๐จ ACTIVE EXPLOITATION
- CISA Warns of Exploited Cisco Secure Firewall Management 0-Day CVE-2026-20316
CVE-2026-20316
A hard-coded credential vulnerability in Cisco Secure Firewall Management Center is actively exploited.- Applies to Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center
- Vulnerability CVE-2026-20316 involves a hard-coded password allowing unauthenticated low-privilege login
- Attackers can remotely access sensitive firewall configurations, policies, and logs
- Exploitation enables lateral movement and privilege escalation in targeted networks
- CISA confirms active exploitation but no confirmed ransomware campaigns yet
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
- ShinyHunters claims breach of Brinks Home, threatens to leak 4.9M records
Hackers breached Brinks Home and threaten to leak stolen customer and employee data.- Applies to Brinks Home, a residential security company serving 1M+ customers in US, Canada, Puerto Rico
- Attack compromised over 4.9 million Salesforce records including customer PII and 3.8 million support chat logs
- Breach occurred via Microsoft Entra voice phishing (vishing) social engineering attack on July 13, 2026
- Threat actors stole employee data including names, emails, job titles, and phone numbers
- Brinks Home detected breach on July 20, engaged forensics experts, and confirmed no impact on alarm systems
๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ CVEs & KEV
- CVE-2026-12940 โ IBM Langflow OSS 1.0.0-1.10.1 โ CVSS 9.8 โ unauthenticated remote code execution via environment variable injection [KEV]
๐ต๏ธ RESEARCH & DEEP DIVES
-
IBM Langflow OSS 1.0.0-1.10.1 vulnerable to unauthenticated RCE via MCP stdio launcher CVE-2026-12940
IBM Langflow OSS versions 1.0.0 through 1.10.1 have an unauthenticated remote code execution vulnerability.- Applies to IBM Langflow OSS versions 1.0.0 through 1.10.1
- Vulnerability is unauthenticated remote code execution via environment variable injection
- Exploited through the MCP (Model Context Protocol) stdio launcher component
- Root cause is incomplete environment variable blocklist missing SHELLOPTS, BASHOPTS, and PS4
- CVE-2026-12940 with CVSS 9.8, CWE-78 OS Command Injection
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Generic TV Streaming Sticks Used for Ad Fraud and Residential Proxy Abuse
Generic TV streaming sticks are exploited to commit ad fraud and operate residential proxies.- Applies to generic Android-based TV streaming sticks, notably the H96 brand
- Devices spoof themselves as mobile phones to click ads on AI-generated websites
- When TV is on, devices act as residential proxies renting out users' internet connections
- When TV is off, devices perform resource-intensive ad fraud tasks via Blockly-coded routines
- Operation traced to Zhejiang Fengwo IoT Technology Ltd, linked to ad fraud and proxy networks
๐ Coverage: krebsonsecurity.com ยท ๐ via Krebs on Security, @briankrebs@infosec.exchange (+2)
๐ ADVISORIES
- VMware patches five vulnerabilities including three critical flaws enabling auth bypass and VM escapes
Broadcom fixed five VMware vulnerabilities including critical auth bypass and VM escape flaws.- Applies to VMware vCenter, ESX, Workstation, Fusion, Cloud Foundation, vSphere, Telco Cloud Platform, and Telco Cloud Infrastructure
- Critical flaws include authentication bypass in VMware Directory Service and directory traversal in vCenter Syslog server
- VMXNET3 virtual network adapter flaw allows VM escape to ESX host via out-of-bounds write
- Other issues include out-of-bounds read causing info disclosure or DoS, and insufficient logging in ESX
- Exploits require network access or local admin in VM; patches released for affected versions including vCenter 9.1.0.0300+ and ESXi 9.1.0.0200+
๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer