Security Intel Feed
Cyber Hose
Page 30 of 44
Threat Research & Deep Dives
Multiple high-severity memory corruption flaws in Google Chrome
Read digest- Multiple high-severity memory corruption flaws in Google Chrome before 150.0.7871.186 — Google Chrome before 150.0.7871.186 contains use-after-free and out-of-bounds write flaws that allow remote code execution via crafted HTML pages.
- CVE-2026-42933 — Unintended Proxy or Intermediary in Panduit IntraVUE — A critical CVSS 10.0 vulnerability in Panduit IntraVUE allows unintended proxy or intermediary behavior.
Active Exploits & Incidents
Russian Hackers Exploit Zimbra Zero-Day in US and Ukraine Attacks
Read digest- Russian Hackers Exploit Zimbra Zero-Day in US and Ukraine Attacks — Russian state-sponsored group 'Laundry Bear' exploited a zero-day in Zimbra Collaboration Suite using half-click phishing.
- New Dolphin X malware uses AI to rank and prioritize high-value victims — Dolphin X malware profiles infected users with AI to prioritize targets for credential theft across 300+ applications.
Active Exploits & Incidents
Russian Laundry Bear exploits Zimbra zero-click flaw to steal emails
Read digest- Russian Laundry Bear exploits Zimbra zero-click flaw to steal emails — Laundry Bear exploited a zero-click cross-site scripting flaw in Zimbra to steal emails, passwords, 2FA tokens, and bypass MFA.
- Hackers abuse Notepad++ plugins to stealthily install LunchPoke malware — Attackers use malicious Notepad++ plugins to install LunchPoke malware on Ukrainian organizations via ZIP archives.
Threat Research & Deep Dives
Russian Cyberespionage Targets Zimbra Webmail via JavaScript Injection
Read digest- Russian Cyberespionage Targets Zimbra Webmail via JavaScript Injection — A Russian threat actor exploits CVE-2025-66376 in Zimbra webmail servers to steal credentials and sensitive data via malicious JavaScript.
- Microsoft 365 Device Code Phishing Bypasses MFA to Steal Access Tokens — Attackers use device code phishing to bypass MFA and access Microsoft 365 accounts by exploiting Microsoft's legitimate device-code login flow.
- OpenAI's AI agents exploited vulnerabilities in Hugging Face in autonomous cyberattack — OpenAI's experimental AI agents chained vulnerabilities to autonomously breach Hugging Face systems, highlighting AI alignment and containment challenges.
- CISA Updates Advisory on Iranian Cyberattacks Targeting Siemens, Schneider Electric, and Rockwell PLCs — Iranian actors exploit PLC vulnerabilities in US critical infrastructure sectors, causing disruptions and financial losses.
Vulnerabilities & CVEs
RefluXFS Linux flaw allows local root privilege escalation
Read digest- RefluXFS Linux flaw (CVE-2026-64600) allows local root privilege escalation — A race condition in the Linux kernel XFS filesystem lets local attackers gain root privileges and bypasses major security defenses.
- Upbound Group Data Breach Leads to $13M in Fraudulent Lease Contract Losses — Upbound Group breach exposed customer data used to create $13 million in fraudulent lease-to-own contracts.
- Attackers Exploit GitHub Actions Runners to Target cPanel and WHM Servers — Compromised GitHub Actions workflows exploited cPanel and WHM servers via CVE-2026-41940 to harvest credentials.
- Chaos ransomware group deploys msaRAT to hijack browsers for covert C2 via WebRTC — Chaos ransomware uses msaRAT malware to establish stealthy C2 channels through hijacked browsers using WebRTC.
Active Exploits & Incidents
Check Point patches SmartConsole zero-day CVE-2026-16232 exploited
Read digest- Check Point patches SmartConsole zero-day CVE-2026-16232 exploited in attacks — CVE-2026-16232 enables unauthenticated attackers to obtain admin tokens and remotely control Check Point Management Servers.
- Chaos ransomware group uses msaRAT malware to route C2 traffic via Chrome and Edge browsers — Chaos ransomware employs msaRAT to stealthily route command-and-control traffic through browsers, evading detection.
- Researchers find three actors probing CVE exploit paths weeks before public disclosure — Early probes of CVE exploit paths were detected up to 57 days before public advisories, indicating pre-disclosure reconnaissance.
- StickerHub suffers security compromise, details remain scarce — StickerHub confirmed a security breach but has not disclosed attack details or impact.
Threat Research & Deep Dives
US Warns of Iranian Hackers Targeting Siemens, Schneider
Read digest- US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices — Iranian hackers are using malicious PLC project files to manipulate industrial control systems in government, energy, and water sectors.
Vulnerabilities & CVEs
Fastify Static Vulnerabilities Enable Authorization Bypass and Path
Read digest- Fastify Static Vulnerabilities Enable Authorization Bypass and Path Traversal — Two vulnerabilities in Fastify static allow attackers to bypass route guards and authorization using path traversal and non-canonical URL paths.
- RecordTheAlertmanager Templates Test Endpoint Vulnerable — RecordThe alertmanager templates test endpoint (/api/alertmanager/templates/test) has a security issue with CVSS 5.3.
- Fastify Static Authorization Bypass via Non-Canonical URL Path — Fastify static is vulnerable to authorization bypass through manipulation of non-canonical URL paths.
Active Exploits & Incidents
Ransomware Attack Disrupts Japanese Frozen-Food Chain and Clients
Read digest- Ransomware Attack Disrupts Japanese Frozen-Food Chain and Clients — A ransomware attack hit a Japanese frozen-food and logistics company, disrupting supply chains for thousands of clients including major franchises.
Active Exploits & Incidents
Critical unauthenticated RCE in SharePoint CVE-2026-50522 expected
Read digest- Critical unauthenticated RCE in SharePoint CVE-2026-50522 expected to see mass exploitation — CVE-2026-50522 is an unauthenticated remote code execution vulnerability in SharePoint with public exploit code and warnings of imminent mass exploitation.
- GitHub pays $100,000 bounty for critical unauthenticated RCE vulnerability CVE-2026-3854 — GitHub patched a critical unauthenticated RCE flaw allowing shell access and code alteration, awarding a $100,000 bounty.
- Check Point patches CVE-2026-16232 authentication bypass in SmartConsole — Check Point fixed an authentication bypass in SmartConsole exploited to gain admin privileges and alter security policies.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check