🚨 ACTIVE EXPLOITS & INCIDENTS
-
CISA orders feds to patch actively exploited Oracle flaw by Saturday — BleepingComputer
CISA mandates federal agencies patch a critical Oracle E-Business Suite vulnerability actively exploited in the wild. The flaw targets financial applications and requires immediate remediation by July 18 to prevent ongoing attacks. -
Russian hackers trojanize WebEx, Zoom apps to push Starland malware — BleepingComputer
Russian financially motivated threat actor UAT-11795 is deploying a new Starland RAT via trojanized WebEx and Zoom clients to steal credentials and cryptocurrency. Cisco Talos confirms this campaign has been active since June 2025, using a bespoke WLDR C2 implant. -
New Spirals ransomware encrypts victim network in under 24 hours — BleepingComputer
The Spirals ransomware group demonstrates rapid intrusion-to-encryption capability, completing full network compromise and data encryption in less than 24 hours. This speed highlights a critical need for enhanced detection and response post-initial access.
🔓 VULNERABILITIES & CVEs
-
Spring Security Authorization Server Dynamic Client Registration endpoints privilege bypass (CVE-2026-22752) — CVE ThreatInt
Critical authentication bypass affects Spring Authorization Server versions 7.0.0 through 7.0.4 and 1.5.0+. This vulnerability allows attackers to bypass authentication controls, posing a high risk for identity and access compromise in affected environments. -
Origin Validation Error in X-Rite MA-T6 allows unauthenticated remote command execution (CVE-2023-49899) — CVE ThreatInt
An unauthenticated remote attacker can execute arbitrary commands due to improper origin validation on the X-Rite MA-T6 device. This flaw enables full device takeover without authentication. -
Remote code execution in X-Rite MA-T6 via SetParameter command (CVE-2023-49900) — CVE ThreatInt
Improper input sanitization in the SetParameter command allows unauthenticated remote code execution on X-Rite MA-T6 devices, facilitating complete system compromise.
📋 VENDOR BULLETINS & ADVISORIES
- Splunk, Zoom Patch Critical Vulnerabilities — SecurityWeek
Splunk and Zoom released patches addressing critical flaws that could lead to credential theft, account takeover, and privilege escalation. Immediate patching is advised to mitigate active exploitation risks.
🕵️ THREAT RESEARCH & DEEP DIVES
-
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign — Cisco Talos
Detailed analysis of UAT-11795 reveals sophisticated malware delivery via trojanized collaboration apps, leveraging a novel Starland RAT and custom WLDR C2 implant. The campaign targets U.S. and European users with credential and crypto theft. -
Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide — The Hacker News
A researcher disclosed a root command execution method on Shark RV2320EDUS robot vacuums by extracting certificates from device flash memory. This flaw allows attackers to control cameras, movement, and extract Wi-Fi credentials across devices in the same AWS region. -
The Hunter's Paradox: Is it time to embrace automated threat hunting? — Cisco Talos
A thoughtful exploration of the balance between human and AI-driven threat hunting. Highlights the challenges of data volume and velocity, and the current limitations of AI trustworthiness in security operations.
📰 LESSER-KNOWN / UNDER-REPORTED
- AI Can Find Bugs, But Human Knowledge Still Proves Them — The Hacker News
AI tools accelerate bug discovery and testing workflows but cannot replace human expertise in validating and proving vulnerabilities. This underscores the ongoing need for skilled analysts in offensive security.