π₯ BREACHES & INCIDENTS
- Baylor Genetics hack exposed sensitive patient and employee data
Baylor Genetics disclosed that a June cyberattack exposed sensitive patient and employee information.- Baylor Genetics patients and current or former employees were affected.
- Patient data potentially included names, birth dates, testing information, lab results, health insurance details and limited Social Security numbers.
- Employee data potentially included Social Security numbers, government IDs and financial account information.
- An unauthorized third party accessed parts of Baylor Geneticsβ network and stored data between June 11 and June 17, 2026.
- Baylor Genetics detected suspicious activity around June 15 and completed its data review on or around July 30.
π Source: baylorgenetics.com Β· π Coverage: cybersecuritydive.com Β· π via Cybersecurity Dive
π΅οΈ RESEARCH & DEEP DIVES
-
C2Looper Rust Backdoor Likely Supports Ransomware Operations via GitHub C2
Zscaler identified C2Looper, a Rust backdoor likely linked to ransomware attacks.- Organizations targeted in ransomware-related activity may be affected by C2Looper.
- C2Looper is a Rust-based backdoor used to establish footholds for lateral movement.
- It can execute arbitrary commands, perform reconnaissance, and deploy second-stage payloads.
- ThreatLabz assesses with low-to-medium confidence that a multi-stage ClickFix chain delivers it.
- The malware uses GitHub for command-and-control communications.
π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
-
MCPwned Presentation Details a Skeleton-Key Vulnerability in MCP Servers
Jonathan Leitschuh presented MCPwned, a vulnerability affecting MCP servers.- The issue applies to Model Context Protocol servers used by AI assistants.
- MCPwned describes one βskeleton keyβ vulnerability capable of compromising MCP servers.
- The supplied material does not detail the attack vector or exploitation steps.
- Jonathan Leitschuh presented the research at BSidesSF 2026.
π Source: youtube.com Β· π Coverage: infosecurity.us Β· π via securityboulevard.com (discovered)
π CVEs & KEV
-
CVE-2026-75045 β CVSS 9.1 β In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an una...
-
CVE-2026-75060 β CVSS 8.4 β In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthen...
-
CVE-2026-75048 β CVSS 8.2 β In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-bloc...
-
CVE-2026-75051 β CVSS 8.1 β In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer betwe...
-
CVE-2026-75044 β CVSS 8.1 β In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missin...
-
CVE-2026-75056 β CVSS 7.8 β In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was p...
-
CVE-2025-27772 β CVSS 7.4 β Uptrain vulnerable to remote code execution via
/new_runendpointUpTrain is... -
CVE-2025-27771 β CVSS 7.4 β Uptrain vulnerable to remote code execution via
/add_promptsendpointUpTrai... -
CVE-2026-75050 β CVSS 7.1 β In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possib...
-
CVE-2026-75049 β CVSS 6.5 β In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user...
-
CVE-2026-75047 β CVSS 6.5 β In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decom...
-
CVE-2026-75054 β CVSS 6.3 β In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI ...
-
CVE-2026-75057 β CVSS 6.2 β In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in pl...