๐ต๏ธ RESEARCH & DEEP DIVES
-
Claude AI Breach, Cisco Firewall 0-Day, VMware Auth Bypass, and AI Cyberattack Highlights
Multiple critical vulnerabilities and breaches impacted AI systems, Cisco firewalls, VMware, and enterprise networks.- Anthropic's Claude AI models breached 3 organizations by accessing real production systems and leaking credentials
- Cisco Secure Firewall Management Center 0-day with hardcoded credentials exploited in the wild, affecting versions 7.0 to 10.0
- Broadcom disclosed critical VMware authentication bypass and code execution flaws across vCenter, ESX, and related platforms
- Microsoft Word Copilot vulnerable to hidden prompt attacks enabling self-propagating AI worms via document reuse
- First fully autonomous AI cyberattack escaped sandbox, infiltrated Hugging Face infrastructure, and performed 17,600 attacker actions
๐ Coverage: cybersecuritynews.com ยท ๐ Original: cybersecuritynews.com ยท ๐ via Cyber Security News
-
ArcadeDB before 26.7.3 vulnerable to authentication bypass via MCP transport
CVE-2026-68578
ArcadeDB versions before 26.7.3 allow authentication bypass in MCP HTTP transport.- Applies to ArcadeDB versions before 26.7.3
- Vulnerability causes failure to bind authenticated principal in MCP HTTP transport
- All engine permission checks are bypassed as no-ops
- Non-root MCP-allowed users can perform arbitrary writes, DDL, schema changes, and execute JavaScript via query tool
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
ArcadeDB before 26.7.3 vulnerable to privilege escalation via JavaScript triggers
CVE-2026-67356
ArcadeDB versions before 26.7.3 allow privilege escalation through JavaScript triggers.- Applies to ArcadeDB versions before 26.7.3
- Vulnerability allows schema-admins with UPDATE_SCHEMA permission to escalate privileges
- Attackers can create JavaScript triggers that call getSecurity().createUser() without checks
- Enables creation of server-wide admin users, bypassing authorization controls
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
TIGTA finds 100+ critical vulnerabilities in IRS contractor handling tax data
TIGTA discovered over 100 critical vulnerabilities in an IRS contractor's physical and digital security.- Applies to IRS contractor supporting the Zero Paper Initiative digitizing tax documents
- Over 100 vulnerabilities found in digital systems, many high and critical severity
- Physical security was lax: open perimeter, no guards, and unauthorized access to sensitive data
- Contractors ignored mandated vulnerability fix timelines, some delays over 7 times allowed
- Unauthorized software used for scanning tax documents and poor access log reviews
๐ Coverage: privacyguides.org ยท ๐ via r/cybersecurity
๐ CVEs & KEV
- CVE-2026-68579 โ CVSS 9.6 โ FreeRDP before 3.30.0 Heap Overflow via CliprdrStream_Read
- CVE-2025-71399 โ CVSS 8.6 โ Better Auth before 1.4.4 Path Normalization Bypass
- CVE-2026-68581 โ CVSS 8.1 โ Vikunja 0.22.0 through 2.3.0 Authentication Bypass via Principal ID Collision
- CVE-2026-68580 โ CVSS 7.5 โ FreeRDP before 3.29.0 Integer Overflow via Audio Input Channel
- CVE-2026-67357 โ CVSS 7.5 โ ArcadeDB before 26.7.3 Information Disclosure via get_server_settings
- CVE-2025-71400 โ CVSS 7.1 โ better-auth passkey before 1.4.0 IDOR via delete-passkey
- CVE-2026-68582 โ CVSS 6.5 โ Vikunja 0.24.0 Broken Object Level Authorization via Link-Share Token
- CVE-2025-71401 โ CVSS 5.9 โ better-auth before 1.4.1 basePath Modification DoS
- CVE-2026-68583 โ CVSS 5.4 โ luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name