🚨 ACTIVE EXPLOITS & INCIDENTS
-
HelloNet campaign — new malicious modules launched through the ViPNet update system — Securelist (Kaspersky)
Targeted attacks against large Russian organizations have been identified leveraging the ViPNet secure network software update mechanism to deploy new malicious modules. This supply chain compromise demands urgent review of ViPNet update integrity and network segmentation controls. -
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE — r/netsec
Millions of Shark robotic vacuums contain remote code execution vulnerabilities, exposing IoT devices to full compromise. Exploits could enable lateral movement or persistent footholds in home or enterprise environments where these devices are connected.
🔓 VULNERABILITIES & CVEs
-
VU#326070: SGLang Pickle Deserialization RCE (CVE-2026-14890) — CERT/CC
SGLang, an open-source framework for large language models, contains a critical pickle deserialization flaw in its expert-parallel backup subsystem enabling remote code execution. Exploitation requires network access and the subsystem to be enabled. No patch or maintainer response yet. CVSS likely high due to RCE and LLM integration. -
PipeWire Sandbox Escape and Arbitrary Code Execution (CVE-2026-5674) — CVE ThreatInt
A sandbox escape vulnerability in PipeWire’s PulseAudio compatibility layer allows attackers to break out of Flatpak and similar sandboxed apps. This elevates risk for Linux desktop environments relying on PipeWire for multimedia services. -
HCL DFXAnalytics Internal File Path Disclosure — CVE ThreatInt
HCL DFXAnalytics dashboard leaks sensitive internal file path information, potentially aiding attackers in reconnaissance and further exploitation. Immediate review of dashboard exposure and patching recommended. -
n8n Token Exchange Flaw Enables Cross-Issuer Account Takeover — The Hacker News
n8n’s Enterprise instances trusting multiple external token issuers improperly authenticate users bysubclaim alone, ignoringiss. Valid tokens from one issuer can log in as users from another, bypassing passwords. Critical for organizations using n8n Enterprise with multi-issuer configs to apply mitigations. -
Google IdP Universal Account Takeover via Device Code Flow Hijacking — r/netsec
Google’s implementation of RFC 8628 device authorization grant is vulnerable to a confused deputy attack allowing invisible, one-click account takeovers across browsers. The authorization server fails to validate client_id and scope consistency, enabling session hijacking. Urgent review of OAuth device flow security advised.
🕵️ THREAT RESEARCH & DEEP DIVES
-
Protecting Privacy in an AI Era — Schneier on Security
Daniel Solove advocates shifting privacy regulation focus from individual control to corporate accountability, recommending data minimization, fiduciary duties, and liability for negligent AI design. This framework is critical as AI systems increasingly handle sensitive personal data. -
AI Agents Broke the Security Playbook. Here's What Replaces It. — BleepingComputer
Traditional security workflows fail against AI agents operating at machine speed. Token Security proposes a new model based on live identity foundations and customizable workflows, signaling a paradigm shift in identity and access management for AI-driven environments.
📰 LESSER-KNOWN / UNDER-REPORTED
-
Mozilla Research Reveals Privacy Risks in Period Tracker Apps — @zackwhittaker@mastodon.social
Mozilla’s latest testing found period tracker apps, including Stardust, sharing sensitive health data with third parties without adequate user consent. This highlights ongoing privacy risks in health-related mobile apps requiring increased scrutiny and regulatory attention. -
Metacurity Highlights: India Nuclear Project Data Leak, TfL Hackers Sentenced, OpenAI AI-Powered Red Teaming, and More — @metacurity@infosec.exchange
Key updates include: hackers leaking blueprints from India’s nuclear project, TfL hackers sentenced to 5.5 years, OpenAI’s new AI-powered red teaming tool, ransomware disrupting Japan’s food supply chain, and a critical Zoom flaw enabling account takeovers. Full details essential for threat intel teams.