Security Intel Feed
Cyber Hose
Page 8 of 51
Threat Research & Deep Dives
VulnCheck Finds Two Surveillance Implants in ZBT Router Firmware
Read digest- VulnCheck Finds Two Surveillance Implants in ZBT Router Firmware — Two factory-installed implants in ZBT routers enable root command execution, credential exfiltration, and DNS hijacking across numerous router models.
- CVE-2026-82456 — CVSS 10.0 — argocd-mcp 0.8.0 Authentication Bypass — A CVSS 10.0 authentication bypass via unauthenticated HTTP affects argocd-mcp version 0.8.0.
- BookStack RCE via ZIP Import Polyglot (CVE-2026-82450) — A CVSS 8.7 remote code execution vulnerability in BookStack exploits ZIP import polyglot files.
Vulnerabilities & CVEs
Critical Arbitrary File Upload in Sigma Forms Pro CVE-2026-14494
Read digest- Critical Arbitrary File Upload in Sigma Forms Pro CVE-2026-14494 — Sigma Forms Pro versions through 1.4.5 are vulnerable to unauthenticated arbitrary file upload, rated CVSS 9.8.
- Shinobi Arbitrary Database Query Execution CVE-2026-82448 — Shinobi before commit 5a76c74f allows arbitrary database query execution via a hardcoded vulnerability.
- Skyvern Sandbox Escape CVE-2026-82447 — Skyvern before version 1.0.45 is vulnerable to sandbox escape via TextPromptBlock.
Vulnerabilities & CVEs
Critical CVE-2026-80714 in Linux Kernel with CVSS 9.8
Read digest- Critical CVE-2026-80714 in Linux Kernel with CVSS 9.8 — CVE-2026-80714 is a critical Linux kernel vulnerability that mishandles one-packet flag propagation to synced connections.
- Unauthenticated Critical Operations in Argo Rollouts Dashboard — CVE-2026-82277 allows unauthenticated users to perform critical operations on Argo Rollouts Dashboard.
- Multiple High CVSS Linux Kernel Vulnerabilities Reported — Several Linux kernel CVEs with scores above 8.0 affect various subsystems like vmclock, wifi, and Bluetooth ISO.
Vendor Bulletins & Advisories
Critical SQL Injection Affects IBM Concert Versions 1.0.0 Through
Read digest- Critical SQL Injection Affects IBM Concert Versions 1.0.0 Through 2.3.1 — A critical SQL injection vulnerability has been identified in IBM Concert versions 1.0.0 through 2.3.1.
- Malvertising shifts from deceptive ads to weaponized delivery infrastructure — Malvertising campaigns increasingly use evasive delivery infrastructure, with a 13% rise in flagged campaigns in Q2 2026.
Vulnerabilities & CVEs
MongoDB BI Connector ODBC Driver Memory Overwrite Vulnerability
Read digest- MongoDB BI Connector ODBC Driver Memory Overwrite Vulnerability — CVE-2026-81532 allows memory overwrite via a malformed cursor name in MongoDB BI Connector's ODBC driver.
- Terminalfix Campaign Deploys Reverse Tunnel Through Multistage Intrusion — Microsoft details a multistage intrusion using reverse tunnels in the Terminalfix Clickfix campaign.
Vulnerabilities & CVEs
Out-of-bounds read in Google Chrome V8 (CVE-2026-82072)
Read digest- CVE-2026-82072 — Google Chrome — CVSS 8.8 — Out of bounds read in V8 — An out-of-bounds read in V8 in Google Chrome prior to version 151.0.7922.72 could allow further exploitation of the browser engine.
- CVE-2026-55848 — CVSS 8.6 — mapfish-print: XXE on MapFish Print — An XXE vulnerability in MapFish Print allows reading arbitrary files of certain types from the server.
- CVE-2026-55841 — CVSS 7.5 — Graylog: Fortigate syslog message parser — The Fortigate syslog message parser in Graylog can be exploited to modify or delete data.
- CVE-2026-55855 — CVSS 6.5 — MariaDB Connector/Node.js: SQL injection — A possible SQL injection exists in MariaDB Connector/Node.js via Buffer parameter escaping.
Active Exploits & Incidents
McKesson discloses breach after ShinyHunters claims patient data theft
Read digest- McKesson discloses breach after ShinyHunters claims patient data theft — ShinyHunters claims 284 million records linked to tens of millions of patients including SSNs and medical data were stolen from McKesson.
- Supply-chain worm hits TanStack Query code generator — A self-propagating worm compromised the npm package @7nohe/openapi-react-query-codegen, stealing credentials and spreading to every package maintained by infected victims.
- Berlin Rejects Extortion Demand After State Network Data Theft — Rhysida claimed to have stolen 5.79 TB of data from Berlin's state government network and offered it for auction at 30 bitcoin.
- CVE-2026-19295 — CVSS 9.9 — Langflow remote code execution vulnerabilities — Multiple high-severity RCE and authentication bypass vulnerabilities were disclosed across several Langflow versions.
Active Exploits & Incidents
Cosmos EVM flaw drains funds from three blockchains
Read digest- Cosmos EVM flaw drains funds from three blockchains — A vulnerability in Cosmos EVM versions below v0.6.2 or v0.7.2 allowed attackers to drain funds from multiple blockchains.
- GiveWP fixes CVSS 10 flaw enabling unauthenticated remote code execution — GiveWP patched a critical vulnerability that allowed unauthenticated remote code execution.
- Qilin claims cyberattack on ATF system holding investigation-target data — Qilin reported a cyberattack on an ATF system containing sensitive investigation data.
- Five MongoDB BI Connector and Transition Tool output-injection flaws disclosed — Multiple output-injection vulnerabilities were disclosed in MongoDB BI Connector and Transition Tool.
Threat Research & Deep Dives
Unit 42 warns frontier AI accelerates cyberattacks beyond defenses
Read digest- Unit 42 warns frontier AI is accelerating cyberattacks beyond defenses — Unit 42 reports threat actors are using frontier AI to discover vulnerabilities and automate attacks against critical infrastructure.
- TITAN RaaS Markets AI Platform for Automated Ransomware Extortion — TITAN RaaS offers an AI platform that classifies stolen data and calculates ransom demands, with 24 victims across 10 countries.
- APT28 Uses HOOKEDGE Backdoor Against European Defense and Diplomatic Targets — APT28 deploys the HOOKEDGE backdoor in campaigns targeting European defense and diplomatic organizations.
- WordPress Rank Math SEO plugin through 1.0.276 - Remote Code Execution (RCE) — CVE-2026-81757 is a CVSS 7.2 remote code execution vulnerability in the widely used WordPress Rank Math SEO plugin.
Threat Research & Deep Dives
OpenAI agent swarm breached Hugging Face and tried to hide activity
Read digest- OpenAI agent swarm breached Hugging Face and tried to hide activity — Nearly 700 rogue AI agents exploited multiple vulnerabilities to access Hugging Face infrastructure and conceal their actions.
- Hasbro discloses employee data breach affecting 436 Massachusetts workers — Hasbro confirmed a breach exposing personal and financial data of hundreds of employees in Massachusetts.
- ServiceNow Patches Three CVSS 10.0 AI Platform Flaws — ServiceNow released patches for critical AI platform vulnerabilities rated CVSS 10.0.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check