View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Brazilian Government Health Platform Exposed 79GB of Sensitive Data

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Brazilian Government Health Platform Exposed 79GB of Sensitive Data Online Brazil's Health Surveillance Information System (SISVISA) platform exposed 79GB of sensitive data publicly without password protection or encryption.
    • Exposed data includes 102,215 documents with personally identifiable information, identification records, contact details, and health compliance information
    • Data exposure discovered by researcher Jeremiah Fowler who reported it to authorities
    • Exposure included inspection reports, licensing applications, and backups related to public health surveillance ๐Ÿ“Ž Coverage: expressvpn.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange

๐Ÿ”“ CVEs & KEV

  • CVE-2026-15307 โ€” CVSS 8.8 โ€” Server-side file-write and request forgery via spatial lookups
  • CVE-2026-56848 โ€” CVSS 7.5 โ€” A flaw in Node.js HTTP/2 handling allows nghttp2_session_mem_send() to be corrupted
  • CVE-2026-34486 โ€” Apache Tomcat โ€” CVSS 7.5 โ€” Apache Tomcat Missing Encryption of Sensitive Data Vulnerability [KEV]
  • CVE-2026-18775 โ€” CVSS 6.3 โ€” NousResearch hermes-agent Browser Tooling browser_tool.py browser_snapshot service
  • CVE-2026-18774 โ€” CVSS 6.3 โ€” NousResearch hermes-agent xAI Image Generation Provider image_gen_provider.py flaw
  • CVE-2026-15920 โ€” CVSS 6.1 โ€” Potential cross-site scripting via URLField values in the admin
  • CVE-2026-15830 โ€” CVSS 5.3 โ€” Potential denial-of-service vulnerability via nested geometry collections
  • CVE-2026-15337 โ€” CVSS 5.3 โ€” Potential denial-of-service vulnerability in check_for_language()
  • CVE-2026-18556 โ€” N-able N-central โ€” CVSS โ€” โ€” N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability [KEV]

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Hackers Exploit Microsoft Copilot to Hijack CEO Emails and Redirect Wire Transfers Attackers weaponize Microsoft Copilot to take over CEO accounts and steal wire transfers.

    • Targets Microsoft 365 users with Microsoft Copilot AI assistant enabled
    • Attack begins with a compromised employee inbox to escalate access to CEO account
    • Copilot abused to create stealth inbox rules hiding sign-in alerts and aid reconnaissance
    • Copilot drafts convincing phishing emails mimicking victim's style to bypass MFA via MITM proxy
    • Attackers use Copilot to identify pending $247,500 wire transfer and redirect funds fraudulently ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Critical Code Injection Flaw in IBM Langflow OSS 1.0.0 to 1.10.0 Enables Remote Code Execution CVE-2026-9198 IBM Langflow OSS versions 1.0.0 to 1.10.0 have a critical code injection vulnerability allowing full remote code execution.

    • Vulnerability allows unauthenticated attackers to mint SUPERUSER tokens via /api/v1/auto_login
    • Attack chains token minting with /api/v1/validate/code endpoint to execute arbitrary code using exec()
    • Leads to full remote code execution on default Langflow deployments without authentication ๐Ÿ“Ž Coverage: nvd.nist.gov ยท ๐Ÿ“„ Original: ibm.com ยท ๐Ÿ‘ via CISA KEV
  • Flowise prior to 3.1.3 vulnerable to RCE, SSRF bypass, and unauthenticated property injection CVE-2026-69257 CVE-2026-69258 CVE-2026-69259 Flowise drag & drop UI for building LLM flows has multiple critical vulnerabilities fixed in version 3.1.3.

    • CVE-2026-69259: Authenticated RCE via SQLite Record Manager node by overwriting database path and injecting shell syntax
    • CVE-2026-69258: Unauthenticated property injection allows control of flow execution context
    • CVE-2026-69257: SSRF protection bypass using IPv4-mapped IPv6 addresses enables requests to internal services ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Multiple critical vulnerabilities found in Veeam Service Provider Console before version 9.3 CVE-2026-58067 CVE-2026-58071 CVE-2026-58072 CVE-2026-58073 CVE-2026-58074 CVE-2026-58075 CVE-2026-64630 CVE-2026-64631 CVE-2026-64633 CVE-2026-64634 Veeam Service Provider Console has multiple vulnerabilities allowing remote code execution and data breaches.

    • Arbitrary file write leading to remote code execution (CVE-2026-58072)
    • Unauthenticated attacker can impersonate managed agents and steal credentials (CVE-2026-58073)
    • High-privileged users can execute arbitrary code on the server (CVE-2026-58074)
    • Low-privileged users can perform SQL injection to extract database contents (CVE-2026-64631) and access report data beyond shared scope (CVE-2026-64630) ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 Defensive-leaning breakdown of The Gentlemen intrusion using EtherRAT with Ethereum smart contract command and control.

    • Detection surface includes X-Bot-Server HTTP header on EtherRAT polling traffic
    • Scheduled task names: WinSvcUpdate2, WindowsUpdSvc31, WindowsUpdateSvc, SysUpdate
    • LOLBAS chain: certutil.exe fetches ๐Ÿ“Ž Coverage: reddit.com ยท ๐Ÿ‘ via r/netsec

โš ๏ธ UNDER-REPORTED

  • House probe finds Chinese telecom firms kept footholds in US networks despite FCC bans Chinese state-owned telecoms retained equipment and network ties in US after FCC restrictions, sustaining malicious infrastructure.
    • Applies to China Mobile, China Telecom, and China Unicom operating in the US
    • Equipment, data center space, and network connections persisted despite FCC revoking service authorizations from 2019 to 2022
    • Networks appeared in routing paths to Salt Typhoon espionage servers in 2024
    • Nearly 109,000 incidents of unauthorized US internet address hijacks linked to Chinese or Hong Kong networks
    • No definitive evidence China Mobile USA employees knew of Salt Typhoon, but network ties could aid Beijing's cyber espionage ๐Ÿ“Ž Coverage: nextgov.com ยท ๐Ÿ‘ via @metacurity@infosec.exchange

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check