View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Zoom Patches Zero-Click RCE in Annotation Protocol

๐Ÿšจ ACTIVE EXPLOITATION

  • Huntress and FBI Reveal Silk Typhoon Takedown Huntress and the FBI disclosed a takedown targeting Silk Typhoon.
    • Huntress and the FBI conducted the operation against Silk Typhoon.
    • The action disrupted attackers and remediated thousands of compromised systems.
    • The operation used Rule 41 authority and precise threat visibility. ๐Ÿ“Ž Coverage: securityboulevard.com ยท ๐Ÿ‘ via securityboulevard.com (discovered)

๐Ÿ’ฅ BREACHES & INCIDENTS

  • Wesco investigates ExfilSquad claim of 2.6 million CRM records stolen Wesco is investigating a cloud CRM data-exfiltration claim by ExfilSquad.
    • Wesco is a global supply-chain and distribution company operating across roughly 50 countries.
    • ExfilSquad claimed to steal about 2.6 million Wesco CRM records.
    • The claimed data includes customer and employee PII, contact data, CRM profiles, business identifiers and authentication metadata.
    • Researchers linked ExfilSquad activity to improperly configured Microsoft Power Pages data tables; Wesco has not disclosed the breach path.
    • Wesco said it found no ransomware or malicious software and reported no business disruption. ๐Ÿ“„ Source: resecurity.com ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ”“ CVEs & KEV

  • CVE-2026-72920 โ€” CVSS 9.8 โ€” SeaweedFS Filer Unauthenticated IAM Access (CVE-2026-72920)
  • CVE-2025-31114 โ€” CVSS 9.3 โ€” Fooocus webui vulnerable to Remote Code ExecutionFooocus is an image generati...
  • CVE-2026-73069 โ€” CVSS 9.1 โ€” Twenty: SQL Injection in the searchVector Field Settings Allows Arbitrary P...
  • CVE-2026-19546 โ€” CVSS 8.8 โ€” Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via call...
  • CVE-2026-14380 โ€” Perl Dbi โ€” CVSS 8.8 โ€” Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via call...
  • CVE-2026-73072 โ€” CVSS 8.5 โ€” Vim: Heap Buffer Overflow when Loading a Spell FileVim is an open source, com...
  • CVE-2026-73076 โ€” CVSS 8.4 โ€” Vim: Arbitrary Command Execution via Malicious .VimballRecord Entry Replay ...
  • CVE-2026-73074 โ€” CVSS 7.1 โ€” Vim: Heap Buffer Overflow in Text Property HandlingVim is an open source, com...
  • CVE-2026-73070 โ€” CVSS 6.8 โ€” Vim: Stack Buffer Overflow in the Vim Socket ServerVim is an open source, com...

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • CopyEscape Docker Flaw Enables Container-to-Host File Writes and Root Code Execution CVE-2026-17106 CVE-2026-17106 lets malicious containers overwrite Docker host files through copy commands.
    • Docker Engine, Docker CLI, Docker Desktop, and Docker Sandboxes users are affected.
    • The docker cp and sbx cp commands can write outside the selected destination, including host files.
    • The exploit combines a filesystem race in archive creation with unsafe symlink handling during extraction.
    • Impact includes developer-account compromise and root code execution when

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check