π¨ ACTIVE EXPLOITS & INCIDENTS
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday β The Hacker News
A new PoC exploit named LegacyHive targets a Windows User Profile Service (ProfSvc) arbitrary hive load elevation of privilege vulnerability. This zero-day allows attackers to escalate privileges by loading malicious user profile hives. Immediate patching and monitoring for exploit attempts are critical.
π΅οΈ THREAT RESEARCH & DEEP DIVES
-
Windows Bind Link Attacks Can Hide Malware From EDR Tools β SecurityWeek
Bitdefender researchers reveal a novel technique abusing Windows bind links to create conflicting filesystem views, effectively hiding malware from endpoint detection and response (EDR) tools. This evasion tactic complicates detection and requires updated EDR heuristics and monitoring for suspicious bind link activity. -
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. β The Hacker News
Traditional SASE inspection models fail to address risks introduced by AI-driven workflows, unsanctioned browser extensions, and autonomous agents operating in SaaS and browser environments. Security teams must evolve beyond packet inspection to include behavioral and AI-contextual analysis to prevent data exfiltration and IP leakage.
π VULNERABILITIES & CVEs
- Grav CMS: Multiple critical vulnerabilities affecting versions prior to 9.1.8, 2.0.4, 2.0.2, 2.0.1, 2.0.0, and 1.0.4 include arbitrary file write (CVE-2026-61873), remote code execution via file upload extension bypass (CVE-2026-61457), JWT session invalidation flaws (CVE-2026-61452), decompression bomb ZIP size bypass (CVE-2026-61449), XSS via Twig string concatenation (CVE-2026-61453), and password reset token poisoning (CVE-2026-61451). These vulnerabilities allow remote attackers to execute code, escalate privileges, or bypass security controls. Patch to latest versions immediately.
- ImageMagick: A broad set of memory leak vulnerabilities (CVE-2026-61872, CVE-2026-61871, CVE-2026-61869, CVE-2026-61868, CVE-2026-61867, CVE-2026-61866, CVE-2026-61865, CVE-2026-61864, CVE-2026-61863), use-after-free (CVE-2026-61860), policy bypass (CVE-2026-61859), information disclosure (CVE-2026-61862), and heap buffer over-write (CVE-2026-61464) affect versions before 7.1.2-26 and 6.9.13-51. Attackers can cause denial of service, memory corruption, or bypass security policies via crafted image files. Upgrade ImageMagick to 7.1.2-26 or later.
- PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery β CVE ThreatInt
PraisonAIβs plugin manager loads and executes arbitrary Python files from project and user directories without validation, enabling remote code execution. Upgrade to 1.6.78 or later to mitigate.
π° LESSER-KNOWN / UNDER-REPORTED
- US Court Denies Warrant for Mass Phone Snooping Using Stingray β Zack Whittaker / Mastodon
A recent U.S. court ruling rejected a government warrant that sought to use a cell-site simulator ("stingray") to collect data on thousands of uninvolved Ohio residents. This sets a precedent limiting bulk surveillance via IMSI catchers and highlights ongoing privacy and legal challenges in law enforcement surveillance technology.