π΅οΈ RESEARCH & DEEP DIVES
- Claude Code Drove a Gentlemen Ransomware Affiliateβs Intrusion
A suspected Gentlemen affiliate used Claude Code throughout ransomware intrusions against at least eight organizations.- Victims included an Australian energy utility, a Mauritius financial firm, manufacturers, and IT and distribution companies.
- The operator targeted internet-exposed VPN appliances, LDAP credentials, domain infrastructure, backups, and SQL databases.
- Claude Sonnet 4.6 interactively refined commands and attack steps from terminal output.
- The actor used FortiGate LDAP pass-back attacks, a hidden VPN account named "test," and CrackMapExec for network discovery.
- Live SQL databases were backed up, compressed, staged, and exfiltrated.
π Source: gambit.security Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News, cryptika.com (discovered)
π ADVISORIES
- Apple Patches Dozens of WebKit Flaws in iOS and macOS Updates
Apple patched dozens of WebKit vulnerabilities across iOS, iPadOS, and macOS.- iOS 26.6.1 and iPadOS 26.6.1 affect supported iPhones and iPads; macOS Tahoe 26.6.2 affects Macs.
- macOS Tahoe 26.6.2 fixes 29 vulnerabilities, while iOS and iPadOS 26.6.1 fix 30.
- iOS 18.7.10 and iPadOS 18.7.10 fix 129 vulnerabilities on older devices.
- WebKit flaws could crash Safari, corrupt memory, expose sensitive data, escape the sandbox, or enable data exfiltration.
π Source: support.apple.com Β· π Coverage: securityweek.com Β· π via SecurityWeek
π CVEs & KEV
-
CVE-2026-15371 β CVSS 8.1 β Velociraptor Stored XSS in URL column typesVelociraptor's web GUI allows spec...
-
CVE-2026-75091 β CVSS 7.2 β Quill Forms through 5.7.1 - Unauthenticated Stored Cross-Site ScriptingThe Quill F...