Security Intel Feed
Cyber Hose
Page 9 of 51
Threat Research & Deep Dives
GiveWP flaw enables unauthenticated PHP object injection and RCE
Read digest- GiveWP flaw enables unauthenticated PHP object injection and remote code execution — Unauthenticated attackers can inject PHP objects and execute arbitrary commands on GiveWP sites with a published donation form and active payment gateway.
- Bauman University Leak Exposes GRU Cyber Training Pipeline — Leaked Bauman Moscow State Technical University records link graduates and supervisors to GRU units associated with APT28 and Sandworm.
- CVE-2026-75005 — Apache APISIX: Unauthenticated CPU-exhaustion DoS — A CVSS 8.7 inefficient-algorithm vulnerability in Apache APISIX allows unauthenticated remote CPU exhaustion.
- Rently Smart Home flaw exposed master PINs and user permissions — A vulnerability in Rently Smart Home exposed master PINs and user permission data.
Active Exploits & Incidents
PaperCut NG/MF Zero-Day Exploited Against Internet-Facing Servers
Read digest- PaperCut NG/MF Zero-Day Exploited Against Internet-Facing Servers — Attackers exploit a pre-authentication RCE chain in all PaperCut NG/MF versions, affecting offices, schools, and other organizations.
- APT28-Linked HOOKEDGE Backdoor Targets European Government Organizations — A previously undocumented Windows batch-script backdoor was deployed against government and diplomatic organizations in Romania, Spain, and Türkiye.
- CVE-2026-77016 — Workeera Remote Tech Job Board Arbitrary File Deletion (CVSS 9.6) — A high-severity arbitrary file deletion flaw affects Workeera Remote Tech Job Board before version 1.0.6.
Threat Research & Deep Dives
Australia arrests two TeamPCP members over supply-chain attacks
Read digest- Australia arrests two alleged TeamPCP members over global supply-chain attacks — Authorities arrested two suspects behind a campaign that breached over 1,000 organizations and stole more than 500,000 credentials via poisoned open-source packages.
- TranslatePress <=3.3.3 Exposes WordPress Sites to Unauthenticated Stored XSS — A popular WordPress translation plugin was found vulnerable to unauthenticated stored cross-site scripting affecting sites running version 3.3.3 or earlier.
- CVE-2026-16759 — Tutor LMS through 4.0.5 Unauthenticated Remote Code Execution — An unauthenticated remote code execution flaw in the Tutor LMS WordPress plugin allows attackers to execute arbitrary code via template parameters.
- CVE-2026-18978 — LiteSpeed Cache through 7.8.1 Unauthenticated Stored XSS — A widely deployed WordPress caching plugin was found vulnerable to unauthenticated stored cross-site scripting via content parameters.
Threat Research & Deep Dives
Silverstripe UserForms flaw enables code execution via email subject
Read digest- Silverstripe UserForms flaw enables code execution via email subject field — Silverstripe CMS sites using the UserForms visual form builder are vulnerable to arbitrary code execution via the email subject field.
- mySites.guru adds Joomla check for backdoor files in core folders — mySites.guru introduced a Joomla audit check that identifies unauthorized files in core folders to detect hidden backdoors.
- Xiiaozet LK100W Authentication Bypass and OS Command Injection CVEs — Multiple critical vulnerabilities in Xiiaozet LK100W include authentication bypass and OS command injection with high CVSS scores.
Vulnerabilities & CVEs
ServiceNow Faces Three CVSS 10.0 Unauthenticated Vulnerabilities
Read digest- CVE-2026-74820 — CVSS 10.0 — Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause in ServiceNow — A CVSS 10.0 unauthenticated SQL injection flaw in ServiceNow's dynamic schema ORDER BY clause could allow attackers to manipulate queries without credentials.
- CVE-2026-18885 — CVSS 10.0 — Unauthenticated Remote Code Execution in GraphQL Composite Data API in ServiceNow — A CVSS 10.0 unauthenticated RCE in ServiceNow's GraphQL Composite Data API enables remote attackers to execute arbitrary code on affected instances.
- CVE-2026-18886 — CVSS 10.0 — Unauthenticated Privilege Escalation via System Configuration Image Upload in ServiceNow — A CVSS 10.0 unauthenticated privilege escalation in ServiceNow allows attackers to gain elevated permissions through a system configuration image upload.
- Unitree G1 EDU Firmware Exposes Unauthenticated Bluetooth Root RCE — CVE-2026-76639 gives attackers within Bluetooth range root-level remote code execution on Unitree G1 EDU humanoid robots running firmware through 1.5.2.
Threat Research & Deep Dives
Salt Typhoon Targeted Telecom Infrastructure for Long-Term Visibility
Read digest- Salt Typhoon Targeted Telecom Infrastructure for Long-Term Communications Visibility — Salt Typhoon compromised U.S. telecom infrastructure to collect communications intelligence, accessing call-record metadata and lawful-investigative information.
- CVE-2026-81700 — openssl_encrypt Signature Bypass Leads to Plugin Execution — A CVSS 9.3 signature bypass in openssl_encrypt enables unauthenticated plugin execution on affected systems.
- CVE-2026-81707 — openssl_encrypt ANSI Escape Sequence Injection — A CVSS 9.3 ANSI escape sequence injection flaw in openssl_encrypt could allow attackers to manipulate terminal output and execution.
Active Exploits & Incidents
Attackers Exploit ownCloud Flaw to Steal Philippine Nuclear Data
Read digest- Attackers Exploit ownCloud CVE-2023-49105 to Steal Philippine Nuclear Data — Attackers forged pre-signed WebDAV requests to steal reactor databases and credentials from a Philippine nuclear research agency.
- CVE-2026-53362 enables Linux kernel privilege escalation via IPv6 — A Linux kernel IPv6 subsystem flaw allows privilege escalation across systems from vendors including SUSE and Red Hat.
- CVE-2026-66384 lets authenticated Artifactory users write outside Docker cache paths — An improper pathname limitation in JFrog Artifactory lets authenticated users write outside intended Docker cache directories.
- GitLab patches Duo Claude AI agent flaw enabling CI command execution — An authenticated developer could execute arbitrary CI pipeline commands through the Duo Claude AI agent in GitLab Enterprise Edition.
Active Exploits & Incidents
Australia Charges Two Alleged TeamPCP Hackers Over Supply-Chain
Read digest- Australia Charges Two Alleged TeamPCP Hackers Over Supply-Chain Attacks — Two alleged TeamPCP members were arrested for injecting malicious code into open-source packages, compromising over 1,000 organizations worldwide.
- Hackers access data of 8.7 million customers at three UK airports — Data of 8.7 million customers from Manchester Airports Group was exposed in a cyberattack affecting three UK airports.
- Russian-linked hackers target senior EU officials on Signal and WhatsApp — Russian-linked hackers used phishing on Signal and WhatsApp to hijack messaging accounts of senior EU officials.
- Russian-Speaking Hackers Used Cursor AI in Intrusions Against Seven Companies — Russian-speaking hackers leveraged Cursor AI to plan and execute intrusions against companies across multiple industries.
Active Exploits & Incidents
Aurora Affiliate Used AI to Attack More Than 20 Organizations
Read digest- Aurora Affiliate Used AI to Attack More Than 20 Organizations — A Russian-speaking Aurora ransomware affiliate used Cursor AI to plan intrusions against more than 20 organizations across nine countries from April through July 2026.
- Two alleged TeamPCP hackers charged in Australia — Australian authorities charged two alleged TeamPCP members over supply-chain attacks that compromised more than 1,000 organizations and stole 500,000-plus credentials.
- PaperCut issues urgent security advisory for all NG/MF versions — PaperCut issued an urgent security advisory affecting all NG and MF versions, with indicators of compromise included.
- SparkRAT Campaign Targets Cambodia Using Vulnerable OPSWAT Driver — A Cambodia-focused campaign abused a vulnerable OPSWAT driver and signed Tencent binaries to deploy SparkRAT across multiple sectors.
Active Exploits & Incidents
Pro-Russian group claims DDoS attack on Norway’s public digital
Read digest- Pro-Russian group claims DDoS attack on Norway’s public digital services — A DDoS attack disrupted Norway’s shared government digital services including ID-porten, affecting millions of users.
- ATF confirms standalone system breach after Qilin ransomware claim — ATF confirmed a breach of a standalone system with no evidence of enterprise network compromise.
- Russian-Linked Groups Use Fake Google Drive Pages to Hijack Accounts — Russian-linked groups hijack targeted accounts using fake cloud-storage pages and OAuth abuse.
- ESET Identifies GuardBreaker LLM Safety-Evasion Technique in Ukraine Attack — Russia-aligned UAC-0099 used GuardBreaker to evade AI malware analysis in a Ukraine-targeted campaign.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check