๐จ ACTIVE EXPLOITATION
-
Critical CosmosEscape Flaw in Azure Cosmos DB Allowed Cross-Tenant Key Access A vulnerability in Azure Cosmos DB's Gremlin API allowed attackers to access any database across tenants.
- Applies to Microsoft Azure Cosmos DB customers and Microsoft internal systems
- Vulnerability in Cosmos DB's Gremlin API enabled sandbox escape via .NET reflection misuse
- Attackers could execute arbitrary code on the DB Gateway component
- Exposed a platform-wide Cosmos Master Key granting full read-write access across tenants, regions, and APIs
- Allowed enumeration of accounts via the Config Store directory and retrieval of primary keys ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News, Cyber Security News
-
Chaos ransomware deployed via Microsoft Teams vishing attacks on North American firms Threat actors use Microsoft Teams vishing calls to deploy Chaos ransomware on corporate devices.
- Targets: Dozens of US and Canadian organizations across services, manufacturing, energy, and construction sectors
- Attack vector: Impersonation of IT support in Microsoft Teams calls to convince employees to grant remote access
- Tools: Remote access via Microsoft Quick Assist and RemSupp, later primarily RemSupp for evasion
- Persistence: PowerShell backdoors disguised as Realtek and Windows audio components in registry
- Outcome: At least three intrusions led to Chaos ransomware deployment, with one encrypting files within 17 hours ๐ Coverage: bleepingcomputer.com ยท ๐ via Cybersecurity Dive, BleepingComputer
-
Home Assistant FFmpeg Flaw Allows File Theft and Root Command Execution Home Assistant's FFmpeg integration flaw enables file theft and root command execution.
- Applies to Home Assistant smart home platform, specifically Wyoming integration announce feature
- Vulnerability allows argument injection in FFmpeg input, enabling reading of arbitrary local files
- Attack uses FFmpeg pseudo-protocols (file:, concat:, subfile:) to bypass input validation
- Exfiltrates sensitive data like SUPERVISOR_TOKEN, enabling root-level command execution
- Requires attacker to control paired Wyoming Assist satellite and valid Home Assistant API token
- Patched in Home Assistant Core version 2026.6.2 with strict FFmpeg protocol allowlist ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
GenieLocker ransomware by Toy Ghouls targets Windows, Linux, and ESXi systems GenieLocker ransomware attacks Windows, Linux, and VMware ESXi systems in Russia's manufacturing sector.
- Targets Windows, Linux, and VMware ESXi systems, mainly in Russia's manufacturing sector since March 2026
- Operated by Toy Ghouls group, formerly using LockBit, Babuk, and RedAlert ransomware families
- Initial access via OpenVPN using stolen valid credentials from trusted partner networks
- Uses tools like OpenSSH, socks5.exe, SoftPerfect Network Scanner, Mimikatz, PsExec, PAExec, and reverse SSH tunnels
- Windows variant includes anti-debugging, secret argument validation, and encrypts files selectively using libsodium crypto library
- Linux and ESXi variants lack anti-debugging but can stop VMs and encrypt virtual disks, risking virtual infrastructure ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ต๏ธ RESEARCH & DEEP DIVES
-
Server-Side Request Forgery in Boruta OAuth and OpenID URIs Allows Remote Attacker Requests
CVE-2026-54885Boruta OAuth/OpenID server is vulnerable to unauthenticated SSRF via request_uri and jwks_uri parameters.- Applies to Boruta versions from 2.3.2 before 2.3.7
- Vulnerability in OAuth request_uri and OpenID jwks_uri fetching code paths
- Allows unauthenticated remote attacker to make server issue HTTP requests to attacker-chosen URIs
- No validation of URI scheme, host, IP allowlist, or response size limits
- Enables SSRF attacks targeting internal services and cloud metadata endpoints ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Hackers Exploit Nearly One in Four Vulnerabilities Before CVE Publication in 2026 Attackers exploited 23.43% of vulnerabilities before their CVEs were published in early 2026.
- Applies to vulnerabilities tracked by VulnCheck in the first half of 2026
- 23.43% of exploited vulnerabilities showed active attacks on or before CVE publication date
- Median time from CVE publication to known exploitation dropped from 120 to 80 days
- Content management systems, especially WordPress plugins, were most targeted
- Network edge devices from Cisco, Palo Alto, Fortinet, and others were heavily attacked
- AI development tools were also targeted, including exploits like CVE-2026-0769 and CVE-2026-5027 ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
โ ๏ธ BREACHES & INCIDENTS
-
Analog Devices confirms June 2026 data breach with file exfiltration, operations unaffected Analog Devices suffered unauthorized access and file exfiltration in June 2026.
- Applies to Analog Devices internal systems detected on June 23, 2026
- Unauthorized party accessed and exfiltrated certain company files
- Incident response activated with external cybersecurity experts engaged
- Operations remained uninterrupted; no confirmed data leak or fraud use reported
- Extortion group ExfilSquad claimed stolen customer data but link to breach unverified ๐ Coverage: bleepingcomputer.com ยท ๐ Original: bleepingcomputer.com ยท ๐ via BleepingComputer, Cyber Security News
-
ExfilSquad claims theft of 740,000 records from UK education and police databases ExfilSquad hackers stole over 740,000 records from UK education and police databases.
- Targets include UK Department for Education helpdesk and Turing portals, and Police National Legal Database
- Data stolen includes names, emails, phone numbers, job titles of officials, school staff, police officers, and public
- Hackers posted data samples on leak site and demanded ransom from at least 14 victims including a UK university
- Police database breach exposed work-related info but no confidential victim, witness, or offender data
- Cybersecurity firm Sophos verified data legitimacy; ExfilSquad's social media account was suspended ๐ Coverage: metacurity.com ยท ๐ via @metacurity@infosec.exchange
-
River Bank Discloses Paying Threat Actor to Conceal Cybersecurity Incident River Bank paid a threat actor to cover up a cybersecurity incident.
- Applies to River Bank, a financial institution
- Incident involves a cybersecurity breach
- Bank paid the threat actor to conceal the incident
- Disclosure made via an SEC 8-K filing ๐ Coverage: cyberplace.social ยท ๐ Original: sec.gov ยท ๐ via @GossiTheDog@cyberplace.social
๐ ADVISORIES
- foreUP golf management API has two critical vulnerabilities exposing customer and merchant data
foreUP's golf management API exposes merchant credentials and customer data via broken object-level authorization.
- Applies to foreUP golf management platform used by over 2,000 golf courses
- CVE-2026-15657 exposes Finix merchant API credentials in customer record responses
- CVE-2026-15658 allows unauthorized access to any customer's profile and payment tokens by changing golfer_id
- Attack requires only a valid low-privilege customer account and exploits missing object-level authorization
- Vulnerabilities affect all facilities using foreUP due to shared web API ๐ Coverage: kb.cert.org ยท ๐ Original: kb.cert.org ยท ๐ via CERT/CC Vulnerability Notes
๐ CVEs & KEV
- Other: 20 CVEs (worst 8.6)