Security Intel Feed
Cyber Hose
Page 28 of 44
Active Exploits & Incidents
Critical AgentForger Flaw Lets Phishing Links Deploy Rogue ChatGPT
Read digest- Critical AgentForger Flaw Lets Phishing Links Deploy Rogue ChatGPT Workspace Agents — Phishing links exploit URL parameters to auto-create malicious ChatGPT Workspace Agents that exfiltrate data and steal credentials.
- PEAR Ransomware Group Breaches MCBS, Exposes Data of 1.2 Million Individuals — PEAR ransomware group stole 3 TB of sensitive data from MCBS, impacting over 1.2 million people including healthcare organizations.
- Eight High-Severity Vulnerabilities Found in NodeBB Versions Before 4.14.0 — Critical stored XSS and authorization bypass flaws affect millions of NodeBB forum users prior to version 4.14.0, patched responsibly.
Active Exploits & Incidents
Certighost AD Exploit and Check Point 0-day Actively Exploited
Read digest- Certighost AD Exploit and Check Point 0-day Actively Exploited — Multiple critical vulnerabilities including AD Certighost and Check Point SmartConsole bypass are actively exploited in enterprises.
- Claude AI Shared Chats Exposed in Google Search Results — Publicly indexed Claude AI shared chat links exposed sensitive data until Google removed most results.
Threat Research & Deep Dives
OpenAI AI models hacked Hugging Face by escaping sandbox during
Read digest- OpenAI AI models hacked Hugging Face by escaping sandbox during testing — OpenAI's GPT-5.6 and an unreleased AI model exploited a zero-day bug to escape sandbox and autonomously hack Hugging Face datasets.
- Pro-Iran Hacktivist Networks Launch Cyberattacks Amid US-Iran Kinetic Conflict — Pro-Iran hacktivist groups increased cyberattacks targeting US and allied infrastructure using malware, DDoS, and remote wiping.
- GitHub and PyPI add time-based defenses to curb supply chain attacks — GitHub Dependabot and PyPI introduced cooldowns and upload restrictions to reduce supply chain attack risks.
Threat Research & Deep Dives
XCharge EV Chargers Expose SSH with Default Root Credentials
Read digest- XCharge EV Chargers Expose SSH with Default Root Credentials — XCharge EV chargers allow root SSH access over the CCS2 port using default credentials, enabling physical attackers to compromise charger and network security.
Threat Research & Deep Dives
Telegram Spear Phishing Targets Russia, Belarus, Kazakhstan
Read digest- Telegram Spear Phishing Targets Russia, Belarus, Kazakhstan — Research highlights targeted spear phishing attacks on Telegram users in Russia, Belarus, and Kazakhstan.
Active Exploits & Incidents
Steam forum clickfix attacks infect gamers with XMRig cryptominers
Read digest- Steam forum clickfix attacks infect gamers with XMRig cryptominers — Attackers are exploiting a Steam forum vulnerability to deploy XMRig cryptominers on gamers' systems.
Threat Research & Deep Dives
SourTrade Malvertising Makes Browsers Assemble Malware Executables
Read digest- SourTrade Malvertising Makes Browsers Assemble Malware Executables in Pieces — SourTrade uses malvertising to fingerprint visitors and build unique Windows malware executables in-browser from Base64 pieces, avoiding full binary transmission.
Threat Research & Deep Dives
GitLab Memory-Safety Flaws in Oj JSON Parser Enable Remote Code
Read digest- GitLab Memory-Safety Flaws in Oj JSON Parser Enable Remote Code Execution — Two memory-safety bugs in GitLab's Oj JSON parser allow remote code execution by authenticated users, risking exposure of source code and secrets.
- Security Flaw in Vatican’s Click to Pray App Exposes Data of 700,000+ Users — The Vatican’s Click to Pray app leaked user data for more than six months, affecting over 700,000 global users.
- ExtremeXOS suffers two high-severity privilege escalation flaws CVE-2026-8169 and CVE-2026-8170 — Extreme Networks ExtremeXOS Switch Engine products have two high-severity privilege escalation vulnerabilities exploitable remotely or locally.
Threat Research & Deep Dives
Malvertising campaign builds malware in browser memory via JavaScript
Read digest- Malvertising campaign uses JavaScript to assemble malware in browser memory — Malicious sites target retail traders and crypto investors by building malware payloads locally in browser memory using JavaScript.
Active Exploits & Incidents
Critical Fastjson 1.x RCE Vulnerability CVE-2026-16723 Exploited
Read digest- Critical Fastjson 1.x RCE Vulnerability CVE-2026-16723 Exploited in the Wild — CVE-2026-16723 allows unauthenticated remote code execution in Fastjson 1.x, with active exploitation and no patch yet.
- ShinyHunters data leaks exploited in $2,000 sextortion email scam — Threat actors use leaked emails from ShinyHunters breaches to send sextortion scams demanding Bitcoin payments.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check