๐ฅ BREACHES & INCIDENTS
- Amgen reports cloud data breach exposing patient health and proprietary info
Amgen suffered a cloud data breach exposing patient and corporate information.- Applies to Amgen, a biotechnology company in California
- Patient protected health information and proprietary corporate data stolen
- Data stored in multiple cloud systems operated by third-party providers
- Attack detected in July 2026; investigation ongoing with forensic experts
- No disclosed details on attack method, affected cloud providers, or threat actors
๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ต๏ธ RESEARCH & DEEP DIVES
-
Adform's ad platform script compromised to steal cryptocurrency via clipboard hijacking
Adform's advertising script was compromised to replace crypto wallet addresses with attacker-controlled ones.- Applies to websites using Adform's ad platform, including its DSP, SSP, and ad servers
- Malicious script trojanized 'trackpoint-async.js' served from s2.adform.net
- Script monitors clipboard for Bitcoin, Ethereum, or TRON wallet addresses and replaces them with attacker addresses
- Malware also rewrites wallet addresses displayed on web pages
- Malicious code communicated with attacker server at 84.32.102.230:7744 and was undetected by antivirus
- Incident discovered July 27, 2026; malicious code removed shortly after
๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
-
Midnight Blizzard's Storm-2945 targets travelers via hotel captive portals for malware and credential theft
Midnight Blizzard's Storm-2945 exploits hotel captive portals to deliver malware and steal traveler credentials.- Targets hospitality sector networks worldwide, including hotels and conference centers
- Compromises captive portal sign-in systems to redirect traffic through attacker-controlled infrastructure
- Delivers malware posing as browser or OS updates, including Windows RATs with extensive espionage capabilities
- Uses adversary-in-the-middle phishing with doppelganger domains mimicking Microsoft services
- Employs AI-augmented operations and ClickFix social engineering to trick users into installing malware
๐ Coverage: microsoft.com ยท ๐ Original: microsoft.com ยท ๐ via Microsoft Security Blog
๐ CVEs & KEV
-
ComfyUI 0.23.0 vulnerable to unauthenticated remote code execution via pickle deserialization
CVE-2026-68771
ComfyUI 0.23.0 has an unauthenticated RCE vulnerability via unsafe pickle deserialization.- Applies to ComfyUI version 0.23.0
- Vulnerability in LoadTrainingDataset node allows arbitrary Python code execution
- Attackers upload crafted shard_*.pkl files via unauthenticated POST /upload/image endpoint
- Arbitrary code executed when torch.load deserializes attacker-controlled pickle payload
- No authentication required; CVSS 9.8 critical severity
๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Critical RCE Vulnerability in sentence-transformers via Local Model Load Bypass
CVE-2026-68770
sentence-transformers allows arbitrary code execution when loading local models despite security flags.- Applies to all versions of the sentence-transformers library
- Vulnerability in import_module_class helper allows bypass of trust_remote_code=False
- Attackers controlling model directory can execute malicious Python code at model load
- Exploitation requires placing crafted files like modeling_*.py referenced in modules.json
- Critical severity with CVSS 9.8, no privileges or user interaction needed
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Savon Ruby SOAP Client Vulnerable to Code Execution via WSDL Operation Names (CVE-2026-53510)
CVE-2026-53510
Savon Ruby SOAP client versions before 2.17.2 allow remote code execution via crafted WSDL operation names.- Applies to Savon Ruby SOAP client versions from 0.9.8 up to 2.17.2
- Vulnerability in Savon::Model.all_operations method evaluating WSDL operation names as Ruby code
- Attacker-controlled WSDL operation names are interpolated into Ruby source passed to module_eval
- Allows remote attackers to execute arbitrary Ruby code within the application process
- Fixed in Savon version 2.17.2
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
CVE-2026-53599 โ CVSS 7.5 โ Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename t...
-
CVE-2026-62999 โ CVSS 7.5 โ Copier: Percent-encoded dot segments in template URLs can allow trusted-prefi...
-
CVE-2026-18394 โ CVSS 7.4 โ Incorrect authorization in Strands Agents Tools http_request proxy credential...
-
CVE-2026-65981 โ CVSS 7.1 โ Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user...
-
CVE-2026-45086 โ CVSS 5.4 โ Decidim: Forms admin question editor lacks authorizationDecidim is a particip...
-
CVE-2026-62324 โ CVSS 5.4 โ Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement ...
-
CVE-2026-55825 โ CVSS 3.1 โ Contao: Possible path traversal in job download URIsContao is an Open Source ...
-
CVE-2026-53551 โ CVSS โ โ free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal serv...
-
CVE-2026-62959 โ CVSS โ โ Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme...
-
CVE-2026-65841 โ CVSS โ โ Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses...