Security Intel Feed
Cyber Hose
Page 3 of 44
Active Exploits & Incidents
FBI disrupts proxy network used in Chinese espionage operations
Read digest- FBI disrupts proxy network used in Chinese espionage operations — The FBI disrupted a proxy infrastructure used to profile targets and support data theft by China-linked operators across U.S. defense, government, healthcare, finance, and energy sectors.
- Ubiquiti patches critical vulnerabilities across UniFi products — Ubiquiti patched multiple remotely exploitable command injection flaws in UniFi Access, Protect, Network, and OS Server with CVSS scores ranging from 9.0 to 9.9.
- NovaCookies Phishing Service Steals Microsoft 365 Sessions for $320 Monthly — A subscription phishing service targets Microsoft 365 users at hundreds of organizations using adversary-in-the-middle relays and genuine DocuSign lures.
- Suspected Chinese-Speaking Operator Breached Philippine Nuclear and Naval Groups — A suspected Chinese-speaking operator stole reactor data and credentials from a Philippine nuclear agency and a Navy-contracted marine engineering firm.
Active Exploits & Incidents
Cyberattack disrupts Boston Scientific's global operations
Read digest- Cyberattack disrupts Boston Scientific's global operations — Boston Scientific detected a cyberattack on August 25 that disrupted IT systems, customer orders, product shipments, and forced at least one plant shutdown.
- OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Operation — OpenAI removed Russian-origin ChatGPT accounts that generated English-language content to promote a pro-Russia influence campaign across multiple platforms.
- Treasury helps financial firms transition to quantum-resistant encryption — The U.S. Treasury is guiding financial firms toward quantum-resistant encryption to protect against future harvest-now-decrypt-later attacks.
Threat Research & Deep Dives
TranslatePress Flaw Enables Unauthenticated WordPress Account Takeover
Read digest- TranslatePress Flaw Enables Unauthenticated WordPress Account Takeover — CVE-2026-19632 allows unauthenticated attackers to extract password-reset keys and seize WordPress admin accounts on over 400,000 sites.
- SonicWall NetExtender Flaws Enable Arbitrary File Writes as Root — Two vulnerabilities in the SonicWall NetExtender Linux client enable path traversal file writes as root and symlink manipulation in the auto-upgrade process.
- Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign — Attackers used signed remote monitoring tools and convincing document lures to blend malicious access with normal IT operations across 46 countries.
- Q2 2026 exploit activity spans AI frameworks, exposed systems and DeFi — Rapid7 counted 8,539 high- and critical-severity disclosures with a 76% rise in public proof-of-concept code across enterprise, AI, and DeFi technologies.
Threat Research & Deep Dives
Core Werewolf Uses CoreRAT to Take Over Russian Windows Systems
Read digest- Core Werewolf Uses CoreRAT to Take Over Russian Windows Systems — A previously undocumented C++ RAT is being deployed against Russian public-sector and defense organizations via Telegram phishing campaigns.
Vendor Bulletins & Advisories
Russia Blocks DoH and DoT as Hacktivists Leak Spanish Personnel Data
Read digest- Russia Blocks DoH and DoT as Hacktivists Leak Spanish Personnel Data — Russia blocked DNS-over-HTTPS and DNS-over-TLS protocols while hacktivists leaked data belonging to Spanish police and military personnel.
- Microsoft Teams outage disrupted meetings and screen sharing in Asia-Pacific — A Microsoft Teams outage disrupted meetings and screen sharing for users across the Asia-Pacific region.
Vulnerabilities & CVEs
Trestle SSTI vulnerability CVE-2026-54757 disclosed with CVSS 7.8
Read digest- CVE-2026-54757 — Trestle Server-Side Template Injection via Recursive Template Re-evaluation — A CVSS 7.8 server-side template injection in Trestle enables code execution through recursive template re-evaluation.
- CVE-2026-41707 — Spring Security DPoP Proof Replay vulnerability — Spring Security's DPoPProofJwtDecoderFactory is vulnerable to DPoP proof replay, rated CVSS 7.4.
- CVE-2026-44476 — Doorkeeper OpenID Connect Dynamic Client Registration flaw — Doorkeeper OpenID Connect's dynamic client registration creates public clients insecurely, rated CVSS 6.3.
Threat Research & Deep Dives
Hidden Email Prompts Can Manipulate Microsoft Copilot Summaries
Read digest- Hidden Email Prompts Can Manipulate Microsoft Copilot Summaries — Attackers can embed invisible HTML prompts in emails to produce false Copilot summaries, deceptive alerts, or malicious instructions via cross-prompt injection.
- CVE-2026-65083 — CVSS 9.9 — NVIDIA OpenShell for Linux sandbox provisioning vulnerability — A critical vulnerability in NVIDIA OpenShell for Linux's sandbox provisioning could allow attackers to escape isolation controls.
- CyberLeek leaks unreleased GTA VI footage in extortion-style campaign — Threat actor CyberLeek published unreleased GTA VI clips and assets in a drip-feed extortion campaign tied to crypto donations and a memecoin.
- CVE-2026-80104 — CVSS 9.3 — DB-GPT 0.8.0 Path Traversal Arbitrary File Write via Skill Upload — A path traversal flaw in DB-GPT's skill upload feature allows arbitrary file writes through crafted filenames.
Active Exploits & Incidents
Attackers Exploit Zimbra Command-Injection Flaw for Unauthenticated
Read digest- Attackers Exploit Zimbra Command-Injection Flaw for Unauthenticated RCE — CVE-2026-73570 enables unauthenticated OS command injection via crafted SMTP requests in Zimbra Collaboration Suite before version 10.1.20.
- DDoS attack disrupts Norway's government digital services — A sustained DDoS attack flooded Norway's shared government infrastructure, causing outages across ID-porten, Altinn, and other public-sector portals.
- Kaltura HTML5 Player Flaws Enable Arbitrary File Reads and Remote Code Execution — Two Kaltura HTML5 player vulnerabilities allow unauthenticated local file disclosure and remote code execution via unsafe deserialization.
- Chinese Hackers Scale Cyberattacks With Low-Cost AI Tools — Chinese-linked operators are combining multiple AI subagents to automate reconnaissance, exploitation, and persistence against government and internet-facing targets.
Active Exploits & Incidents
Nutex Health says attackers stole data in cyberattack
Read digest- Nutex Health says attackers stole data in cyberattack — Nutex Health is investigating a breach where an unauthorized party accessed and exfiltrated data from its servers.
- ASOS Reports Customer Account Access Using Compromised Credentials — ASOS customers were affected by unauthorized account access using externally sourced credentials.
- NVIDIA NemoClaw flaw lets malicious webpages poison local AI models — A malicious webpage can control NemoClaw’s local Ollama server, modifying AI models via an exposed API.
- ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Attack Commands — ToxNetV2 botnet leverages NVIDIA AI to craft shell and SSH attack commands targeting AArch64 Linux systems.
- Marimo Flaw Let Crafted Notebooks Execute MCP Commands in Edit Mode — Marimo notebooks before version 0.23.15 allowed attacker-supplied MCP commands execution via crafted notebooks.
Active Exploits & Incidents
Attackers breach 274 Zimbra servers via actively exploited RCE flaw
Read digest- Attackers breach 274 Zimbra servers through actively exploited RCE flaw — Unauthenticated attackers exploit an SNMP notification RCE in Zimbra Collaboration Suite, compromising 274 servers with 8,200 more unpatched.
- Mirage2FA Targets 9,426 Microsoft 365 Accounts and Steals Sessions — An AiTM phishing campaign steals M365 credentials, MFA codes, and session cookies across 94 countries with over 4,500 potentially compromised addresses.
- CVE-2026-8508 Enables Captive-Portal Bypass on 39 Zyxel Models — A pre-authentication flaw lets unauthenticated attackers bypass social-login controls on 39 Zyxel access points and routers via the guest Wi-Fi captive portal.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check