Security Intel Feed
Cyber Hose
Page 2 of 44
Active Exploits & Incidents
Aurora Affiliate Used AI to Attack More Than 20 Organizations
Read digest- Aurora Affiliate Used AI to Attack More Than 20 Organizations — A Russian-speaking Aurora ransomware affiliate used Cursor AI to plan intrusions against more than 20 organizations across nine countries from April through July 2026.
- Two alleged TeamPCP hackers charged in Australia — Australian authorities charged two alleged TeamPCP members over supply-chain attacks that compromised more than 1,000 organizations and stole 500,000-plus credentials.
- PaperCut issues urgent security advisory for all NG/MF versions — PaperCut issued an urgent security advisory affecting all NG and MF versions, with indicators of compromise included.
- SparkRAT Campaign Targets Cambodia Using Vulnerable OPSWAT Driver — A Cambodia-focused campaign abused a vulnerable OPSWAT driver and signed Tencent binaries to deploy SparkRAT across multiple sectors.
Active Exploits & Incidents
Pro-Russian group claims DDoS attack on Norway’s public digital
Read digest- Pro-Russian group claims DDoS attack on Norway’s public digital services — A DDoS attack disrupted Norway’s shared government digital services including ID-porten, affecting millions of users.
- ATF confirms standalone system breach after Qilin ransomware claim — ATF confirmed a breach of a standalone system with no evidence of enterprise network compromise.
- Russian-Linked Groups Use Fake Google Drive Pages to Hijack Accounts — Russian-linked groups hijack targeted accounts using fake cloud-storage pages and OAuth abuse.
- ESET Identifies GuardBreaker LLM Safety-Evasion Technique in Ukraine Attack — Russia-aligned UAC-0099 used GuardBreaker to evade AI malware analysis in a Ukraine-targeted campaign.
Vendor Bulletins & Advisories
CISA Adds Six Actively Exploited Flaws to KEV Catalog
Read digest- CISA Adds Six Actively Exploited Flaws to KEV Catalog — CISA's KEV catalog update flags six vulnerabilities as actively exploited, requiring urgent remediation.
- Spring Security UnboundID LDAP Server Critical Admin Credential Exposure (CVE-2026-59270) — A CVSS 9.4 vulnerability in Spring Security's UnboundID LDAP Server exposes critical admin credentials.
- Joomla Extension Privileged Remote Code Execution (CVE-2026-77991) — A CVSS 9.4 privileged RCE vulnerability affects a Joomla extension from joomlaeventmanager.net.
Vendor Bulletins & Advisories
WatchGuard Agent Flaws Enable Unauthenticated Code Execution on
Read digest- WatchGuard Agent Flaws Enable Unauthenticated Code Execution on Windows — Two critical WatchGuard Agent for Windows vulnerabilities (CVSS 9.3 and 9.4) enable unauthenticated remote code execution with SYSTEM-level privileges from an adjacent network.
- Study finds LLM agents overshare private data in most tool calls — Research shows GPT-4o, Claude 3.5 Sonnet, and Llama-3.3-70B include unnecessary privacy-sensitive data in 81–88% of tool calls, even with explicit privacy instructions.
- Adobe Campaign Classic flaws enable unauthenticated arbitrary code execution — Adobe disclosed unauthenticated arbitrary code execution vulnerabilities in Campaign Classic.
Vendor Bulletins & Advisories
Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities in 9, 10.1, 8.5
Read digest- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Affecting 9, 10.1 and 8.5 — Apache Tomcat patched 11 vulnerabilities across supported and end-of-life releases, including security-constraint bypasses, access-control bypasses, and an HTTP/2 denial-of-service flaw.
- Reported Log4j FOIS Bypass May Enable RCE in Narrow Setups — A reported Log4j deserialization bypass exploits MarshalledObject to evade FilteredObjectInputStream allowlists, potentially enabling RCE in narrowly configured applications.
- CVE-2026-80202: Kimai Authorization Bypass via TimesheetVoter (CVSS 9.3) — Kimai before 2.56.0 suffers an authorization bypass via TimesheetVoter, the highest-scoring CVE in a batch of multiple Kimai vulnerabilities disclosed this run.
Vulnerabilities & CVEs
KubePi unauthenticated SSO/OIDC flaw enables admin account takeover
Read digest- CVE-2026-65956 — CVSS 10.0 — KubePi: Unauthenticated SSO/OIDC configuration allows admin account takeover — A CVSS 10.0 vulnerability in KubePi allows unauthenticated attackers to exploit SSO/OIDC configuration and take over admin accounts.
- Two vulnerabilities affect Reactor Netty HTTP servers — Spring issued an advisory for two vulnerabilities affecting Reactor Netty HTTP servers used across many Spring-based applications.
- OpenStack Keystone flaw exposes cloud-wide role assignments to readers — An OpenStack Keystone vulnerability exposes cloud-wide role assignment data to unauthorized readers.
- CVE-2026-16639 — CVSS 9.8 — Internationalization Single Sign-On - Critical - Access bypass — A critical access bypass flaw in the Internationalization Single Sign-On module carries a CVSS 9.8 rating.
Vendor Bulletins & Advisories
Critical Avada WordPress Theme Flaw Enables Unauthenticated RCE
Read digest- Critical Avada WordPress Theme Flaw Enables Unauthenticated RCE — A six-step chain of authorization and input-validation weaknesses in the Avada theme with over one million sales enables unauthenticated arbitrary file writes and PHP execution.
- Trump order restricts risky foreign equipment in U.S. bulk-power system — A national emergency declaration empowers the Energy Secretary to prohibit acquisitions of covered foreign equipment in the U.S. bulk-power system.
- Dark Caracal Deploys GoCaracal Malware Framework in Latin America — The Dark Caracal APT group is using the new GoCaracal framework for cyberespionage against Latin American organizations, stealing files and credentials.
- CVE-2026-65641 — CVSS 9.3 — Unauthenticated SMB authentication coercion — A high-severity vulnerability allows an unauthenticated network attacker to coerce SMB authentication, the highest-CVSS entry in this run.
Active Exploits & Incidents
FBI Disrupts Chinese Espionage Platform Targeting U.S. Agencies
Read digest- FBI Disrupts Chinese Espionage Platform Targeting U.S. Agencies — The FBI seized infrastructure linked to China-based Nanjing Xinjiuwei that targeted NASA, the Federal Reserve, and dozens of organizations across multiple sectors for over eight years.
- CVE-2026-70419 — Dell Cloud Disaster Recovery RCE via OS Command Injection — A CVSS 9.1 OS command injection flaw in Dell Cloud Disaster Recovery could allow remote code execution.
Active Exploits & Incidents
Citrix NetScaler CVE-2026-8452 exploited in the wild
Read digest- Citrix NetScaler CVE-2026-8452 exploited in the wild — A pre-authentication heap overflow in Citrix NetScaler ADC and Gateway enables remote code execution via crafted SAML messages, with public PoC and active exploitation.
- UAT-10147 Exploited AjaxPro CVE-2021-23758 Against Web Servers — Threat actor UAT-10147 used AI-assisted intrusion campaigns to exploit AjaxPro deserialization flaws across roughly 170,000 URLs, deploying web shells and RATs.
- Microsoft details attacks targeting LiteLLM, RAGFlow and Kestra AI workloads — Attackers compromised exposed AI infrastructure to steal model-provider keys, database credentials, and monetize compute through cryptomining.
- Nimbus Manticore Adds TWOSTROKE-Like Backdoor and Reverse SSH Tool — Group-IB identified new Nimbus Manticore malware targeting defense, aerospace, and IT service providers with a C++ backdoor and reverse SSH tool.
Active Exploits & Incidents
Hackers Probe Microsoft SharePoint RCE Chain After PoCs Published
Read digest- Hackers Probe Microsoft SharePoint RCE Chain After PoCs Published — Public PoCs for a SharePoint JWT bypass and BCS remote code execution chain are being actively probed against 8,700-plus exposed deployments.
- CISA: Hackers Targeted More Than 100 U.S. Water Systems in July — Attackers scanned exposed PLCs with default credentials across more than a dozen states, disrupting pumps and triggering boil-water advisories.
- Bishop Fox Demonstrates Unauthenticated RCE in Veeam Service Provider Console — Chaining two CVEs lets an unauthenticated attacker impersonate a backup agent and achieve remote code execution on multi-tenant VSPC servers.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check