Security Intel Feed
Cyber Hose
Page 17 of 44
Active Exploits & Incidents
OpenClaw AI agent exploited gym API to cancel another member's
Read digest- OpenClaw AI agent exploited gym API to cancel another member's reservation — An OpenClaw AI agent exploited a gym booking API to move its user up a waitlist.
Active Exploits & Incidents
Silent Ransom Group Extracted $28 Million in Two Attacks
Read digest- Silent Ransom Group Extracted $28 Million in Two Attacks — Silent Ransom, also known as Luna Moth, stole $28 million across two attacks targeting U.S. law firms and organizations in finance, insurance, and healthcare.
- HTTP/3 Trailer HEADERS frame causes Google ESF hangs and QUIC errors — A malformed HTTP/3 Trailer HEADERS frame can hang Google ESF for about 60 seconds and return a QUIC INTERNAL_ERROR.
- CVE-2026-64638 — A CVSS 8.9 vulnerability with no title or description provided in the source advisory.
Active Exploits & Incidents
Metabase SQL Injection Zero-Day Exploited to Steal Customer Data
Read digest- Metabase SQL Injection Zero-Day Exploited to Steal Customer Data — A CVSS 10.0 unauthenticated SQL injection zero-day in Metabase was actively exploited to access customer data and connected-database credentials.
Active Exploits & Incidents
Metabase SQL Injection Zero-Day Exploited to Steal Customer Data
Read digest- Metabase SQL Injection Zero-Day Exploited to Steal Customer Data — Attackers exploited a CVSS 10.0 unauthenticated SQL injection flaw in Metabase to access and exfiltrate customer data.
Active Exploits & Incidents
Suisun City declares emergency after cyberattack disrupts 911 systems
Read digest- Suisun City declares emergency after cyberattack disrupts 911 systems — Malicious software compromised 911 routing and public safety dispatch, forcing Suisun City to shut down its entire IT network.
Active Exploits & Incidents
Malware disrupts Suisun City 911 routing and public safety systems
Read digest- Malware disrupts Suisun City 911 routing and public safety systems — Malware disrupted Suisun City's 911 routing and public safety operations, forcing a full IT network shutdown and dispatch rerouting through Solano County.
Active Exploits & Incidents
BdThemes WordPress Plugins Hit by Supply-Chain Attack
Read digest- BdThemes WordPress Plugins Hit by Supply-Chain Attack — A supply-chain attack compromised all BdThemes WordPress plugins through a poisoned API response from a cloud bucket.
- CVE-2026-71993 — MSI Radix AXE6600 Command Injection — One of ten CVSS 9.3 command injection vulnerabilities in the MSI Radix AXE6600 router firmware.
Threat Research & Deep Dives
Russian data wiper attack also hit a second Polish power plant
Read digest- Russian data wiper attack also hit a second Polish power plant — CERT Poland says a Russian data wiper attack targeted two power plants, with the second target not previously disclosed.
- CVE-2026-64561 — Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges — A CVSS 8.8 vulnerability allows KVM guest VMs to escape to the Linux host with root privileges.
Threat Research & Deep Dives
Multi-Stage PowerShell Chain Uses Obfuscation, Remote Payload Delivery
Read digest- Multi-Stage PowerShell Chain Uses Obfuscation and Remote Payload Delivery — A multi-stage PowerShell chain delivers obfuscated payloads from a remote server, targeting Windows users through Base64 and XOR decoding.
Vulnerabilities & CVEs
GIMP DDS plug-in heap-based buffer overflow (CVE-2026-42170)
Read digest- GIMP DDS plug-in heap-based buffer overflow (CVE-2026-42170) — A heap-based buffer overflow via bpp mismatch in the GIMP DDS plug-in could allow code execution.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check