Security Intel Feed
Cyber Hose
Page 21 of 44
Active Exploits & Incidents
BINDCLOAK Windows Backdoor Steals Tokens to Escalate Privileges
Read digest- BINDCLOAK Windows Backdoor Steals Tokens to Escalate Privileges in Espionage Campaign — BINDCLOAK steals Windows tokens to run malware with elevated privileges targeting Middle East government energy sectors.
- Midnight Blizzard hijacks hotel Wi-Fi to steal travelers' cloud credentials — Midnight Blizzard compromises hotel Wi-Fi gateways to deliver fake login pages and steal cloud credentials worldwide.
- Malicious GitHub Issue Can Exploit Google AI Agent to Breach CI/CD Pipeline — A crafted GitHub issue can manipulate Google AI agents to execute remote code and exfiltrate credentials in CI/CD pipelines.
Threat Research & Deep Dives
North Korean Hackers Hide Malware Servers in Empty Ethereum
Read digest- North Korean Hackers Hide Malware Servers in Empty Ethereum Transactions — North Korean hackers use empty Ethereum transactions to hide malware command servers and target developers through malicious npm packages.
Vulnerabilities & CVEs
Heap-Buffer-Overflow in Gimp APNG Loader CVE-2026-42169
Read digest- Heap-Buffer-Overflow in Gimp APNG Loader CVE-2026-42169 — CVE-2026-42169 causes a heap-buffer-overflow in Gimp's APNG loader when fctl width exceeds ihdr width.
- Path Traversal Vulnerability in CLI Command CVE-2026-14818 — CVE-2026-14818 allows path traversal in a CLI command used for executing configuration.
- Improper Authorization in diaowen DWSurvey CVE-2026-18723 — CVE-2026-18723 exposes an improper authorization vulnerability in Survey Status up-survey-status.do.
- Authorization Issue in diaowen DWSurvey dev-survey.do CVE-2026-18722 — CVE-2026-18722 involves an authorization issue in DwDeisgnSurveyController.devSurvey.
- SSO API Login Redirect Vulnerability in kalcaddle kodbox CVE-2026-18721 — CVE-2026-18721 causes a redirect vulnerability in kalcaddle kodbox's SSO API Login apiLogin.
Threat Research & Deep Dives
Security Assessment Reveals Multiple Vulnerabilities
Read digest- Security Assessment Reveals Multiple Vulnerabilities in Internet-Facing MCP Servers — A dynamic assessment audited 414 MCP servers, finding 68 vulnerabilities including SQL injection and SSRF, with most lacking OAuth.
- Researchers demonstrate stealthy backdoor evading diffusion model semantic watermarks — A stealthy backdoor method evades semantic watermarks in latent diffusion models, achieving high evasion success while remaining stealthy.
- Domain Decoupling Attack exploits DNS validation gap in CDN and shared hosting — A DNS-based authorization gap allows attackers to access other tenants in shared hosting by exploiting shared IP permissions.
Threat Research & Deep Dives
Critical Command Injection Flaw Found in GL.iNet GL-MT3000 Devices
Read digest- Critical Command Injection Flaw Found in GL.iNet GL-MT3000 up to Firmware 4.4.5 — CVE-2026-18686 allows unauthenticated remote command injection on GL.iNet GL-MT3000 devices running firmware 4.4.0 to 4.4.5.
Vulnerabilities & CVEs
No new critical CVEs reported in this cycle
Read digest- No new critical CVEs reported in this cycle — This cycle reports 20 other CVEs without scores and no major new vulnerabilities disclosed.
Active Exploits & Incidents
Attackers Exploit N-able Patch Bypass Flaw CVE-2026-18577 on RMM
Read digest- Attackers Exploit N-able Patch Bypass Flaw CVE-2026-18577 on RMM Servers — CVE-2026-18577 allows attackers to bypass authentication and gain administrator access on N-able RMM servers.
- Chinese Actor Uses DeepSeek AI Agent for Proxyjacking Campaign Targeting SMBs — A Chinese threat actor used an AI agent to conduct proxyjacking on over 1,200 SMB hosts, building a relay infrastructure.
- Iranian-Linked Cyb3rAvengers Target US Water Infrastructure in Recent Attacks — Iranian APT Cyb3rAvengers exploited exposed PLCs and weak security to remotely control US municipal water systems.
- AIOHTTP prior to 3.14.2 vulnerable to HTTP request smuggling via WebSocket upgrade — AIOHTTP versions before 3.14.2 have a request smuggling flaw in WebSocket upgrades allowing protocol confusion.
Active Exploits & Incidents
Cyberattack Exposes Data of 31,000 in Liechtenstein’s Register
Read digest- Cyberattack Exposes Data of 31,000 in Liechtenstein’s Register of Company Beneficiaries — A breach exposed data of 31,000 individuals in Liechtenstein’s register supporting anti-money laundering efforts.
- Russian DOUBLECUP ClickFix service hides malware in browser cache PNG images — DOUBLECUP malware hides in browser cache PNG images and targets Windows and macOS devices via fake CAPTCHA prompts.
- Fake Roblox Xeno script launcher spreads infostealer and RAT malware — Fake Xeno Executor installers infect Roblox players with info-stealing RAT malware that enables remote control.
Active Exploits & Incidents
INC Ransomware Dominates Exploitation of SonicWall SMA 1000 VPN Flaws
Read digest- INC Ransomware Dominates Exploitation of SonicWall SMA 1000 Vulnerabilities — INC Ransomware exploits SonicWall SMA 1000 VPN flaws using multiple tools to achieve command execution and persistence.
- Malware on Windows Can Hijack Google Passkey Accounts Without User Verification — Malware on Windows can silently hijack Google passkey accounts by exploiting Chrome's cloud authenticator and device trust model.
Threat Research & Deep Dives
OpenWrt luci-app-dockerman RCE via read ACL in docker_rpc.uc backend
Read digest- OpenWrt luci-app-dockerman RCE via read ACL in docker_rpc.uc backend — Authenticated attackers with read ACL can inject shell commands via HTTP POST to the docker_rpc.uc backend, leading to remote code execution.
- Weekly Recap: Rogue AI Breaches, $88M Bitcoin Theft, Water System Attacks, DNS Hijacks — Multiple incidents include AI model breaches, Bitcoin theft from Coldcard wallets, attacks on water systems, and DNS hijacks linked to APT29.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check