π΅οΈ RESEARCH & DEEP DIVES
-
CISA Adds Ray Code-Injection Flaw CVE-2025-62593 to KEV Catalog
CVE-2025-62593
CISA added a Ray code-injection flaw to its exploited-vulnerabilities catalog.- Ray developers and users may be affected.
- CVE-2025-62593 is a Ray code-injection vulnerability that enables remote code execution.
- The flaw is exploitable through Firefox and Safari.
- CISA added the vulnerability to KEV on August 18, 2026; exploitation in ransomware campaigns is listed as unknown.
π Source: github.com Β· π Coverage: cisa.gov Β· π via CISA KEV
-
CircleCI MCP Server Exposed to Unauthenticated RCE via Allowlist Bypass
CircleCIβs MCP server is vulnerable to unauthenticated remote code execution.- The issue affects users running CircleCIβs MCP server with AI assistants such as Claude or Cursor.
- The MCP server allows unauthenticated remote code execution.
- Its Host/Origin allowlist can be bypassed by any non-browser client.
- The issue is tracked as GHSA-xv5j-cwgj-22r4; no CVE identifier is listed.
π Source: reddit.com Β· π Coverage: remedio.io Β· π via r/netsec
-
Certighost flaw lets domain users abuse Enterprise CAs for privilege escalation
CVE-2026-54121
CVE-2026-54121 lets a standard domain user escalate privileges through an Enterprise CA.- Active Directory environments using Enterprise Certificate Authorities are affected.
- CVE-2026-54121 can let a standard domain user turn an Enterprise CA into a Domain Controller.
- The flaw abuses an AD CS enrollment chase or callback path.
- The CA trusts requester-supplied attributes when resolving the identity placed in an issued certificate.
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
-
AI-authored GitHub Actions change exposed Snowflake repo to workflow injection
Wiz found that Copilot Autofix introduced a workflow injection flaw in a Snowflake repository.- Snowflakeβs public snowflakedb/snowflake-connector-net repository was affected.
- The jira_issue.yml workflow allowed unauthenticated GitHub issue titles to execute arbitrary commands on a GitHub Actions runner.
- Copilot Autofix co-authored commit 4a1b8ce on June 18, 2026, replacing env-and-jq parsing with direct shell interpolation of the issue title.
- Wiz Red Agent exploited the flaw on June 23 using a crafted issue title and exfiltrated Jira credentials to subdomain.oast.me from runner IP 20.106.182.197.
- The exposed token authenticated as qa@snowflake.net and provided read access to Snowflake Jira projects.
π Source: github.com Β· π Coverage: wiz.io Β· π via @metacurity@infosec.exchange
-
Operation ASTERIX Exposed a Crypto-Fraud Pipeline Using AI-Assisted Tooling
Rapid7 uncovered an exposed infrastructure supporting a cryptocurrency fraud operation.- Cryptocurrency users were targeted by the operation.
- The exposed server held phone-number datasets, validated leads, phishing panels, fake wallets, and exfiltration tools.
- Vishing and phishing workflows used voice-dialing scripts and impersonation lures.
- AI coding assistants helped build Electron applications, obfuscate code, modify phishing infrastructure, and package malware.
- Rapid7-listed infrastructure included 136.0.213.184:1337 and atechservicecentre.co.uk.
π Source: github.com Β· π Coverage: rapid7.com Β· π via rapid7.com (discovered)
-
CrowdStrike Trains AI to Reason Through Security Detection Triage
CrowdStrike developed reasoning-enabled AI models for detection triage.- CrowdStrike Charlotte AI triage models assess security detections.
- The models classify alerts as true positives or false positives with calibrated confidence scores.
- NVIDIA Nemotron-powered models weigh command lines, behavioral context, and other signals.
- Step-by-step reasoning produces a transparent chain before issuing a verdict.
π Coverage: crowdstrike.com Β· π via CrowdStrike Blog
-
Detecting NTDS.dit Extraction Attempts on Domain Controllers
Attackers may extract NTDS.dit from domain controllers to steal Active Directory credentials.- Active Directory environments and domain controllers are affected.
- NTDS.dit contains directory objects, password hashes, and other identity data.
- Attackers can copy or extract the database for offline credential attacks and domain access.
- Shadow copies can be used to access and copy ntds.dit from the domain controller.
π Coverage: clearpathsecurity.co.uk Β· π via securityboulevard.com (discovered)
π CVEs & KEV
-
CVE-2026-19693 β CVSS 8.1 β extract-zip arbitrary file write outside the destination directory via a syml...
-
CVE-2026-16138 β CVSS 8.0 β Remote code execution via unsafe deserialization in Progress ShareFile Storag...
-
CVE-2026-15218 β CVSS 7.9 β Models-as-a-service: red hat openshift ai: maas-api and maas-controller servi...
-
CVE-2026-59910 β CVSS 7.8 β Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz...
-
CVE-2026-56686 β CVSS 7.8 β Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz...
-
CVE-2026-56090 β CVSS 7.3 β Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Searc...
-
CVE-2026-56685 β CVSS 7.3 β Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutraliz...
-
CVE-2026-68821 β Microsoft App Installer β CVSS 7.3 β Pretty laughable/predictable MS response
-
CVE-2026-16137 β CVSS 7.2 β Path traversal via unsanitized upload filename leads to arbitrary file write ...
-
CVE-2026-16139 β CVSS 7.2 β Arbitrary file write via path traversal in Progress ShareFile Storage Zones C...
-
CVE-2026-59909 β CVSS 7.1 β Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vuln...