π₯ BREACHES & INCIDENTS
-
Nutex Health says attackers stole data in cyberattack
Nutex Health says an unauthorized party exfiltrated data from its servers.- Nutex Health, a healthcare and services provider, is investigating the breach.
- An unauthorized third party accessed Nutex servers and exfiltrated information.
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
-
ASOS Reports Customer Account Access Using Compromised Credentials
ASOS reported unauthorized access to customer accounts using externally sourced credentials.- ASOS US Sales LLC customers were affected.
- Names, contact details, addresses, birth dates, linked social accounts, and partial payment-card data may have been accessed.
- Attackers used credentials obtained outside ASOS in a likely credential-stuffing or account-takeover attack.
- ASOS detected the activity on July 28, 2026, and confirmed it the next day; suspicious transactions were blocked or canceled.
π Source: oag.ca.gov Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News, cryptika.com (discovered)
π΅οΈ RESEARCH & DEEP DIVES
-
NVIDIA NemoClaw flaw lets malicious webpages poison local AI models
A malicious webpage can take control of NemoClawβs local Ollama server.- NemoClaw users running OpenClaw or other supported agents with local Ollama inference are affected.
- The exposed Ollama API can enumerate, delete, or modify local models.
- NemoClawβs Windows-host path binds Ollama to 0.0.0.0:11434 without authentication.
- DNS rebinding bypasses browser-origin checks and lets a webpage rewrite the modelβs Go chat template through /api/create.
π Source: oasis.security Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Attack Commands
ToxNetV2 uses NVIDIA AI to generate shell and SSH attack commands.- The botnet targets AArch64 Linux systems.
- ToxNetV2 operates as a peer-to-peer Linux botnet.
- It sends system and botnet data to an AI service for analysis.
- The malware converts selected AI responses into proposed shell and remote SSH commands.
π Source: techcrunch.com Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News, cryptika.com (discovered)
-
Attackers Obfuscate Cloud Metadata IPs Through Hostnames
Attackers are using obfuscated hostnames to scan cloud metadata services.- Cloud-hosted applications exposed to SSRF scans are affected.
- Literal IP blocklists can miss requests targeting 169.254.169.254.
- Observed hostnames include 169.254.169.254.nip.io and 169-254-169-254.sslip.io.
- Attackers also use 1u.ms for DNS rebinding and on-the-fly IP resolution.
π Coverage: isc.sans.edu Β· π via SANS ISC
-
Provenance Blockchain bug enabled unauthorized marker admin access
A Provenance Blockchain bug let users grant themselves marker-account admin control.- The flaw affected Provenance Blockchainβs marker accounts, including 82 live financial-asset markers on mainnet.
- Versions before 1.28.0 allowed unauthorized users to obtain marker-account administrator control without holding HASH tokens.
- A state-divergence bug enabled users to grant themselves administrative access.
- The issue was fixed in PR #2627 and released in version 1.28.0 on May 1, 2026.
π Source: github.com Β· π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
π ADVISORIES
-
Marimo Flaw Let Crafted Notebooks Execute MCP Commands in Edit Mode
Marimo fixed a flaw that let crafted notebooks execute attacker-supplied MCP commands.- Marimo notebook users running versions before 0.23.15 were affected.
- The code-injection flaw is tracked as CVE-2026-75149 and carries CVSS 8.7 under v4.
- A crafted notebook can supply an attacker-controlled MCP server command through its configuration.
- Opening the notebook in edit mode launches the command as a local subprocess before cells execute.
- The attack requires victim interaction but does not require attacker authentication.
π Source: osv.dev Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
Interpol operation arrests 58 in Black Axe-linked financial crime crackdown
Interpol arrested 58 people in an operation targeting Black Axe-linked financial networks.- Operation Jackal IV targeted Black Axe and other Africa-based criminal groups across four continents.
- Authorities identified 263 suspects and arrested 58 people, including 39 in South Africa.
- Networks conducted business email compromise, romance and investment scams, money laundering, vehicle trafficking and sextortion.
- Criminals used call centers, electronic wallets, shell companies, remittance services and social media coercion.
- An Argentina-based Crime-as-a-Service network supplied website domains and laundering support to West African groups; investigators linked 196 people to it.
π Coverage: cyberscoop.com Β· π via CyberScoop
-
cisa-red-team-soc-assessments β CISA Advisories
-
π Source for Fake Microsoft SysScan Sites Push Antivirus Removal and Remote Access Scams β malwarebytes.com
-
π Source for Microsoftβs August 2026 updates fix 421 vulnerabilities, including one exploited flaw β msrc.microsoft.com
-
π Source for WhatsApp Adds Multiple Passkeys and Stronger Two-Step Verification β blog.whatsapp.com
π CVEs & KEV
-
CVE-2026-77998 β CVSS 10.0 β Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via...
-
CVE-2026-57863 β CVSS 8.7 β Crater Invoice 6.0.6 Path Traversal RCE via update/unzip endpointCrater Invoi...
-
CVE-2026-79655 β CVSS 7.8 β Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/...
-
CVE-2026-55525 β CVSS 7.5 β PraisonAI: SSRF via redirect-following in praisonaiagents web_crawlPraisonAI ...
-
CVE-2026-63076 β CVSS 7.5 β Invalid Pointer Dereference in CMP Server via Crafted protectionAlgIssue summ...
-
CVE-2026-63075 β CVSS 7.5 β QUIC ACK-only Packet Retention Can Cause Memory ExhaustionIssue summary: When...
-
CVE-2026-63072 β CVSS 7.5 β Heap Buffer Overflow in CMS Key UnwrappingIssue summary: OpenSSL CMS decrypti...
-
CVE-2026-54874 β CVSS 7.5 β Excessive Memory Use Buffering DTLS Records for a Future EpochIssue summary: ...
-
CVE-2026-18798 β CVSS 7.5 β QUIC Server May Trigger Double Free When Processing INITIAL PacketIssue summa...
-
CVE-2026-14457 β CVSS 7.5 β RPK Server Signature Algorithm Selection Can Dereference a Missing Certificat...
-
CVE-2026-55529 β CVSS 6.9 β PraisonAI: Origin validation bypass in MCP HTTP Stream transport allows brows...