Security Intel Feed
Cyber Hose
Page 12 of 44
Vendor Bulletins & Advisories
Microsoft to Make Passkeys Default in Entra ID, Retire SMS MFA
Read digest- Microsoft to Make Passkeys Default in Entra ID, Retire SMS and Voice MFA — Microsoft will make passkeys the default authentication method in Entra ID, ending SMS and voice MFA by February 2027.
- CVE-2026-18438 — Templately through 3.7.1 — Authenticated Arbitrary File Upload to RCE — A CVSS 8.8 flaw in the Templately WordPress plugin allows authenticated contributors to achieve remote code execution via arbitrary file upload.
Vulnerabilities & CVEs
Critical TrueBooker Account Takeover Flaw (CVE-2026-16142)
Read digest- CVE-2026-16142 — CVSS 9.8 — TrueBooker through 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Object References — A CVSS 9.8 IDOR flaw in TrueBooker through version 1.2.6 enables unauthenticated account takeover.
- CVE-2026-15826 — CVSS 9.8 — User Profile Builder through 3.16.4 - Unauthenticated Authentication Bypass via Type Confusion — A CVSS 9.8 type confusion vulnerability in User Profile Builder through 3.16.4 allows unauthenticated authentication bypass.
Vulnerabilities & CVEs
Paymob for WooCommerce SQL Injection (CVE-2026-15205)
Read digest- CVE-2026-15205 — CVSS 8.6 — Paymob for WooCommerce before 4.1.9 - Unauthenticated SQL Injection via Paymob Cal... — An unauthenticated SQL injection vulnerability affects Paymob for WooCommerce before version 4.1.9.
- CVE-2026-18039 — CVSS 8.1 — Essential Addons for Elementor before 6.7.2 - Unauthenticated Privilege Escalation... — An unauthenticated privilege escalation flaw affects Essential Addons for Elementor before version 6.7.2.
Vulnerabilities & CVEs
Critical Auth Bypass in User Session Synchronizer (CVE-2026-15341)
Read digest- CVE-2026-15341 — User Session Synchronizer through 1.4.0 - Unauthenticated Authentication Bypass — A CVSS 9.8 unauthenticated authentication bypass affects User Session Synchronizer through version 1.4.0.
- CVE-2026-15303 — 6Storage Rentals through 2.27.0 - Unauthenticated Account Takeover — A CVSS 9.8 unauthenticated account takeover via the email parameter affects 6Storage Rentals through version 2.27.0.
- CVE-2026-14484 — RapiSafe through 1.0.4 - Unauthenticated Arbitrary File Deletion — A CVSS 9.1 unauthenticated arbitrary file deletion flaw affects RapiSafe through version 1.0.4.
Vulnerabilities & CVEs
CVE-2026-74243: Quay unauthenticated secscan endpoint flaw
Read digest- CVE-2026-74243 — Quay exposes an unauthenticated secscan notification endpoint when PSK is unset, rated CVSS 6.5.
Threat Research & Deep Dives
Metasploit adds 13 exploit modules, HTTP profiles and ARM shells
Read digest- Metasploit adds 13 exploit modules, HTTP profiles and ARM shells — Rapid7 added 13 new modules and payload features including malleable HTTP profiles and AArch64 reverse-TCP shells.
- Semaphore Git URL Handling Enables OS Command Injection — CVE-2026-73682 (CVSS 8.8) allows Manager or Owner users to inject OS commands via git_url repository handling.
- Cockpit CMS Flaw Enables Authenticated Command Injection via FFmpeg — CVE-2026-73680 (CVSS 8.8) allows authenticated users with upload permission to execute commands via FFmpeg filenames.
Active Exploits & Incidents
Hackers accused of €30M bank fraud exploiting service-provider flaw
Read digest- Hackers accused of €30M bank fraud exploiting service-provider flaw — Attackers stole roughly €30 million by exploiting a faulty software update in a financial service provider's payment-processing system.
- CVE-2026-73849 — A CVSS 9.8 vulnerability in emlog allows unauthenticated reinstallation via install.php.
- CVE-2026-19682 — A CVSS 9.4 command injection vulnerability exists in Security Center.
Threat Research & Deep Dives
Jewelbug Runs Government Espionage and Crypto Fraud From One Panel
Read digest- Jewelbug Runs Government Espionage and Crypto Fraud From One Control Panel — Jewelbug compromised 15+ government webmail tenants and stole 580,000+ cookies using shared infrastructure for espionage and crypto fraud.
- Third-party breach exposes data from 300 Scottish prosecution staff — A supplier breach exposed employment data of around 300 COPFS staff, though casework systems were unaffected.
- ExfilSquad targets misconfigured Microsoft Power Pages portals — ExfilSquad exfiltrated customer and business data from publicly accessible Power Pages portals with overly broad anonymous permissions.
- CVE-2026-19871 — Hard-coded credentials in Prospero Flow CRM — A CVSS 9.3 hard-coded credential vulnerability in Prospero Flow CRM employee onboarding leads this CVE roundup.
Active Exploits & Incidents
Hackers exploit macOS Screen Sharing bypass to deploy Monero miners
Read digest- Hackers exploit macOS Screen Sharing bypass to deploy Monero miners — CVE-2026-65400 allows unauthenticated network attackers to access macOS Screen Sharing and deploy Monero cryptocurrency miners.
- TP-Link Aginet Flaws Enable Authentication Bypass and Device Takeover — TP-Link disclosed flaws in Aginet devices that allow authentication bypass and full device takeover.
- Cloudflare Gateway detects and controls MCP traffic — Cloudflare Gateway now identifies MCP requests using protocol-level heuristics and offers controls to block direct connections.
- Week 33 roundup covers sextortion, Gunra ransomware and Defender bypass — SentinelOne highlighted a sextortion conviction, Gunra ransomware, and a Microsoft Defender bypass called ShieldBreak.
Active Exploits & Incidents
Clop claims 89GB Shell data theft in wider enterprise software
Read digest- Clop claims 89GB Shell data theft in wider enterprise software campaign — Clop allegedly exploited one unpatched PTC Windchill flaw across nearly 50 companies, stealing 89GB from Shell alone.
- Dysphoria Botnet Compromises 296,000 IoT Devices for DDoS and C2 Relays — A botnet of roughly 296,000 compromised IoT devices uses known router and camera flaws for DDoS attacks and C2 relaying.
- Trivy Compromise, Not LiteLLM, Drove Most of 2,500-Organization Exposure — The earlier Trivy compromise, not the brief malicious LiteLLM PyPI releases, accounted for most of the 2,500-org exposure.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check