Security Intel Feed
Cyber Hose
Page 23 of 44
Threat Research & Deep Dives
Claude AI Breach, Cisco Firewall 0-Day, VMware Auth Bypass, and AI
Read digest- Claude AI Breach, Cisco Firewall 0-Day, VMware Auth Bypass, and AI Cyberattack Highlights — Multiple critical vulnerabilities and breaches impacted AI systems, Cisco firewalls, VMware, and enterprise networks.
- ArcadeDB before 26.7.3 vulnerable to authentication bypass via MCP transport — ArcadeDB versions before 26.7.3 allow authentication bypass in MCP HTTP transport, enabling arbitrary writes and schema changes.
- ArcadeDB before 26.7.3 vulnerable to privilege escalation via JavaScript triggers — ArcadeDB versions before 26.7.3 allow privilege escalation through JavaScript triggers, enabling creation of server-wide admin users.
- TIGTA finds 100+ critical vulnerabilities in IRS contractor handling tax data — TIGTA discovered over 100 critical vulnerabilities in an IRS contractor's physical and digital security supporting tax data digitization.
Active Exploits & Incidents
Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft
Read digest- Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft in 41 Minutes — A firmware flaw in Coldcard Bitcoin hardware wallets allowed attackers to reproduce seed outputs and steal over $70 million in Bitcoin.
- Hackers Target 30+ Minnesota Water Systems in 48-Hour Cyberattack — More than 30 Minnesota water systems were hit by a disruption-focused cyberattack causing at least one plant shutdown.
Active Exploits & Incidents
Brinks Home Confirms Data Breach After ShinyHunters Steal 4.9M Records
Read digest- Brinks Home Confirms Data Breach After ShinyHunters Steal 4.9M Records — Nearly five million records were stolen from Brinks Home through unauthorized access to Salesforce and support systems.
Vendor Bulletins & Advisories
Rails patches critical Active Storage flaw with remote code execution
Read digest- Rails patches critical Active Storage flaw with remote code execution risk — A critical vulnerability in Rails Active Storage allows unauthenticated attackers to read arbitrary files and execute code remotely.
- Scope of Cyberattacks on U.S. Water Supply Expands, Linked to Iran — Cyberattacks targeting U.S. water supply infrastructure have expanded, with evidence suggesting Iranian involvement.
- Multiple high-severity vulnerabilities found in FreeRDP before version 3.29.0 — FreeRDP versions before 3.29.0 contain multiple critical flaws including heap overflows and use-after-free bugs that can cause crashes and memory corruption.
Active Exploits & Incidents
Adform Supply Chain Compromise Distributes Crypto-Stealing Clipboard
Read digest- Adform Supply Chain Compromise Distributes Crypto-Stealing Clipboard Hijacker — Attackers hijacked a JavaScript tracking script on Adform's domain to swap copied crypto wallet addresses with attacker-controlled ones.
- Amgen reports cloud data breach exposing patient health and proprietary info — Amgen suffered a cloud data breach exposing patient protected health information and proprietary corporate data.
- Ruby on Rails patches critical RCE vulnerability in Active Storage image processing — Ruby on Rails patched a critical unauthenticated remote code execution vulnerability affecting Active Storage with libvips.
Vulnerabilities & CVEs
Adobe Campaign Classic RCE Flaw CVE-2026-48449 Scores CVSS 10.0
Read digest- Adobe Campaign Classic RCE Flaw CVE-2026-48449 Scores CVSS 10.0 — A critical RCE vulnerability in Adobe Campaign Classic allows arbitrary code execution without user interaction.
- Hijacked Hotel Wi-Fi Delivers CornFlake RAT via Fake Browser Updates — Attackers hijack hotel Wi-Fi DNS to deliver CornFlake RAT via fake browser update pages, stealing credentials and spying on users.
Threat Research & Deep Dives
Adform supply chain hack steals cryptocurrency from Finnish betting
Read digest- Adform supply chain hack steals cryptocurrency from Finnish betting site — Malicious code injected via Adform's supply chain targeted cryptocurrency wallets of Veikkaus users.
Threat Research & Deep Dives
Command Injection Flaw in TP-Link Archer AXE75 OpenVPN Module
Read digest- Command Injection Flaw in TP-Link Archer AXE75 OpenVPN Module — Authenticated adjacent attackers can execute arbitrary OS commands by importing malicious VPN client configs.
Vulnerabilities & CVEs
ComfyUI 0.23.0 vulnerable to unauthenticated remote code execution
Read digest- ComfyUI 0.23.0 vulnerable to unauthenticated remote code execution — ComfyUI 0.23.0 allows unauthenticated attackers to execute arbitrary Python code via crafted pickle files.
- Critical RCE Vulnerability in sentence-transformers via Local Model Load Bypass — sentence-transformers library allows arbitrary code execution when loading local models without proper security.
- Savon Ruby SOAP Client Vulnerable to Code Execution via WSDL Operation Names (CVE-2026-53510) — Savon Ruby SOAP client versions before 2.17.2 allow remote code execution via crafted WSDL operation names.
Active Exploits & Incidents
Amgen confirms July 2026 cloud data breach exposing sensitive patient
Read digest- Amgen confirms July 2026 cloud data breach exposing sensitive patient and proprietary data — Amgen suffered a cloud data breach exposing sensitive proprietary and patient health data from AWS-hosted environments.
- Chinese-Speaking Hackers Target Central Asian Governments with OctLurk and SilkLurk Malware — Chinese-speaking hackers used OctLurk and SilkLurk backdoors to target government and critical sectors in Central Asia and Syria.
- Cyberattacks Hit Water Facilities in Seven U.S. States, Disrupting Operations — Multiple water treatment plants across seven U.S. states experienced cyberattacks disrupting their operations.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check