSS 6.3 issue causing a TypeError in qs.stringify when handling malformed objects.
Vulnerabilities & CVEs
Cloud Commander Directory Traversal CVE-2026-82460 Scores 9.3
Read digest- Cloud Commander Directory Traversal CVE-2026-82460 Scores 9.3 — CVE-2026-82460 is a critical directory traversal vulnerability in Cloud Commander with a high CVSS score of 9.3.
Vulnerabilities & CVEs
SAML SSO unauthenticated auth bypass via X.509 (CVE-2026-75807)
Read digest- CVE-2026-75807 — CVSS 7.5 — SAML Single Sign On through 5.4.6 - Unauthenticated Authentication Bypass via X.509 — An unauthenticated authentication bypass in SAML Single Sign-On through version 5.4.6 could allow attackers to circumvent identity checks.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check