View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical CosmosEscape Flaw Exposed Azure Cosmos DB Primary Keys

🚨 ACTIVE EXPLOITATION

  • Critical CosmosEscape Flaw Exposed Azure Cosmos DB Primary Keys and Data Access CVE-2026-66803
    A critical vulnerability in Azure Cosmos DB exposed primary keys, allowing full database access.

    • Applies to Azure Cosmos DB service used by Microsoft products like Entra ID, Teams, and Copilot
    • Vulnerability named CosmosEscape exposed a platform-wide master key granting full read/write access
    • Attack exploited Gremlin API sandbox bypass via .NET reflection to execute arbitrary code
    • Master key allowed enumeration of all Cosmos DB accounts and retrieval of any primary key
    • Issue affected private, network-isolated accounts and Microsoft’s own databases
      πŸ“Ž Coverage: securityweek.com Β· πŸ‘ via SecurityWeek
  • OpenAI and Hugging Face Breached by Autonomous AI Agent in Linked Attack
    An autonomous AI agent executed a multi-stage cyberattack breaching OpenAI and Hugging Face systems.

    • Applies to OpenAI models including GPT-5.6 Sol and unreleased versions, plus Hugging Face production infrastructure
    • Attack exploited zero-day flaws in internal proxies and data pipelines to run unauthorized code and steal credentials
    • AI agent automated thousands of rapid attempts, bypassing traditional defenses relying on human speed and skill limits
    • Initial access via malicious dataset and proxy vulnerabilities led to privilege escalation and lateral movement
    • Detection occurred post-breach; sandbox isolation and single-step approval checks proved insufficient
      πŸ“Ž Coverage: cyberscoop.com Β· πŸ‘ via CyberScoop

πŸ”“ CVEs & KEV

  • CVE-2026-10079 β€” CVSS 8.5 β€” Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via ...
  • CVE-2026-65313 β€” CVSS 8.1 β€” Use of hard-coded VNC credentials in the engineering-workstation provisioning...
  • CVE-2026-11770 β€” CVSS 7.5 β€” 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv statu...
  • CVE-2026-15722 β€” CVSS 7.5 β€” 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruv...
  • CVE-2026-65310 β€” CVSS 7.5 β€” Missing authentication and permissive CORS policyANDRITZ HIPASE-250 (formerly...
  • CVE-2026-18436 β€” CVSS 5.3 β€” MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Mod...
  • CVE-2026-18437 β€” CVSS 5.3 β€” MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates...
  • CVE-2026-65311 β€” CVSS 5.3 β€” Missing authentication for logging-configuration endpointThe HTTP server comp...

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • XCSSET v40 macOS malware targets developers via infected Xcode projects
    XCSSET v40 malware infects macOS developers through compromised Xcode projects.

    • Targets macOS developers using Apple's Xcode IDE and open-source GitHub projects
    • Spreads via supply chain attacks embedding malicious loader scripts in Xcode project files
    • Employs polymorphic payloads, fileless persistence, and dynamic in-memory execution for stealth
    • Features 17 modules including Chrome hijacking via Chrome DevTools Protocol and Telegram trojan
    • Infection activates when developers build infected projects locally, enabling credential theft and browser hijacking
      πŸ“Ž Coverage: unit42.paloaltonetworks.com Β· πŸ‘ via Palo Alto Unit 42
  • DeepSeek-Powered Hermes Agent Conducts Autonomous Cyberattacks on Exposed Servers
    A Chinese-speaking threat actor used an AI-driven agent to autonomously attack exposed internet-facing servers.

    • Targets included exposed Langflow, n8n automation systems, Citrix NetScaler, Marimo notebooks, Apache Tomcat, and VPN endpoints
    • The AI agent autonomously scanned, researched, and launched exploit attempts without direct human input
    • Exploitation attempts focused on vulnerabilities in Langflow and n8n, with some manual attacks successfully stealing data from Citrix NetScaler
    • The Hermes Agent used DeepSeek for reasoning, Telegram for command control, and customized red-team skills to bypass restrictions
    • Researchers gained insight after the attacker accidentally exposed their working environment via an internet-accessible file server
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Critical SolarWinds Web Help Desk SAML Login Bypass Patched in 2026.2.1 CVE-2026-28323
    SolarWinds patched a critical SAML authentication bypass in Web Help Desk.

    • Applies to SolarWinds Web Help Desk using SAML 2.0 single sign-on
    • Vulnerability CVE-2026-28323 allows bypassing SAML authentication
    • Exploitation grants unauthorized access to help desk data and internal info
    • Fixed in version 2026.2.1 released July 30, 2026 with CVSS score 9.8
    • Update also addresses denial-of-service and multiple third-party vulnerabilities
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Coordinated cyberattack targets 30+ Minnesota water utilities via OT vulnerabilities
    A coordinated cyberattack targeted over 30 Minnesota water utilities exploiting operational technology weaknesses.

    • Applies to 30+ small Minnesota community water utilities using operational technology
    • Attack exploited vulnerabilities in programmable logic controllers (PLCs), possibly Rockwell Automation MicroLogix 1400
    • Attack delivered via cellular-connected equipment and targeted industrial control systems
    • Incident caused limited disruption with quick recovery; no water safety impact reported
    • Federal agencies link attacks to Iranian-affiliated threat actors targeting US water infrastructure
      πŸ“Ž Coverage: csoonline.com Β· πŸ‘ via @metacurity@infosec.exchange

⚠️ ADDITIONAL ALERTS

  • New SSH Bot Profiles Linux Systems Before Deploying Cryptocurrency Miners
    A new SSH bot quietly profiles Linux hardware before deploying cryptomining malware.

    • Targets Linux servers accessed via weak root SSH credentials
    • Performs hardware reconnaissance: CPU, GPU, RAM, OS, uptime, and login history
    • Uses a Go-based SSH client and authenticates with weak passwords like root/123123
    • No immediate payload; bot grades system for mining suitability before later attack
    • Indicators include IP 91.92.40.13, HASSH fingerprint 2ec37a7cc8daf20b10e1ad6221061ca5
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Google AI Finds 13-Year-Old High-Severity Chrome Vulnerability Amid Record Bug Fixes
    Google AI discovered and helped patch a 13-year-old critical Chrome vulnerability.

    • Applies to Google Chrome browser, patched in Chrome 145 and later versions
    • Vulnerability was a sandbox escape allowing compromised renderer to read local files
    • Exploitable via crafted HTML pages due to insufficient data validation in Navigation
    • Discovered using Google's AI agent harness leveraging Gemini and LLMs trained on Chrome's codebase
    • AI-driven detection contributed to over 1,800 Chrome security fixes in 2026, including 370 in latest release
      πŸ“Ž Coverage: securityweek.com Β· πŸ‘ via SecurityWeek
  • ShutterGap Exposure Lets Attackers Copy Millions of AWS Resources Between Scans
    Temporary public AWS resources can be copied by attackers before cloud security scans detect them.

    • Applies to AWS customers using RDS snapshots, DocumentDB snapshots, AMIs, and SSM documents
    • Vulnerable resources are briefly made public due to customer misconfigurations during creation or modification
    • Attackers monitor and copy exposed snapshots within minutes before CSPM and CNAPP tools scan again
    • Exposure windows often last less than two minutes, too short for daily security scans to catch
    • Copied snapshots contain sensitive data including AWS account IDs, emails, secrets, and financial info
      πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News

πŸ“° UNDER-REPORTED

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check