Security Intel Feed
Cyber Hose
Page 22 of 44
Active Exploits & Incidents
River Bank Hit by June Ransomware Attack, Hackers Deleted Stolen Data
Read digest- River Bank Hit by June Ransomware Attack, Hackers Deleted Stolen Data — River Bank was hit by ransomware in June, with hackers deleting stolen data after exfiltration; investigation is ongoing.
- Octagon Android RAT hides as Bahrain BH Alert app and survives reboots — A new Android RAT impersonates Bahrain's BH Alert app, persists through reboots, and steals sensitive data.
- Samsung bans smart TV apps that share users’ internet connections with strangers — Samsung removes and bans smart TV apps that share users' internet connections via residential proxy networks.
- Kaspersky reports ransomware and insider threats at Brazilian educational institutions — Brazilian educational institutions faced ransomware and insider threats exploiting valid accounts and exposed apps.
Active Exploits & Incidents
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE
Read digest- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS — A Chinese threat actor uses a leaked exploit kit to deliver malware stealing credentials from Apple iOS devices.
- PNLD Breach Exposes UK Police and Government Contact Details on Dark Web — A breach of the Police National Legal Database exposed contact details of UK police and government personnel on the dark web.
- Hackers breach Liechtenstein beneficial owners register, data of 31,000 entities stolen — Hackers illegally accessed and copied data from Liechtenstein's beneficial owners register affecting 31,000 entities.
Active Exploits & Incidents
SonicWall SMA 1000 VPNs Face Zero-Click Root Compromise
Read digest- SonicWall SMA 1000 VPNs Face Zero-Click Root Compromise — Two vulnerabilities allow attackers to bypass restrictions and gain root access on SonicWall SMA 1000 series VPN appliances.
- Russian APT Midnight Blizzard hacks public Wi-Fi gateways to steal Microsoft credentials — Russian state-sponsored hackers target public Wi-Fi to steal Microsoft 365 credentials using adversary-in-the-middle attacks.
- Thermo Fisher Patches High-Severity Flaw Allowing Nearly Undetectable DNA File Tampering — A flaw in Applied Biosystems software allowed tampering with DNA data files before analysis, now patched with digital signatures.
Active Exploits & Incidents
Critical Auth Bypass in N-able N-central Enables Remote Admin Takeover
Read digest- Critical Auth Bypass in N-able N-central Enables Remote Admin Takeover, Patch Issued — Attackers exploited an authentication bypass in N-able N-central to gain full admin access, affecting both cloud and on-premises deployments.
- Three High-Severity Flaws in Hugging Face Diffusers Enable Arbitrary Code Execution — Multiple vulnerabilities in Hugging Face Diffusers allow arbitrary code execution via malicious model repositories.
- MacSync macOS Stealer Uses Fake Claude Guide to Harvest Passwords and Crypto Wallets — MacSync malware targets macOS users with a fake Claude AI guide to steal credentials, wallets, and install persistent access.
Threat Research & Deep Dives
Coldcard Bitcoin Wallet Hacked for $70M; Russia Behind Hotel WiFi
Read digest- Coldcard Bitcoin Wallet Hacked for $70M; Russia Behind Recent Hotel WiFi Attacks — Coldcard Bitcoin hardware wallets were compromised, causing a $70 million theft, with Russia identified as the attacker in recent hotel WiFi breaches.
Vulnerabilities & CVEs
No new critical vulnerabilities reported in this cycle
Read digest- No new critical vulnerabilities reported in this cycle — This digest covers 20 CVEs without scores and no new critical exploits or advisories this cycle.
Vulnerabilities & CVEs
Incomplete Patch Leads to Administrative Account Takeover
Read digest- Incomplete Patch Leads to Administrative Account Takeover — Two incomplete patches have resulted in administrative account takeover vulnerabilities that must be addressed immediately.
Active Exploits & Incidents
UK Government Investments agency suffers data breach exposing
Read digest- UK Government Investments agency suffers data breach exposing officials' details — Sensitive data and contact details of 51 officials were publicly accessible for about 40 hours due to policy failure.
- Family phones compromised to send abusive messages via WhatsApp and SMS — Multiple family members' phones on iOS and Android were compromised to impersonate and send abusive messages.
- Israel Thwarts Iranian Cyberattacks Targeting Water Infrastructure — Israel prevented cyberattacks on water infrastructure attributed to Iranian state-backed actors.
- Facebook Malvertising Campaign Uses C2 Infrastructure for Attacks — A malvertising campaign on Facebook uses command and control servers to deliver payloads to users.
Vulnerabilities & CVEs
Critical SQL Injection in PyAthena 3.35.4 with CVSS 9.8
Read digest- Critical SQL Injection in PyAthena 3.35.4 with CVSS 9.8 — CVE-2026-65321 allows SQL injection via DefaultParameterFormatter in PyAthena 3.35.4, affecting DELETE and CTAS queries.
- Path Traversal in huggingface/transformers with CVSS 7.1 — A path traversal vulnerability affects huggingface/transformers, potentially exposing sensitive files.
- Out-of-bounds read in Zephyr OCPP 1.6 RPC message parser — Zephyr OCPP 1.6 suffers an out-of-bounds read in its RPC message parser, risking memory corruption.
Threat Research & Deep Dives
Google Chrome to block New Tab hijacker extensions on unmanaged
Read digest- Google Chrome to block New Tab hijacker extensions by default on unmanaged devices — Google Chrome plans to block policy-installed hijacker extensions on unmanaged consumer devices to prevent malware abuse and repeated installation attempts.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check