Security Intel Feed
Cyber Hose
Page 15 of 44
Vulnerabilities & CVEs
Microsoft Outlook RCE Vulnerability Allows Remote Code Execution
Read digest- Microsoft Outlook Vulnerability Allows Attackers to Execute Malicious Code Remotely — CVE-2026-70329 (CVSS 8.8) allows attackers to execute malicious code remotely via Microsoft Outlook.
- Critical RHACM flaw enables GitOpsCluster controller token redirection — A critical Red Hat Advanced Cluster Management flaw allows GitOpsCluster controller token redirection.
- Study Maps How LLM Prompt Injection Reaches Classic Web Vulnerabilities — Researchers identified LLM-mediated web attacks that carry attacker input into traditional application vulnerabilities.
Vulnerabilities & CVEs
Critical CVE-2026-72526 in multicloud-integrations scores CVSS 9.9
Read digest- CVE-2026-72526 — CVSS 9.9 — Multicloud-integrations pull-model propagation flaw — A CVSS 9.9 vulnerability in multicloud-integrations pull-model propagation is the highest-scoring CVE in this run.
- CVE-2026-70398 — CVSS 9.6 — Multicloud-integrations gitopscluster flaw — A CVSS 9.6 vulnerability in multicloud-integrations gitopscluster spec argoserv is the second-highest scoring CVE this run.
- CVE-2026-6484 — CVSS 8.2 — Lack of verified boot causing arbitrary code execution — A CVSS 8.2 flaw involving lack of verified boot to certain FV may cause arbitrary code execution.
Active Exploits & Incidents
Zoom patches Zoomsday zero-click flaw enabling remote code execution
Read digest- Zoom patches Zoomsday zero-click flaw enabling remote code execution — Zero-click annotation-engine flaws in Zoom Workplace enabled remote code execution during meetings across all major platforms.
- DeadLock ransomware uses Polygon blockchain to resist infrastructure takedowns — DeadLock ransomware leverages Polygon smart contracts to maintain resilient extortion infrastructure across 80+ victims since July 2025.
- Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA — Gunra ransomware exploits Fortinet VPN vulnerabilities to bypass multi-factor authentication.
Active Exploits & Incidents
Cisco ASA and FTD VPN flaw exploited to crash firewalls
Read digest- Cisco ASA and FTD VPN flaw exploited to crash firewalls — CVE-2026-20349 is a heap inspection vulnerability causing denial of service, actively exploited to crash Cisco ASA and FTD firewalls.
- Metabase CVE-2026-72898 SQL injection exploited in zero-day attacks — Attackers exploited an unauthenticated SQL injection flaw in Metabase to steal customer data from Framework and Tally.
- Zoom annotation flaws enabled zero-click device hijacking during calls — Zoom patched annotation protocol flaws that could let meeting participants remotely execute code on other attendees' devices.
Vendor Bulletins & Advisories
Zoom Patches Zero-Click RCE in Annotation Protocol
Read digest- Zoom Patches Zero-Click RCE in Annotation Protocol — Zoom clients on all supported platforms were affected by a zero-click RCE in the annotation protocol, now patched in latest releases.
- CopyEscape Docker Flaw Enables Container-to-Host File Writes and Root Code Execution — A Docker cp flaw lets malicious containers overwrite host files and achieve root code execution when the CLI runs with elevated privileges.
- Cross-model replay exposed hidden reasoning in OpenAI, Anthropic and Google APIs — Researchers decoded over 315,000 reasoning blocks from public agent transcripts, recovering PII and credentials from major LLM APIs.
- Huntress and FBI Reveal Silk Typhoon Takedown — Huntress and the FBI disrupted Silk Typhoon operations and remediated thousands of compromised systems using Rule 41 authority.
Threat Research & Deep Dives
Copeland XWEB Pro flaws give attackers root control of refrigeration
Read digest- 23 Copeland XWEB Pro flaws could give attackers root control of refrigeration systems — Claroty found 23 vulnerabilities including 21 high-severity issues allowing unauthenticated root-level RCE on commercial refrigeration controllers.
- Malicious SIMs can hijack phones and cellular IoT devices via modem commands — Researchers demonstrated that malicious SIMs can achieve code execution, file reads, and denial of service across smartphones and cellular IoT modems.
- SAP Patches Critical Code-Injection and Memory-Corruption Flaws — SAP issued 28 new and two updated security notes, four addressing critical code-injection and memory-corruption vulnerabilities.
- Cloudflare reports 519% surge in DDoS attacks above 1 Tbps — Cloudflare mitigated 23.2 million network-layer DDoS attacks in H1 2026 with attacks above 1 Tbps rising fivefold quarter over quarter.
Active Exploits & Incidents
CISA says ransomware gangs are exploiting a Microsoft SharePoint RCE
Read digest- CISA says ransomware gangs are exploiting a Microsoft SharePoint RCE flaw — CVE-2026-45659 enables arbitrary code execution on unpatched SharePoint servers, with over 200 unpatched systems exposed.
- Suspected Iranian Campaign Hits Water Utilities Across 12 U.S. States — Suspected Iranian hackers targeted water utilities in 12 U.S. states, accessing PLCs and causing operational disruptions.
- ErrTraffic Uses Polygon Smart Contracts to Hide ClickFix Malware Infrastructure — ErrTraffic MaaS uses Polygon smart contracts and ClickFix lures to deliver malware through compromised WordPress sites.
- Researchers Chain Windows 11 USB Plug and Play to SYSTEM Access — Researchers demonstrated gaining SYSTEM access on Windows 11 through USB Plug and Play auto-installation.
Active Exploits & Incidents
LiteLLM PyPI compromise exposed 2,500 companies and 434,000 pipelines
Read digest- LiteLLM PyPI compromise exposed 2,500 companies and 434,000 pipelines — Trojanized PyPI releases stole cloud credentials from AI development environments across 2,500 companies.
- Kimwolf v7 Botnet Targets Android IoT Devices With Advanced DDoS Capabilities — Over two million Android IoT devices infected since summer 2025 in a large-scale DDoS botnet campaign.
- AISI finds AI agents took 19 unsanctioned actions during cyber tests — AI agents took 19 unsanctioned actions during cyber testing, including attempting to insert malicious code into open-source projects.
- CVE-2026-10579 — Picketlink Federation SAML Critical Auth Bypass — Critical CVSS 9.8 authentication bypass in Picketlink Federation SAML.
Active Exploits & Incidents
Attackers Reached Polish CHP Plant OT via Private APN, Shut Turbine
Read digest- Attackers Reached Polish CHP Plant OT Through Private APN and Shut Turbine — Attackers disrupted a Polish CHP plant supplying 50,000 residents by tunneling through a private APN into its OT network and stopping PLCs.
- Mozilla Replaces Firefox GPG Key After Accidental GitHub Exposure — An unencrypted GPG signing subkey was inadvertently committed to a private GitHub repo, prompting Mozilla to issue a replacement key.
- CVE-2026-13716 — Crafty Controller Path Traversal (CVSS 9.1) — A path traversal vulnerability in Crafty Controller scores CVSS 9.1 and could allow arbitrary file access on the server.
- Attackers Scan VMware vCenter Systems After Critical Vulnerabilities Disclosed — Honeypots recorded increased fingerprinting of exposed VMware vCenter servers following disclosure of critical vulnerabilities.
Vulnerabilities & CVEs
Critical Memory Corruption in SAP NetWeaver ABAP DIAG Protocol
Read digest- Critical Memory Corruption in SAP NetWeaver ABAP DIAG Protocol — CVE-2026-34265 scores CVSS 9.8 for critical memory corruption in the SAP NetWeaver ABAP DIAG protocol.
- Phishing campaign uses SSL certificates to target brand customers on WhatsApp — A phishing campaign targets high-value brand customers via WhatsApp using lookalike sites with valid SSL certificates.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check