π¨ ACTIVE EXPLOITATION
- vBulletin patches critical pre-auth RCE flaw CVE-2026-61511 with public exploit
CVE-2026-61511
vBulletin fixed a critical pre-auth remote code execution vulnerability in its forum software.- Affects vBulletin forum software versions 5.x up to 5.7.5 and 6.x up to 6.2.1
- Vulnerability allows unauthenticated attackers to execute arbitrary PHP code via template rendering
- Exploitation targets the ajax/render/[template] endpoint, abusing the runMaths() function's improper input sanitization
- Public proof-of-concept exploit uses 'phpfuck' technique to bypass sanitization and execute system commands
- Patch released in v6.2.2 and backported to 6.2.1, 6.2.0, and 6.1.6; no updates planned for 5.x branch
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
π ADVISORIES
-
Microsoft patches 'Certighost' flaw allowing AD certificate impersonation and privilege escalation
Microsoft patched a vulnerability in Active Directory Certificate Services enabling privilege escalation.- Applies to Microsoft Active Directory Certificate Services (AD CS) in enterprise environments
- Flaw allows low-privileged domain users to impersonate domain controllers via certificate enrollment
- Exploits a broken trust boundary in certificate-based client authentication using manipulated request attributes
- Attack uses LDAP and LSA services on attacker-controlled hosts to supply forged identity data
- Proof-of-concept exploit released; vulnerability tracked as CVE-2026-54121 and patched in July 2026 updates
π Coverage: darkreading.com Β· π Original: darkreading.com Β· π via Dark Reading
-
Critical RCE Flaw in JetBrains TeamCity Pre-2026.1.3 Allows Unauthenticated OS Command Execution
CVE-2026-63077
JetBrains TeamCity has a critical unauthenticated remote code execution vulnerability.- Applies to all TeamCity On-Premises versions before 2025.11.7 and 2026.1.3
- Vulnerability CVE-2026-63077 allows attackers to bypass authentication and execute OS commands
- Exploited via TeamCity agent polling protocol over HTTP/HTTPS without authentication
- Attackers can access project data, server configs, credentials, modify build jobs, and compromise CI/CD pipelines
- Patch available in TeamCity 2025.11.7 and 2026.1.3; security patch plugin supports versions 2017.1 and later
π Coverage: cybersecuritynews.com Β· π Original: cybersecuritynews.com Β· π via Cyber Security News
-
Nginx CVE-2026-42533 Buffer Overflow Lets Attackers Execute Code via TLS Requests
CVE-2026-42533
A heap buffer overflow in Nginx allows unauthenticated attackers to execute arbitrary code.- Affects NGINX Plus and Open Source versions using regex-based map directives or non-cacheable variables
- Vulnerability triggered via crafted HTTP or TLS requests exploiting Stream module's ssl_preread feature
- Heap buffer overflow arises from incorrect length calculation in internal script engine's complex value evaluation
- Attackers can cause worker process crashes or achieve remote code execution by bypassing ASLR
- Discovered by Zhenpeng (Leo) Lin and Depth First Labs; F5 published advisory July 15, 2026
π Coverage: cybersecuritynews.com Β· π Original: cybersecuritynews.com Β· π via Cyber Security News
β οΈ RESEARCH & DEEP DIVES
-
Anthropic's Claude Mythos AI Finds New Cryptographic Weaknesses in HAWK and AES
Anthropic's Claude Mythos AI discovered novel cryptographic weaknesses in HAWK and reduced-round AES.- Applies to HAWK, a NIST post-quantum digital signature candidate, and reduced-round AES-128 cipher
- AI found an improved key-recovery attack halving HAWK-256's key strength by exploiting lattice symmetry
- Discovered a MΓΆbius Bridge fingerprinting technique speeding up cryptanalysis of 7-round AES-128 by 200-800x
- Findings do not threaten full AES-128 or deployed systems and were coordinated with NIST and HAWK authors
- Research involved semi-autonomous AI operation costing about $100,000 and extensive human validation
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
Flying Eagle Android RAT Source Code Leaked, 170 Servers Found in Hong Kong
Researchers uncovered leaked Flying Eagle Android RAT source code and identified 170 active servers.- Targets Android devices via a fake Chinese Public Security Bureau app and phishing overlays
- Leaked source code includes APK builder with evasion features like randomized class names and encrypted C2 URLs
- 170 active servers identified across Hong Kong ASNs using TLS certificate pivots and panel fingerprints
- Distributed and modified via Telegram channels SQLRCE0 and Yxη§ζ with international targeting potential
- A successor platform called Night Dragon is under development as of June 2026
π Coverage: hunt.io Β· π via r/netsec
-
Anthropic AI Model Identifies Flaws in Strong Encryption Algorithms
Anthropic's AI model discovered vulnerabilities in robust encryption algorithms.- Applies to widely used tough-to-crack encryption algorithms
- Anthropic AI model analyzed and found cryptographic weaknesses
- No CVE identifiers assigned yet
- Details on specific algorithms or attack methods not disclosed
π Coverage: infosec.exchange Β· π via @metacurity@infosec.exchange
π CVEs & KEV
- Other: 21 CVEs (worst 8.6)