Security Intel Feed
Cyber Hose
Page 27 of 44
Active Exploits & Incidents
Critical Zero-Day OS Command Injection in Arista VeloCloud
Read digest- Critical Zero-Day OS Command Injection in Arista VeloCloud Orchestrator Exploited — Arista VeloCloud Orchestrator on-premises versions before 5.2.3.145, 6.1.3.46, 6.4.2.4, and 7.0.0.1 are actively exploited via a remote OS command injection zero-day.
- Unpatched Fastjson RCE Vulnerability Exploited in Attacks Targeting Multiple Sectors — Attackers exploit an unauthenticated remote code execution flaw in Fastjson 1.x across business, financial, healthcare, and retail sectors.
- Five Critical Vulnerabilities Found in Progress LoadMaster Appliances Allow Root Access — Five vulnerabilities in Progress LoadMaster appliances allow authenticated users to escalate to root access, though no active exploitation is reported.
Active Exploits & Incidents
Attackers Exploit Critical Command Injection Flaw in Arista VeloCloud
Read digest- Attackers Exploit Critical Command Injection Flaw in Arista VeloCloud Orchestrator — CVE-2026-16812 allows remote OS command injection in Arista VeloCloud Orchestrator, leading to full compromise and active exploitation.
- CISA Warns of Active Exploitation of Fortinet FortiOS Vulnerability CVE-2025-68686 — Fortinet FortiOS vulnerability CVE-2025-68686 is actively exploited to expose sensitive information via symlink persistence bypass.
- Origin Energy Data Breach Exposes Personal Data of 900,000 Australians — Data breach at Origin Energy exposed personal data of 900,000 customers, with ransom threats reported but unconfirmed.
- Operation STANDOFF Uses GitHub Redirects to Mask Russian Cybercrime Campaign — Russian cybercrime campaign Operation STANDOFF uses GitHub redirects to deliver multi-malware payloads and evade detection.
- DCSync Attack Enables Silent Theft of Active Directory Password Hashes — DCSync attacks allow stealthy theft of Active Directory password hashes by impersonating domain controllers using replication rights.
Threat Research & Deep Dives
Europol Launches Project COMPASS to Combat Teen Hacker Network
Read digest- Europol Launches Project COMPASS to Combat Teen Hacker Network Exploiting Minors — Europol's Project COMPASS disrupts a decentralized teen hacker network involved in cybercrime, extortion, and violent offenses.
- New SPORE attack extracts private memory from isolated LLM agents via tool interfaces — Researchers reveal a novel attack extracting private data from long-term memory in LLM agents, risking user privacy in multi-user setups.
Threat Research & Deep Dives
Autonomous AI Agent Hermes Used in Espionage Attack on Thai Ministry
Read digest- Autonomous AI Agent Hermes Used in Espionage Attack on Thai Ministry of Finance — Attackers leveraged the open-source Hermes AI agent in unrestricted mode to conduct espionage on Thailand's Ministry of Finance.
Active Exploits & Incidents
New Certighost PoC exploit enables attackers to hijack Windows domains
Read digest- New Certighost PoC exploit enables attackers to hijack Windows domains — The exploit targets Windows Active Directory Certificate Services to allow low-privileged users to impersonate Domain Controllers and perform privileged AD operations.
- Confused Deputy Flaws Persist in Google Cloud and Microsoft Azure — Confused deputy vulnerabilities in major cloud platforms enable attackers to bypass access controls and escalate privileges to admin levels.
- New AI attack reconstructs typed text from keyboard sounds with up to 99% accuracy — Researchers developed an AI method that reconstructs typed text from acoustic keystroke sounds with high accuracy using unsupervised audio analysis and Transformer models.
Threat Research & Deep Dives
Critical OS Command Injection in Arista VeloCloud Orchestrator On-Prem
Read digest- Critical OS Command Injection in Arista VeloCloud Orchestrator On-Prem (CVE-2026-16812) — CVE-2026-16812 allows remote OS command execution and compromises confidentiality, integrity, and availability of the orchestrator.
Active Exploits & Incidents
Dysphoria IoT Botnet Uses Blockchain C2 and Victim Relays After
Read digest- Dysphoria IoT Botnet Uses Blockchain C2 and Victim Relays After JackSkid Takedown — The Dysphoria IoT botnet employs blockchain-based name services and victim relay meshes to evade takedown and infect over 200,000 devices.
- phpMyFAQ before 4.1.6 vulnerable to remote code execution via configuration API — Authenticated admins can exploit a remote code execution flaw in phpMyFAQ versions before 4.1.6 by uploading malicious ZIP attachments.
- SiYuan before v3.7.2 vulnerable to stored XSS leading to RCE via title-img attribute — Stored XSS in SiYuan before v3.7.2 allows editors to execute arbitrary code with full Node.js access in Electron renderer.
- SiYuan Desktop before v3.7.2 vulnerable to reflected XSS leading to RCE via siyuan protocol — Reflected XSS in SiYuan Desktop before v3.7.2 enables remote code execution without privileges or user interaction.
Active Exploits & Incidents
Hacked Public Wi-Fi Gateways Steal Microsoft 365 Corporate Credentials
Read digest- Hacked Public Wi-Fi Gateways Used to Steal Microsoft 365 Corporate Credentials — Attackers compromise SOHO Wi-Fi gateways at public venues to intercept Microsoft 365 credentials via DNS redirection.
- Windows WalletService Flaw Lets Standard Users Escalate to SYSTEM Privileges — A local privilege escalation vulnerability in Windows WalletService allows code execution as SYSTEM without admin rights.
- Anubis Ransomware Hits Coca-Cola's Fairlife, Causing Data Breach and Production Halt — Anubis ransomware encrypted systems and exfiltrated 1 TB of data, halting production at four Fairlife facilities.
- Critical RCE Vulnerability in Fastjson Java Library Actively Exploited Since July 2026 — CVE-2026-16723 enables unauthenticated remote code execution in Fastjson 1.x, actively exploited across multiple sectors.
Active Exploits & Incidents
Ransomware Gangs Exploit VPN and Firewall Flaws in Palo Alto
Read digest- Ransomware Gangs Exploit VPN and Firewall Flaws in Palo Alto, Fortinet, Citrix, Check Point — Ransomware operators exploit authentication bypass and credential harvesting vulnerabilities in major VPN and firewall appliances.
- DentaQuest Data Breach in May 2026 Potentially Affects Over 23 Million People — Hackers stole sensitive personal and dental health information from DentaQuest, impacting millions.
- East Asian-linked TELESHIM malware abuses Telegram for C2 in Middle East govt attacks — New malware campaign uses Telegram API for command-and-control to evade detection in Middle East government attacks.
- SparkKitty malware steals crypto wallet seed phrases from iOS and Android photos — Malware uses OCR to steal cryptocurrency wallet seed phrases from mobile device photos.
- BlueNoroff Hijacks Trusted Telegram Accounts to Spread ClickFix Malware via Fake Zoom Calls — Threat actor hijacks Telegram accounts to deliver malware via fake video call invites targeting crypto firms.
Threat Research & Deep Dives
Researchers Boot Jailbroken iOS 27 on iPhone 11 Pro Using usbliter8
Read digest- Researchers Boot Jailbroken iOS 27 on iPhone 11 Pro Using usbliter8 Exploit — The exploit requires physical access and specialized hardware to bypass iOS security, disabling critical services.
- New JSON RCE Bug Threatens Java Ecosystem — A critical remote code execution vulnerability in JSON parsing threatens Java applications, though details remain scarce.
- PyPI Blocks File Uploads on Releases Older Than 14 Days to Prevent Package Poisoning — PyPI now blocks file uploads on old releases to prevent supply-chain attacks exploiting compromised maintainer tokens.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check