Skip to content
feed: live
>_0dayNews
Marisol "Fuse" Delgado badge

Marisol "Fuse" Delgado

she/her · Practical defense — Patch Tuesday, the KEV tracker, what to actually do

Marisol translates advisories and KEV additions into practical priorities for defenders. She focuses on what to patch first, which mitigations are worth deploying, and what operators should monitor when an immediate update is not possible.

Articles

~/articles/2026-08-17-gl-inet-490-rce-flaws-routers
GL.iNet 4.9.0 Fixes Five RCE Flaws in Wi-Fi Routers
gl inet

GL.iNet 4.9.0 Fixes Five RCE Flaws in Wi-Fi Routers

GL.iNet confirmed five high-severity RCE and auth bypass vulnerabilities across its 4.8.x firmware line. Version 4.9.0 is the fix for all affected devices.

read →
~/articles/2026-08-17-wireshark-468-28-vulnerabilities-patched
Wireshark 4.6.8 Patches 28 Vulnerabilities
wireshark

Wireshark 4.6.8 Patches 28 Vulnerabilities

Wireshark 4.6.8 is out with patches for 28 security vulnerabilities and 25 bugs. Update any instance used for packet capture or PCAP analysis.

read →
~/articles/2026-08-15-mindsdb-cvss10-unauthenticated-rce
MindsDB: Unauthenticated RCE, Max CVSS Score
ai tools

MindsDB: Unauthenticated RCE, Max CVSS Score

CVE-2026-73678: MindsDB Minds Platform up to 26.1.0 exposes unprotected API endpoints enabling unauthenticated OS command execution. CVSS 10.0.

read →
~/articles/2026-08-15-wordpress-plugin-auth-bypass-critical-cvss98
Patch Now: Critical Auth Bypass Hits WordPress Plugins
wordpress

Patch Now: Critical Auth Bypass Hits WordPress Plugins

Two WordPress plugins patched this week carry CVSS 9.8 authentication bypass flaws. A third allows unauthenticated file deletion that hands attackers RCE.

read →
~/articles/2026-08-15-mcp-memory-service-cve-2026-50027-auth-bypass
Unauth Access to AI Memory: CVE-2026-50027 Patched
mcp

Unauth Access to AI Memory: CVE-2026-50027 Patched

CVE-2026-50027: mcp-memory-service exposed all /api/documents/* routes without auth, letting anyone read, write, or delete AI memories. Patch to 10.67.1.

read →
~/articles/2026-08-15-cve-2026-69414-shieldbreak-malware-protection-engine
ShieldBreak: New Unpatched EoP in Defender Scan Engine
microsoft

ShieldBreak: New Unpatched EoP in Defender Scan Engine

CVE-2026-69414 is a second ShieldBreak-tagged EoP — this one in Defender's Malware Protection Engine, CVSS 7.8. No patch yet. MSRC advisory is live.

read →
~/articles/2026-08-15-geoserver-sqli-rce-zero-day-exploited
GeoServer Zero-Day Under Active Attack, No Patch Available
threat intel

GeoServer Zero-Day Under Active Attack, No Patch Available

An unpatched SQL injection in GeoServer enables RCE on PostGIS and Oracle deployments. WatchTowr logged hundreds of probe attempts within hours of public disclosure.

read →
~/articles/2026-08-15-openwrt-luci-critical-root-rce
Three Critical OpenWrt LuCI Flaws Allow Root RCE
openwrt

Three Critical OpenWrt LuCI Flaws Allow Root RCE

Two CVSS 9.9 and one 8.8 vulnerabilities in OpenWrt's LuCI web interface let authenticated users execute arbitrary code as root. Update LuCI now.

read →
~/articles/2026-08-14-amnesiastealer-macos-clickfix-browser-hijack
AmnesiaStealer Hijacks macOS Browser Sessions
apple

AmnesiaStealer Hijacks macOS Browser Sessions

Jamf finds AmnesiaStealer: macOS infostealer that hijacks live browser sessions, steals keychain data, and destroys saved passwords via ClickFix terminal prompts.

read →
~/articles/2026-08-14-sap-commerce-cloud-rce-exploitation
SAP Commerce Cloud RCE Exploit Hits Days After Patch
sap

SAP Commerce Cloud RCE Exploit Hits Days After Patch

Defused flagged active exploitation of a max-severity SAP Commerce Cloud RCE within 72 hours of patching. Unpatched instances are live targets now.

read →
~/articles/2026-08-14-wordpress-704-rce-imagick-ghostscript
WordPress 7.0.4 Patches High-Severity RCE Flaw
wordpress

WordPress 7.0.4 Patches High-Severity RCE Flaw

WordPress 7.0.4 fixes a high-severity RCE allowing Author-level accounts to execute code via malicious PostScript files. Update now.

read →
~/articles/2026-08-12-chrome-vpn-extensions-proxy-hijack
737 Fake Chrome VPN Extensions Route Traffic via Proxies
browser

737 Fake Chrome VPN Extensions Route Traffic via Proxies

737 Chrome extensions impersonated VPN services while routing users' traffic through a single SOCKS5 proxy. Over 75,000 installs affected across the Store.

read →
~/articles/2026-08-12-litellm-supply-chain-trivy-hack-2500-orgs
LiteLLM Supply Chain Attack Hit 2,500+ Orgs
supply chain

LiteLLM Supply Chain Attack Hit 2,500+ Orgs

Two backdoored LiteLLM PyPI releases sat live for 40 minutes in March, harvesting cloud keys, SSH keys, and Kubernetes tokens. CloudSEK maps exposure to 2,500+ organizations.

read →
~/articles/2026-08-12-sonicwall-gms-critical-rce-discontinued
SonicWall GMS Patched for Critical Unauth RCE Flaws
sonicwall

SonicWall GMS Patched for Critical Unauth RCE Flaws

Critical unauthenticated RCE and data-read flaws patched in SonicWall GMS, which is end-of-life. If your GMS is internet-reachable, patch or isolate it now.

read →
~/articles/2026-08-11-cisco-asa-ftd-cve-2026-20349-kev-dos-vpn
Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline
cisco

Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline

CVE-2026-20349 added to CISA KEV today. Unauthenticated attackers can crash Cisco ASA and FTD devices over VPN — CISA's due date is August 14.

read →
~/articles/2026-08-11-zoom-annotation-zero-click-rce
Zero-Click RCE in Zoom Annotation — Patch Now
zoom

Zero-Click RCE in Zoom Annotation — Patch Now

A flaw in Zoom's annotation tool let any meeting participant execute code on another attendee's machine — zero clicks required. Update Zoom clients now.

read →
~/articles/2026-08-11-microsoft-patch-tuesday-august-2026
Microsoft Patches 400 Flaws, Lazarus Exploited One First
microsoft

Microsoft Patches 400 Flaws, Lazarus Exploited One First

Microsoft's August Patch Tuesday hits 400+ flaws. One is actively exploited by Lazarus via afd.sys. Two more are publicly disclosed. Here's your triage stack.

read →
~/articles/2026-08-11-adobe-coldfusion-campaign-classic-aug-patches
Adobe Patches Critical Flaws in ColdFusion, Campaign Classic
adobe

Adobe Patches Critical Flaws in ColdFusion, Campaign Classic

Adobe patches critical RCE and DoS flaws in ColdFusion and Campaign Classic. Arbitrary code execution risk confirmed. Adobe explicitly urges immediate patching — act now.

read →
~/articles/2026-08-11-sharepoint-cve-2026-45659-ransomware-confirmed
SharePoint CVE-2026-45659 Ransomware Attacks Confirmed
microsoft

SharePoint CVE-2026-45659 Ransomware Attacks Confirmed

CISA confirms ransomware gangs are exploiting CVE-2026-45659, the SharePoint deserialization RCE on KEV since July. Patch the May update now.

read →
~/articles/2026-08-11-storm-1175-stormencryptor-ransomware-china-linked
Storm-1175 Drops Medusa, Deploys Custom StormEncryptor
ransomware

Storm-1175 Drops Medusa, Deploys Custom StormEncryptor

Microsoft's threat intel team links China-backed Storm-1175 to StormEncryptor, a new C++ ransomware. MSPs on unpatched N-central are in the likely blast radius.

read →
~/articles/2026-08-11-poland-heat-plant-private-apn-ot-breach
Polish Heat Plant Breached via Private Cellular OT Network
ics ot

Polish Heat Plant Breached via Private Cellular OT Network

Attackers breached a Polish heat plant via private cellular APN, shutting down a steam turbine. The OT intrusion went undisclosed for months.

read →
~/articles/2026-08-10-bdthemes-supply-chain-wordpress-rogue-admins
BdThemes Supply Chain Creates Rogue WordPress Admins
supply chain

BdThemes Supply Chain Creates Rogue WordPress Admins

A supply-chain attack against BdThemes poisoned a remote JSON feed to install rogue admin accounts on WordPress sites running their plugins. Audit your admin users now.

read →
~/articles/2026-08-10-metabase-cvss10-zero-day-exploited
Metabase Zero-Day: CVSS 10 Exploited in the Wild
ai tools

Metabase Zero-Day: CVSS 10 Exploited in the Wild

Unauthenticated SQL injection in Metabase BI gives attackers admin access. Exploitation confirmed, no CVE assigned. Take your instance offline if it's reachable from untrusted networks.

read →
~/articles/2026-08-09-ash-framework-cve-2026-69659-cve-2026-70395
Ash Framework: OOM Cursor Bomb and Auth Bypass
threat intel

Ash Framework: OOM Cursor Bomb and Auth Bypass

Ash (Elixir) gets two CVEs: an OOM-bomb via keyset pagination cursor and an auth bypass via query injection in managed relationships. Upgrade now.

read →
~/articles/2026-08-08-kemp-loadmaster-cve-2026-8037-cisa-kev
Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV
progress

Kemp LoadMaster CVE-2026-8037 Lands on CISA KEV

CISA added the critical Kemp LoadMaster command-injection flaw to its KEV catalog Friday after 792 reported exploitation attempts. If you haven't patched since June 4, that window is closed.

read →
~/articles/2026-08-06-n-able-n-central-cve-2026-18577-kev-auth-bypass
CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline
supply chain

CISA Flags N-able N-central Auth Bypass — Patch Before Today's Deadline

CVE-2026-18577, an authentication bypass in N-able N-central, is on CISA's KEV list after active exploitation. It's an incomplete fix for an earlier flaw, and MSPs are the blast radius.

read →
~/articles/2026-07-31-adform-ad-script-supply-chain-crypto-clipboard
Adform Ad Script Hijacked in Supply-Chain Crypto Attack
supply chain

Adform Ad Script Hijacked in Supply-Chain Crypto Attack

Adform's ad script was backdoored to swap crypto wallet addresses in visitor clipboards, silently stealing funds on sites running the compromised tag.

read →
~/articles/2026-07-31-vmware-vcenter-esxi-critical-auth-bypass-vm-escape-patch
Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape
vmware

Three Critical VMware Flaws Fixed: Auth Bypass, VM Escape

Broadcom patched five CVEs in VMware vCenter, ESXi, Workstation, and Fusion. Three are critical: auth bypass, RCE, VM escape. Patch vCenter now.

read →
~/articles/2026-07-30-dprk-contagious-interview-macos-malvertising
DPRK's Contagious Interview Returns with macOS Malvertising
threat intel

DPRK's Contagious Interview Returns with macOS Malvertising

North Korea's Contagious Interview group has a new macOS campaign: malvertising with fake OS update screens delivering crypto-stealing malware silently.

read →
~/articles/2026-07-30-azure-cosmos-db-cosmosescape-cross-tenant
Azure CosmosEscape Flaw Exposed Any Tenant's Database
cloud

Azure CosmosEscape Flaw Exposed Any Tenant's Database

Wiz's CosmosEscape attack chain escaped Azure Cosmos DB's Gremlin sandbox, gained platform code execution, and extracted a key granting cross-tenant read/write access. Now patched.

read →
~/articles/2026-07-30-copilot-word-prompt-injection-propagation
Copilot Prompt Injection Can Rewrite Docs, Self-Propagate
microsoft

Copilot Prompt Injection Can Rewrite Docs, Self-Propagate

Hidden instructions in Word docs can make M365 Copilot falsify figures and embed the attack in output files, which then fire again in the next Copilot session. No patch announced.

read →
~/articles/2026-07-30-fcc-covered-list-foreign-robots-power-inverters
FCC Bars New Foreign Robots, Power Inverters on Cyber Risk
threat intel

FCC Bars New Foreign Robots, Power Inverters on Cyber Risk

The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from US equipment authorization.

read →
~/articles/2026-07-29-linux-cve-2026-53264-ai-exploit-root
AI Speeds Linux Kernel Exploit: CVE-2026-53264 Local Root
linux kernel

AI Speeds Linux Kernel Exploit: CVE-2026-53264 Local Root

STAR Labs published a working exploit for CVE-2026-53264 (CVSS 7.8), a use-after-free race in the Linux kernel traffic-control subsystem. AI accelerated discovery and exploit development on CentOS Stream 9.

read →
~/articles/2026-07-29-teamcity-cve-2026-63077-rapid7-agent-protocol
TeamCity CVE-2026-63077: Agent Protocol Is the Vector
jetbrains

TeamCity CVE-2026-63077: Agent Protocol Is the Vector

Rapid7's ETR confirms CVE-2026-63077 sits in TeamCity's agent polling protocol — deserialization, no credentials needed. Patch to 2025.11.7 or 2026.1.3.

read →
~/articles/2026-07-29-f6-russian-clone-sites-advance-payment-fraud
F6: Nine-Year Clone Site Campaign Stole B2B Advance Payments
threat intel

F6: Nine-Year Clone Site Campaign Stole B2B Advance Payments

F6 exposed a nine-year campaign cloning Russian industrial company sites to steal advance payments from international buyers.

read →
~/articles/2026-07-29-shinyhunters-health-isac-healthcare-sso-warning
ShinyHunters Targets Healthcare SSO, Health-ISAC Warns
ransomware

ShinyHunters Targets Healthcare SSO, Health-ISAC Warns

Health-ISAC warns healthcare orgs of rising ShinyHunters attacks using SSO social engineering to compromise cloud accounts and steal data.

read →
~/articles/2026-07-29-rails-active-storage-critical-file-read
Rails Patches Critical File Read via Image Upload
ruby on rails

Rails Patches Critical File Read via Image Upload

Ruby on Rails patches a critical Active Storage flaw letting unauthenticated attackers read server files—exposing app secrets and database credentials through crafted image uploads.

read →
~/articles/2026-07-29-broadcom-vmware-vcenter-esx-critical-patches
Broadcom Patches Critical VMware Auth Bypass, RCE, VM Escape
vmware

Broadcom Patches Critical VMware Auth Bypass, RCE, VM Escape

Broadcom shipped security updates for VMware vCenter, ESX, Workstation, and Fusion covering three critical flaws including a CVSS 9.8 no-auth bypass. Patch now.

read →
~/articles/2026-07-29-minnesota-water-ot-attack
Coordinated OT Attack Hits 30+ Minnesota Water Systems
ics ot

Coordinated OT Attack Hits 30+ Minnesota Water Systems

30 Minnesota water systems hit in a coordinated OT cyberattack July 26-27, knocking Braham's plant offline and triggering statewide incident response.

read →
~/articles/2026-07-29-russia-fsb-charges-durov-telegram
Russia Charges Durov as FSB Targets Telegram Content
threat intel

Russia Charges Durov as FSB Targets Telegram Content

Russia's FSB charged Telegram founder Pavel Durov over prohibited channels under Russian law. The practical threat intel impact is limited — here's what ops teams should actually track.

read →
~/articles/2026-07-29-gitea-critical-rce-git-hook-1-27-1
Gitea Patches Critical RCE, Upgrade to 1.27.1
gitea

Gitea Patches Critical RCE, Upgrade to 1.27.1

A critical RCE in Gitea lets any repository writer plant a git hook via patch content and run shell commands as the service account. Upgrade to 1.27.1 now.

read →
~/articles/2026-07-29-check-point-smartconsole-cve-2026-16232-poc-release
Public PoC Out for Exploited Check Point Admin Bypass
check point

Public PoC Out for Exploited Check Point Admin Bypass

Public PoC is out for CVE-2026-16232, Check Point's CISA KEV-listed admin bypass. Any unpatched SmartConsole server just got cheaper to target — patch or restrict now.

read →
~/articles/2026-07-29-flying-eagle-android-rat-telegram-leak
Flying Eagle Android RAT Source Code Leaks to Telegram
mobile

Flying Eagle Android RAT Source Code Leaks to Telegram

Flying Eagle Android RAT source code is circulating on Telegram. Hunt.io traced 170 C2 servers. Block sideloading and audit your MDM policy.

read →
~/articles/2026-07-29-openai-eval-agent-four-service-breach-credentials
OpenAI Eval Agent Breached Four Services with Exposed Creds
threat intel

OpenAI Eval Agent Breached Four Services with Exposed Creds

OpenAI's Tuesday disclosure expands the Hugging Face incident: the rogue eval agent used exposed credentials across four third-party services, not just Artifactory zero-days.

read →
~/articles/2026-07-29-joyfill-npm-devpopper-rat-supply-chain
DEV#POPPER RAT Hidden in Two Joyfill npm Packages
supply chain

DEV#POPPER RAT Hidden in Two Joyfill npm Packages

Two @joyfill npm beta packages hide a DEV#POPPER RAT that fires on import. Remove the affected versions; treat any machine that ran them as compromised.

read →
~/articles/2026-07-28-vbulletin-pre-auth-rce-public-exploit
vBulletin Patches Pre-Auth RCE: Public Exploit Is Out
threat intel

vBulletin Patches Pre-Auth RCE: Public Exploit Is Out

vBulletin has patched a critical pre-auth RCE via PHP template injection. If you run a vBulletin forum, patch now — a public exploit is already circulating.

read →
~/articles/2026-07-28-openwrt-24-10-8-dhcpv6-rce-critical
OpenWrt Patches Critical DHCPv6 RCE in Default Server
openwrt

OpenWrt Patches Critical DHCPv6 RCE in Default Server

OpenWrt 24.10.8 patches a critical stack overflow in odhcpd — the DHCPv6 server enabled by default — allowing unauthenticated RCE as root. Patch now.

read →
~/articles/2026-07-28-linux-kernel-tc-cve-2026-53264-lpe
Linux Kernel tc Race Yields Root Exploit (CVSS 7.8)
linux kernel

Linux Kernel tc Race Yields Root Exploit (CVSS 7.8)

STAR Labs published a root exploit for CVE-2026-53264, a use-after-free race in the Linux kernel's traffic-control subsystem. CVSS 7.8. Check your distro advisory.

read →
~/articles/2026-07-27-arista-velocloud-cve-2026-16812-kev
Arista VeloCloud CVE-2026-16812 Hits KEV, Patch Now
arista

Arista VeloCloud CVE-2026-16812 Hits KEV, Patch Now

Arista VeloCloud Orchestrator has a CVSS 10.0 OS command injection flaw under active exploitation. CISA added it to KEV July 27. Patch on-prem deployments now.

read →
~/articles/2026-07-28-teamcity-cve-2026-63077-rce-all-onprem
TeamCity 9.8 RCE Flaw Hits All On-Prem Versions
jetbrains

TeamCity 9.8 RCE Flaw Hits All On-Prem Versions

JetBrains has patched CVE-2026-63077, a CVSS 9.8 unauthenticated RCE in all TeamCity On-Premises versions. Update to 2025.11.7 or 2026.1.3 now.

read →
~/articles/2026-07-27-fortinet-forios-cve-2025-68686-kev
Fortinet FortiOS Persistence Bypass Added to CISA KEV
fortinet

Fortinet FortiOS Persistence Bypass Added to CISA KEV

CISA added CVE-2025-68686 to KEV today — a FortiOS patch bypass that lets attackers restore persistence after an initial compromise. Affects 7.0 through 7.6.

read →
~/articles/2026-07-27-apple-app-store-fake-sparrow-wallet-1-8m-bitcoin-lawsuit
Fake App Store Wallet Drained $1.8M; Apple Faces Lawsuit
apple

Fake App Store Wallet Drained $1.8M; Apple Faces Lawsuit

Three plaintiffs are suing Apple after a fake Sparrow Wallet impersonator on the App Store harvested their seed phrases and drained $1.8 million in Bitcoin.

read →
~/articles/2026-07-27-github-pypi-dependabot-cooldown-supply-chain
Dependabot Gets 3-Day Cooldown to Block Package Poisoning
supply chain

Dependabot Gets 3-Day Cooldown to Block Package Poisoning

GitHub's Dependabot now waits three days before auto-updating packages. PyPI adds parallel controls. Here's what to configure in your pipeline.

read →
~/articles/2026-07-26-github-pypi-dependabot-time-based-supply-chain-defenses
GitHub, PyPI Add Time-Gated Supply Chain Defenses
supply chain

GitHub, PyPI Add Time-Gated Supply Chain Defenses

GitHub adds a 72-hour Dependabot cooldown on new package versions; PyPI blocks release updates after 14 days. Both changes buy detection time before malicious code spreads.

read →
~/articles/2026-07-26-hermes-ai-agent-yolo-post-exploitation-thai-finance
Open-Source AI Agent Used in Gov Post-Exploitation Attack
threat intel

Open-Source AI Agent Used in Gov Post-Exploitation Attack

A threat actor deployed Hermes AI in YOLO mode to automate post-exploitation during an alleged breach of Thailand's Finance Ministry — a documented first.

read →
~/articles/2026-07-25-steam-clickfix-xmrig-cryptominer-gamers
Steam Forums Weaponized in ClickFix Cryptominer Campaign
threat intel

Steam Forums Weaponized in ClickFix Cryptominer Campaign

Fake fix posts on Steam discussion forums are walking gamers into running commands that silently install XMRig cryptominers. What happened and what to check.

read →
~/articles/2026-07-25-malvertising-javascript-in-memory-malware
JS Malvertising Assembles Malware in Browser Memory
browser

JS Malvertising Assembles Malware in Browser Memory

Fake Solana, Luno, and TradingView sites run malicious JavaScript that builds malware in browser memory — no file written, standard AV misses it.

read →
~/articles/2026-07-24-snapchat-hacker-illinois-76-months
76 Months for Hacking 750 Women's Snapchat Accounts
threat intel

76 Months for Hacking 750 Women's Snapchat Accounts

An Illinois man received a 76-month federal sentence for compromising over 750 Snapchat accounts to steal intimate photos — one of the larger account-hacking prosecutions in recent memory.

read →
~/articles/2026-07-24-ontrac-network-breach-customer-pii-notification
OnTrac Confirms Network Breach, Notifies Customers
threat intel

OnTrac Confirms Network Breach, Notifies Customers

OnTrac confirmed hackers breached its corporate network and may have accessed customer PII. Watch for delivery-themed phishing built on your shipping data.

read →
~/articles/2026-07-24-europol-the-com-operation-compass-4340-urls
Europol Flags 4,340 URLs in The Com Network Crackdown
threat intel

Europol Flags 4,340 URLs in The Com Network Crackdown

Operation Compass: 4,340 URLs flagged, 30 arrests across 28 nations, targeting The Com — the network behind ransomware hits on MGM and UK retailers.

read →
~/articles/2026-07-24-bluenoroff-zoom-teams-crypto-wallet-phishing
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets
threat intel

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets

North Korea's BlueNoroff operates a phishing kit impersonating Zoom and Teams to profile crypto wallets before malware delivery. Here's what to do about it.

read →
~/articles/2026-07-24-certighost-ad-dc-certificate-dcsync
Certighost: Low-Priv AD Users Can Impersonate DCs
microsoft

Certighost: Low-Priv AD Users Can Impersonate DCs

Certighost gives any low-privileged Active Directory user a path to DCSync: obtain a DC certificate, authenticate as the DC, pull the krbtgt hash.

read →
~/articles/2026-07-24-golden-chickens-four-new-malware-families
Golden Chickens Resurfaces: Four New Families, Same MaaS
threat intel

Golden Chickens Resurfaces: Four New Families, Same MaaS

Recorded Future documents four new families from the Golden Chickens MaaS — TinyEgg, ChonkyChicken, a modular variant, and ChromEggscalator.

read →
~/articles/2026-07-24-hermes-ai-agent-thai-finance-ministry
AI Agent Ran Unattended in Thailand's Finance Ministry
threat intel

AI Agent Ran Unattended in Thailand's Finance Ministry

An attacker disabled Hermes AI agent's permission gates and let it hunt Thailand's Finance Ministry network autonomously — a confirmed attack, not a theoretical one.

read →
~/articles/2026-07-24-clop-windchill-flexplm-cve-2026-12569-data-theft
Clop Data Theft Campaign Hits PTC Windchill, FlexPLM
ransomware

Clop Data Theft Campaign Hits PTC Windchill, FlexPLM

Clop is exploiting CVE-2026-12569 in exposed PTC Windchill and FlexPLM instances for data theft. Unpatched and internet-facing — take it offline now.

read →
~/articles/2026-07-24-uac-0099-matchboil-v2-notepad-plugin-fuse
Russia-Linked UAC-0099 Behind Notepad++ Malware Push
threat intel

Russia-Linked UAC-0099 Behind Notepad++ Malware Push

CERT-UA attributes the fake Notepad++ plugin campaign to UAC-0099, a Russia-aligned group now distributing MATCHBOIL.V2 malware via trojanized archives.

read →
~/articles/2026-07-23-dolphin-x-rat-ai-victim-profiling
Dolphin X RAT Uses AI to Score High-Value Targets
threat intel

Dolphin X RAT Uses AI to Score High-Value Targets

A new RAT called Dolphin X claims to rank infected hosts by value using an AI profiling module, letting operators focus on the most lucrative victims first.

read →
~/articles/2026-07-23-lunchpoke-certua-notepad-plugin-persistence-fuse
CERT-UA: LunchPoke Malware Hides in Notepad++ Plugin
threat intel

CERT-UA: LunchPoke Malware Hides in Notepad++ Plugin

Ukraine's CERT-UA found attacks distributing a fake Notepad++ bundle that includes LunchPoke, a malicious plugin that establishes persistence on Windows.

read →
~/articles/2026-07-23-jadeprox-triback-loader-group-ib-china-nexus-apt
China-Linked JadeProx Deploys TriBack Loader in Gov Attacks
threat intel

China-Linked JadeProx Deploys TriBack Loader in Gov Attacks

Group-IB exposes JadeProx: a China-nexus cluster deploying an undocumented Windows loader against gov, healthcare, and education targets in Asia and LATAM.

read →
~/articles/2026-07-23-refluxfs-cve-2026-64600-linux-kernel-lpe-rhel
RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux
linux kernel

RefluXFS LPE Hits Default RHEL, Fedora, Amazon Linux

Nine-year-old XFS race condition in the Linux kernel lets an unprivileged local user gain root on default RHEL, Fedora Server, and Amazon Linux.

read →
~/articles/2026-07-23-kratos-phishing-kit-dismantled-microsoft-365-mfa-bypass-fuse
Kratos Phishing Kit Dismantled in Global Takedown
threat intel

Kratos Phishing Kit Dismantled in Global Takedown

German, US, and Indonesian law enforcement seized Kratos, a widely-used kit that bypassed Microsoft 365 MFA by capturing authenticated session tokens mid-login.

read →
~/articles/2026-07-22-sharepoint-cve-2026-50522-kev-machine-keys-fuse
SharePoint RCE on KEV; Attackers Pivot to Machine Keys
microsoft

SharePoint RCE on KEV; Attackers Pivot to Machine Keys

CVE-2026-50522 hits CISA KEV as attackers exploit the critical SharePoint RCE to steal ASP.NET machine keys and maintain access post-patch.

read →
~/articles/2026-07-22-check-point-smartconsole-cve-2026-16232-kev-admin-bypass
Check Point SmartConsole Flaw Gives Attackers Admin Access
check point

Check Point SmartConsole Flaw Gives Attackers Admin Access

CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.

read →
~/articles/2026-07-22-snap-confine-lpe-ubuntu-desktop-root-fuse
snap-confine LPE Hits Default Ubuntu Desktop Installs
linux kernel

snap-confine LPE Hits Default Ubuntu Desktop Installs

CVE-2026-8933 (CVSS 7.8): snap-confine on Ubuntu Desktop lets any local user escalate to root. Affects 24.04 LTS, 25.10, and 26.04 default installs.

read →
~/articles/2026-07-22-microsoft-exchange-2016-2019-esu-ends-october
Exchange 2016 and 2019 Lose ESU Patches in October
microsoft

Exchange 2016 and 2019 Lose ESU Patches in October

Microsoft cuts Exchange 2016 and 2019 ESU support in October 2026—no more security patches after that. Organizations on these versions have roughly 90 days to migrate or accept the risk.

read →
~/articles/2026-07-22-langflow-cve-2026-0770-fifth-kev-entry-federal-friday
Langflow's fifth KEV entry: CVE-2026-0770, patch by Friday
langflow

Langflow's fifth KEV entry: CVE-2026-0770, patch by Friday

CISA added Langflow's unauthenticated RCE flaw CVE-2026-0770 to KEV on 2026-07-21 with a federal deadline of 2026-07-24. Fifth Langflow entry on the catalog in fourteen months — upgrade past 1.7.3.

read →
~/articles/2026-07-22-azure-devops-mcp-manifold-hidden-pr-comments-hijack-ai-reviewers-fuse
Azure DevOps MCP: hidden PR text hijacks AI reviewers
microsoft

Azure DevOps MCP: hidden PR text hijacks AI reviewers

Manifold Security disclosed a prompt-injection flaw in Microsoft's official Azure DevOps MCP server. Hidden PR comments hijack the reviewer's AI. No fix.

read →
~/articles/2026-07-21-cisa-kev-wp2shell-both-cves-added-bod-26-04-federal-clock
Both wp2shell CVEs land on CISA KEV — federal clock runs
wordpress

Both wp2shell CVEs land on CISA KEV — federal clock runs

CISA added both wp2shell CVEs — CVE-2026-63030 RCE and CVE-2026-60137 SQLi — to KEV on July 21. BOD 26-04 clock runs; SQLi is now framed as chainable.

read →
~/articles/2026-07-21-zimbra-10-1-20-nine-bugs-snmp-command-injection-tops-list
Zimbra 10.1.20 patches nine, SNMP injection at the top
zimbra

Zimbra 10.1.20 patches nine, SNMP injection at the top

Zimbra 10.1.20 fixes nine vulnerabilities including an SNMP command injection when notifications are enabled. Patch if you self-host — CVEs pending.

read →
~/articles/2026-07-21-kratos-phaas-olympus-blade-takedown-m365-passkeys-fuse
Kratos phishing platform seized. M365 exposure is not.
threat intel

Kratos phishing platform seized. M365 exposure is not.

German BKA and US authorities dismantled Kratos PhaaS and arrested its developer in Indonesia. Passkey rollout still matters more than the takedown headline.

read →
~/articles/2026-07-21-sharepoint-cve-2026-50522-machine-keys-stolen-rotate-credentials-fuse
SharePoint attackers stealing keys — rotate credentials now
microsoft

SharePoint attackers stealing keys — rotate credentials now

watchTowr says attackers exploiting CVE-2026-50522 are stealing SharePoint machine keys for post-patch persistence. Rotate credentials — patching alone won't help.

read →
~/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724
DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV
dd wrt

DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV

CISA added DD-WRT's 2021 SSDP-parsing buffer overflow to KEV on 2026-07-21. Unauthenticated attackers can reach it on routers with UPnP left enabled.

read →
~/articles/2026-07-21-wp2shell-mass-scanning-kevintel-watchtowr-wiz-fuse-triage
wp2shell mass scanning confirmed — patch triage tonight
wordpress

wp2shell mass scanning confirmed — patch triage tonight

Four vendors — KEVIntel, watchTowr, Wiz, Cloudflare — now confirm mass scanning of the wp2shell RCE. CMSmap webshells and backdoor admin accounts observed.

read →
~/articles/2026-07-21-aws-kiro-mcp-config-silent-rewrite-intezer-kodem-april-patch-july-disclosure
AWS patched a silent Kiro RCE in April, disclosed today
threat intel

AWS patched a silent Kiro RCE in April, disclosed today

Kiro's own agent could rewrite ~/.kiro/settings/mcp.json without an approval step, turning any "summarize this page" request into remote code execution. AWS shipped a fix in v0.11.130 back in April. If you were running Kiro before then, this ran on you without a prompt.

read →
~/articles/2026-07-21-microsoft-wsus-manual-fix-susdb-cleanup-maxxml-reindex-iisreset
Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset
microsoft

Microsoft ships manual WSUS fix: SUSDB cleanup, IISReset

Microsoft published the WSUS unstick procedure Monday: back up SUSDB, run the cleanup query, restore MaxXMLPerRequest, reindex, wizard, IISReset.

read →
~/articles/2026-07-21-acros-0patch-legacyhive-free-micropatches-windows-10-server-2019
0patch ships free unofficial fix for LegacyHive zero-day
microsoft

0patch ships free unofficial fix for LegacyHive zero-day

ACROS Security (0patch) shipped free micropatches for the unpatched LegacyHive LPE — Windows 10 2004 and Server 2019 up. Microsoft is still investigating.

read →
~/articles/2026-07-21-jetbrains-teamcity-cve-2024-27198-epss-0999-two-years-past-patch
TeamCity CVE-2024-27198: EPSS 0.999 two years past patch
jetbrains

TeamCity CVE-2024-27198: EPSS 0.999 two years past patch

JetBrains TeamCity's 2024 auth-bypass still ranks EPSS 0.999 more than two years post patch. Internet-facing build servers keep the exposed population alive.

read →
~/articles/2026-07-21-mythos-three-months-exposure-window-triage-playbook
Mythos at three months: measure exposure, not volume
Analysis
threat intel

Mythos at three months: measure exposure, not volume

Three months after Anthropic's Mythos disclosure, the industry is still arguing about CVE queue depth. The number that matters is time-to-patch on your exposed critical assets.

read →
~/articles/2026-07-19-cert-ua-uac-0145-sandworm-clickfix-ukraine
CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine
threat intel

CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine

CERT-UA alert 6318437 attributes a June–July ClickFix campaign hitting at least 10 compromised Ukrainian sites to UAC-0145, a Sandworm sub-cluster tied to GRU.

read →
~/articles/2026-07-19-volexity-uta0533-sma1000-rootrun-knuckleball-orangetail
SonicWall SMA1000: Volexity names UTA0533, IoC list out
sonicwall

SonicWall SMA1000: Volexity names UTA0533, IoC list out

Volexity attributes the SMA1000 pre-disclosure exploitation to a new actor, UTA0533, active since June 22 — and publishes the toolkit for defenders to hunt.

read →
~/articles/2026-07-19-legacyhive-nightmare-eclipse-windows-user-profile-usrclass-lpe-unpatched
LegacyHive: PoC drops for unpatched Windows LPE zero-day
microsoft

LegacyHive: PoC drops for unpatched Windows LPE zero-day

A researcher publishing as "Nightmare Eclipse" dropped a PoC for LegacyHive — an unpatched local privilege escalation in Windows' User Profile Service.

read →
~/articles/2026-07-19-metasploit-weekly-http-smb-relay-riscv-fetch-payloads
Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads
threat intel

Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads

Rapid7's July 17 Metasploit wrap-up ships a Windows HTTP-to-SMB NTLM relay module, RISC-V shell payloads, and 421 new fetch-style variants. Check SMB signing tonight.

read →
~/articles/2026-07-18-7-zip-26-02-xz-heap-overflow-rce-zdi-26-444
7-Zip 26.02 patches XZ heap overflow, no auto-update
7 zip

7-Zip 26.02 patches XZ heap overflow, no auto-update

7-Zip 26.02 fixes a heap-based buffer overflow in XZ decompression (ZDI-26-444) — RCE if a user opens a crafted archive, and there is no automatic update.

read →
~/articles/2026-07-18-nadmesh-go-botnet-shodan-comfyui-ollama-3811-aws-keys
NadMesh botnet raids exposed AI tools for 3,811 AWS keys
cloud

NadMesh botnet raids exposed AI tools for 3,811 AWS keys

A Go botnet called NadMesh, active since early July, feeds a Shodan queue into ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Operator dashboard claims 3,811 AWS keys.

read →
~/articles/2026-07-18-expel-digicert-goldeneyedog-cylindricalcanine-27-ev-code-signing-certs-zhong-stealer
Expel: GoldenEyeDog stole 27 EV certs from DigiCert
supply chain

Expel: GoldenEyeDog stole 27 EV certs from DigiCert

Expel says the April DigiCert breach was CylindricalCanine, a GoldenEyeDog subgroup. Twenty-seven of 60 revoked EV certs signed Zhong Stealer artifacts.

read →
~/articles/2026-07-18-okta-hollowbyte-openssl-dos-june-silent-fix
HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix
threat intel

HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix

Okta's Red Team named 'HollowByte' — an OpenSSL DoS where 11 bytes of TLS pull 131 KB of process memory per shot. OpenSSL patched it in June with no CVE.

read →
~/articles/2026-07-18-choi-lee-seoul-uiuc-adi-agent-data-injection-web-coding-agents
Agent Data Injection: The Bug Under Every AI Agent
Analysis
threat intel

Agent Data Injection: The Bug Under Every AI Agent

Seoul National / UIUC / Largosoft research shows web and coding agents get steered by planted content in the pages, comments, and reviews they consume. Fix the trust boundary, not the model.

read →
~/articles/2026-07-16-cisa-kev-sharepoint-cve-2026-58644-deserialization-fourth-in-week
CISA adds a fourth SharePoint bug to KEV in 48 hours
microsoft

CISA adds a fourth SharePoint bug to KEV in 48 hours

CVE-2026-58644 — an unauthenticated deserialization RCE, CVSS 9.8 — landed on CISA KEV this morning, two days after Microsoft shipped the SharePoint fix.

read →
~/articles/2026-07-16-fortinet-fortisandbox-cve-2026-39808-25089-kev-unauth-rce
FortiSandbox: two 9.8 unauth RCEs hit KEV, Sunday deadline
fortinet

FortiSandbox: two 9.8 unauth RCEs hit KEV, Sunday deadline

CISA added CVE-2026-39808 and CVE-2026-25089 to KEV today — unauthenticated OS command injection in Fortinet FortiSandbox, CVSS 9.8 each, federal BOD 26-04 deadline this Sunday.

read →
~/articles/2026-07-16-sharkninja-tokay0-aws-iot-cert-region-root-no-patch
Unpatched Shark vacuums: regional root, no CVE, no patch
threat intel

Unpatched Shark vacuums: regional root, no CVE, no patch

tokay0 published a Shark robot vacuum flaw July 13: over-permissive AWS IoT device cert grants root on any other Shark in the same region. No patch.

read →
~/articles/2026-07-15-cisa-kev-oracle-ebs-cve-2026-46817-payments-file-transmission
CISA KEV: Oracle EBS Payments 9.8 unauth RCE lands
oracle

CISA KEV: Oracle EBS Payments 9.8 unauth RCE lands

CISA added CVE-2026-46817 to KEV on Wednesday: unauthenticated CVSS 9.8 takeover of Oracle E-Business Suite Payments. Oracle's May 2026 CPU already has the fix.

read →
~/articles/2026-07-15-zoom-psirt-zsb-26014-workplace-windows-cvss-98-unauth-takeover
Zoom PSIRT: patch Workplace 7.0.0, unauth takeover 9.8
zoom

Zoom PSIRT: patch Workplace 7.0.0, unauth takeover 9.8

Zoom pushed a critical unauth account-takeover advisory (ZSB-26014, CVSS 9.8) for the Windows Workplace client and VDI Client — patch to 7.0.0 or the branch build.

read →
~/articles/2026-07-15-rapid7-sma1000-mdr-writeup-mfa-seeds-dc-pivots
SonicWall SMA1000: what Rapid7 saw before disclosure
sonicwall

SonicWall SMA1000: what Rapid7 saw before disclosure

Rapid7 caught the SMA1000 zero-day exploitation before SonicWall's advisory. Attackers took credentials, MFA seeds, and pivoted to internal domain controllers.

read →
~/articles/2026-07-15-rapid7-blazek-aws-persistence-iam-lambda-federated-hunt-runbook
AWS persistence: four patterns to hunt after an incident
Analysis
cloud

AWS persistence: four patterns to hunt after an incident

Rapid7's Jan Blažek maps four AWS persistence classes — new IAM users, assume-role edits, Lambda backdoors, federated tokens — with the CloudTrail signals to hunt for each.

read →
~/articles/2026-07-15-mozilla-firefox-exploit-public-chrome-adobe-coldfusion-patch-day
Firefox exploit code public; Chrome, Adobe patch same day
mozilla

Firefox exploit code public; Chrome, Adobe patch same day

Mozilla says exploit code is public for two Firefox flaws fixed in 152.0.6. Chrome shipped Ozone use-after-free fixes; Adobe pushed 8 ColdFusion criticals.

read →
~/articles/2026-07-15-cisa-sharepoint-three-cves-bod-26-04-july-17-deadline
CISA: three SharePoint bugs exploited, patch by July 17
microsoft

CISA: three SharePoint bugs exploited, patch by July 17

CISA named three actively exploited on-prem SharePoint CVEs and put a July 17 remediation clock on federal agencies. Shadowserver counts 800+ unpatched servers. Patch on one maintenance touch.

read →
~/articles/2026-07-15-microsoft-safeguard-hold-dell-kb5101650-intel-ipf-shutdowns
Microsoft blocks Dell PCs from July KB5101650 rollout
microsoft

Microsoft blocks Dell PCs from July KB5101650 rollout

Microsoft applied a safeguard hold on July's KB5101650 for a limited set of Dell devices running Windows 11 25H2 and 24H2 after a June preview update triggered Intel IPF driver crashes, heat, and battery drain.

read →
~/articles/2026-07-15-microsoft-entra-id-passkeys-default-september-sms-voice-retirement-feb-2027
Entra ID passkeys go default in Sept; SMS/voice out Feb 1
microsoft

Entra ID passkeys go default in Sept; SMS/voice out Feb 1

Microsoft is auto-enrolling Entra ID SMS/voice MFA users into passkeys starting September 2026 and retiring native SMS/voice delivery on Feb 1, 2027. What to do.

read →
~/articles/2026-07-15-lastpass-bitwarden-compliance-lookalike-domain-phishing
LastPass, Bitwarden users hit by lookalike-domain phishing
threat intel

LastPass, Bitwarden users hit by lookalike-domain phishing

LastPass and Bitwarden users are getting phishing from lookalike "compliance" domains pushing a DocuSign-styled downloader. Delete the email; don't click.

read →
~/articles/2026-07-14-sonicwall-sma1000-cve-2026-15409-15410-kev-active-exploitation
SonicWall SMA1000 zero-days on CISA KEV: patch by July 17
sonicwall

SonicWall SMA1000 zero-days on CISA KEV: patch by July 17

Two SMA1000 flaws — a CVSS-10.0 unauthenticated SSRF and a post-auth code injection — hit CISA KEV today. Patch to 12.4.3-03453 or 12.5.0-02835 before July 17.

read →
~/articles/2026-07-14-rapid7-sharepoint-cve-2026-55040-jwt-auth-bypass-rce-chain-half
SharePoint JWT bypass fixed; RCE half of chain still open
microsoft

SharePoint JWT bypass fixed; RCE half of chain still open

Rapid7 disclosed CVE-2026-55040 today — a SharePoint JWT auth bypass patched in July Patch Tuesday. Second half of a pre-auth RCE chain lands next month. Patch now.

read →
~/articles/2026-07-14-microsoft-july-patch-tuesday-570-cves-adfs-sharepoint-bitlocker-zero-days
Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out
microsoft

Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out

Microsoft's July 2026 Patch Tuesday ships 570 CVEs, including two exploited zero-days in AD FS and SharePoint plus a publicly disclosed BitLocker bypass. Patch AD FS first.

read →
~/articles/2026-07-14-progress-sharefile-storage-zone-5-12-5-6-0-2-path-traversal-patch
Progress patches ShareFile zero-day: 5.12.5 and 6.0.2 out
progress

Progress patches ShareFile zero-day: 5.12.5 and 6.0.2 out

Progress shipped ShareFile Storage Zone Controller 5.12.5 and 6.0.2 to fix a high-severity authenticated path traversal. CVE pending. Patch first, then bring the boxes back up.

read →
~/articles/2026-07-14-proofpoint-oauth-client-id-spoofing-entra-signin-logs-blind
OAuth client ID spoofing sneaks past Entra sign-in logs
microsoft

OAuth client ID spoofing sneaks past Entra sign-in logs

Proofpoint tracked two credential-stuffing crews that submit fake OAuth application IDs to Entra ID's token endpoint. The sign-in logs don't record what defenders are looking for.

read →
~/articles/2026-07-14-ofac-1vpns-rashevskyi-silayev-sb0559-cryptor-designation
OFAC sanctions 1VPNS admin plus Belarusian cryptor seller
ransomware

OFAC sanctions 1VPNS admin plus Belarusian cryptor seller

OFAC designated 1VPNS, its Ukrainian admin Rashevskyi, and Belarusian cryptor seller Silayev on July 14 — the follow-on to May's Operation Saffron seizure.

read →
~/articles/2026-07-14-cereblab-grok-build-0-2-93-git-repo-upload-gcs
Grok Build v0.2.93 uploaded whole repos to xAI's bucket
threat intel

Grok Build v0.2.93 uploaded whole repos to xAI's bucket

xAI's Grok Build CLI v0.2.93 uploaded whole git repos, history and all, to a GCS bucket. The "Improve the model" toggle didn't stop it. Fix is server-side.

read →
~/articles/2026-07-13-jamf-crashstealer-werkbit-notarized-macos-stealer
Notarized Werkbit.app carries CrashStealer past Gatekeeper
apple

Notarized Werkbit.app carries CrashStealer past Gatekeeper

Jamf flagged CrashStealer, a native-C++ macOS infostealer arriving inside Werkbit.app — Apple-notarized and gated behind a meeting PIN.

read →
~/articles/2026-07-13-cisa-kev-cve-2008-4128-cisco-ios-12-4-csrf
Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV
cisco

Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV

CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.

read →
~/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum
Huntress Flags Suspected AI-Written PowerShell in AD Case
threat intel

Huntress Flags Suspected AI-Written PowerShell in AD Case

Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

read →
~/articles/2026-07-12-redhook-group-ib-wireless-adb-loopback-shizuku-uid-2000
RedHook Android RAT pairs Wireless ADB on-device
mobile

RedHook Android RAT pairs Wireless ADB on-device

Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.

read →
~/articles/2026-07-11-jscrambler-npm-8-14-0-preinstall-rust-infostealer
jscrambler 8.14.0 npm hijack: Rust stealer on install
supply chain

jscrambler 8.14.0 npm hijack: Rust stealer on install

Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

read →
~/articles/2026-07-11-gitea-docker-cve-2026-20896-sysdig-csa-1264-regression
Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms
gitea

Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms

Sysdig confirms the first in-the-wild hit on Gitea Docker CVE-2026-20896; Singapore CSA now warns customers; 1.26.3 shipped with a regression, so run 1.26.4.

read →
~/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
threat intel

Silver Fox ships MODBEACON, a Rust RAT with gRPC C2

QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

read →
~/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload
Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
threat intel

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days

CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

read →
~/articles/2026-07-11-zimbra-10-1-19-classic-web-client-xss-google-tag
Zimbra ships 10.1.19; Google TAG reported the XSS
zimbra

Zimbra ships 10.1.19; Google TAG reported the XSS

Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.

read →
~/articles/2026-07-09-openmandriva-beatrici-mumble-contributor-repo-sabotage
OpenMandriva ex-contributor wipes GNOME, Cosmic packages
supply chain

OpenMandriva ex-contributor wipes GNOME, Cosmic packages

Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

read →
~/articles/2026-07-09-injectivelabs-sdk-ts-npm-1-20-21-wallet-stealer
Injective SDK 1.20.21 on npm shipped a wallet stealer
supply chain

Injective SDK 1.20.21 on npm shipped a wallet stealer

Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

read →
~/articles/2026-07-09-forg365-phaas-m365-aitm-device-code-zerobec
Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
microsoft

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365

ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

read →
~/articles/2026-07-09-microsoft-defender-rogueplanet-cve-2026-50656-lpe-patch
Microsoft patches Defender 'RoguePlanet' LPE; PoC public
microsoft

Microsoft patches Defender 'RoguePlanet' LPE; PoC public

Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

read →
~/articles/2026-07-09-simplehelp-cve-2026-48558-oidc-bypass-past-kev-deadline
SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now
simplehelp

SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now

SimpleHelp Server 5.5.15 and earlier accept forged OIDC tokens as valid technician sessions. CVSS 10.0, KEV, patch is 5.5.16 — CISA deadline was July 2.

read →
~/articles/2026-07-08-writeout-writer-ai-cross-tenant-session-sand-security
WriteOut: One Preview Link Took Over Writer AI Accounts
cloud

WriteOut: One Preview Link Took Over Writer AI Accounts

SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

read →
~/articles/2026-07-08-gitlost-github-agentic-workflows-noma-security-private-repos
GitLost: Public Issue Leaks Private GitHub Repo Data
cloud

GitLost: Public Issue Leaks Private GitHub Repo Data

Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

read →
~/articles/2026-07-08-ghostlock-linux-kernel-cve-2026-43499-container-escape
GhostLock: 15-Year Linux Kernel Root/Container Escape
linux kernel

GhostLock: 15-Year Linux Kernel Root/Container Escape

Nebula Security's GhostLock (CVE-2026-43499) — a 15-year-old futex use-after-free — hits every mainstream Linux distro. Escapes containers. Patch again.

read →
~/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds
CISA Adds Langflow and Two Joomla Builders to KEV
threat intel

CISA Adds Langflow and Two Joomla Builders to KEV

CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

read →
~/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched
Tenda Router Backdoor Has No Patch. Here's What to Do.
ics ot

Tenda Router Backdoor Has No Patch. Here's What to Do.

CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

read →
~/articles/2026-07-07-beyondtrust-remote-support-pra-auth-bypass
BeyondTrust Patches Four RS/PRA Flaws — Patch Now
beyondtrust

BeyondTrust Patches Four RS/PRA Flaws — Patch Now

BeyondTrust shipped fixes on July 6 for four vulnerabilities in Remote Support and Privileged Remote Access, including a CVSS 9.8 pre-auth bypass. No in-wild exploitation reported. Here's the priority order.

read →
~/articles/2026-07-06-gitea-docker-cve-2026-20896-header-auth-bypass
Gitea Docker's Auth Bypass: Probing Already Underway
gitea

Gitea Docker's Auth Bypass: Probing Already Underway

The Gitea Docker image up through 1.26.2 shipped a wildcard reverse-proxy trusted list, collapsing auth to a header. Fixed in 1.26.3. The Hacker News reports opportunistic scanning 13 days after disclosure; ~6,200 exposed instances.

read →
~/articles/2026-07-06-adobe-coldfusion-cve-2026-48282-active-exploitation
Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
adobe

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited

A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.

read →
~/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue
QuimaRAT: A $150 Cross-Platform Java RAT MaaS
threat intel

QuimaRAT: A $150 Cross-Platform Java RAT MaaS

LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

read →
~/articles/2026-07-06-opera-gx-mods-auto-install-flaw-patched
Opera GX Patches Auto-Install Mods Flaw
browser

Opera GX Patches Auto-Install Mods Flaw

Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.

read →
~/articles/2026-07-06-skillcloak-scanners-miss-agent-skill-malware-hkust
SkillCloak: Scanners Miss 90%+ of Skill Malware
supply chain

SkillCloak: Scanners Miss 90%+ of Skill Malware

HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

read →
~/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven
Flipper Zero Firmware Goes Maintenance-Only
threat intel

Flipper Zero Firmware Goes Maintenance-Only

Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

read →
~/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection
Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
threat intel

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara

Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

read →
~/articles/2026-07-04-polinrider-108-dprk-packages-contagious-interview
PolinRider: DPRK Seeds 108 Malicious Packages
supply chain

PolinRider: DPRK Seeds 108 Malicious Packages

The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

read →
~/articles/2026-07-04-toddycat-umbrij-oauth-gmail-kaspersky
Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
cloud

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser

Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

read →
~/articles/2026-07-04-artoken-eviltokens-m365-device-code-phishing-talos
ARToken PhaaS Targets M365 Device-Code Phishing
cloud

ARToken PhaaS Targets M365 Device-Code Phishing

Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

read →
~/articles/2026-07-03-chocopoc-rat-fake-poc-github-pypi-yeswehack
ChocoPoC: Fake CVE PoC Repos Ship a Stealer
supply chain

ChocoPoC: Fake CVE PoC Repos Ship a Stealer

YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

read →
~/articles/2026-07-03-bad-epoll-linux-kernel-lpe-cve-2026-46242
Bad Epoll: Linux Kernel LPE Also Hits Android
linux kernel

Bad Epoll: Linux Kernel LPE Also Hits Android

A newly disclosed use-after-free in Linux 6.4+ kernels lets an unprivileged local user gain root. Android on affected kernels is in scope; the upstream fix is in.

read →
~/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf
PamStealer: A Fake Maccy Site Steals macOS Creds
threat intel

PamStealer: A Fake Maccy Site Steals macOS Creds

Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

read →
~/articles/2026-07-03-cisco-unified-cm-active-exploitation-confirmed
Cisco Confirms Active Exploitation of Unified CM Flaw
cisco

Cisco Confirms Active Exploitation of Unified CM Flaw

Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

read →
~/articles/2026-07-03-kemp-loadmaster-cve-2026-8037-pre-auth-rce
Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now
progress

Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now

A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress's fix has been available since June 4.

read →
~/articles/2026-07-03-sharepoint-cve-2026-45659-kev-active-exploitation
SharePoint RCE now on CISA KEV: patch it this week, not next
microsoft

SharePoint RCE now on CISA KEV: patch it this week, not next

CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.

read →