Security Intel Feed
Cyber Hose
Page 32 of 44
Active Exploits & Incidents
Critical SharePoint RCE CVE-2026-50522 Actively Exploited After
Read digest- Critical SharePoint RCE CVE-2026-50522 Actively Exploited After Public PoC Release — Attackers exploit CVE-2026-50522 to execute remote code on SharePoint servers after public proof-of-concept release.
- Qilin Ransomware Exploits PAN-OS Auth Bypass for Initial Access — Qilin ransomware attackers exploit PAN-OS authentication bypass CVE-2026-0257 to gain network access and escalate privileges.
- Exploitation of ServiceNow CVE-2026-6875 Remote Code Execution Flaw Seen Days After Patch — ServiceNow CVE-2026-6875 sandbox escape RCE exploited shortly after patch release on hosted and self-hosted instances.
Active Exploits & Incidents
Estée Lauder Discloses Data Theft via Oracle EBS Zero-Day Exploit
Read digest- Estée Lauder Discloses Data Theft via Oracle EBS Zero-Day Exploit — Cl0p exploited a zero-day RCE in Oracle EBS to steal 870GB of sensitive employee data starting August 2025.
- Open-Source Android AI Agents Vulnerable to Invisible Screen Text Code Execution Attacks — Invisible text overlays enable remote code execution on Android AI agents via adb shell commands.
- Bit2Watt Attack Lets Cloud Tenants Disrupt Power Grids Using GPU Workloads — Cloud GPU workloads can be modulated to destabilize power grids without exploits or elevated privileges.
- HollowGraph Malware Uses Microsoft 365 Calendar for C&C Communication — Malware hides encrypted C&C messages in Microsoft 365 calendar events to evade detection.
- UCSD finds vulnerabilities in KARR car alarms affecting 2M+ vehicles, patch released — Security flaws in KARR car alarms allow remote hijacking of over 2 million vehicles, with a patch now available.
Active Exploits & Incidents
Qilin ransomware exploits critical Palo Alto GlobalProtect VPN auth
Read digest- Qilin ransomware exploits critical Palo Alto GlobalProtect VPN auth bypass — Qilin ransomware gang exploits CVE-2026-0257 to bypass VPN authentication, leading to network breaches and domain-wide encryption.
- Clover Health Investments Discloses Data Breach via Social Engineering Attack — Social engineering compromised employee accounts at Clover Health, exposing personal and protected health information.
- Meta paid $78,000 bounty for broken access control flaw exposing support data — Meta patched a broken access control vulnerability that exposed customer support data after a $78,000 bounty payment.
- Sandworm uses fake CAPTCHAs to trick users into running malware via PowerShell — Kremlin-backed Sandworm group uses fake CAPTCHAs on compromised websites to trick users into executing malware.
Threat Research & Deep Dives
TaintRadar enhances static vulnerability detection with
Read digest- TaintRadar enhances static vulnerability detection using semantic-aware code property graphs — TaintRadar augments static analysis with semantic layers to detect vulnerabilities like SQLi and stored XSS in PHP applications.
- Fuzz'EMup uses EM side-channel signals to guide black-box embedded firmware fuzzing — Fuzz'EMup leverages electromagnetic emanations to improve fuzzing coverage of embedded firmware without instrumentation.
Vulnerabilities & CVEs
Multiple Unrestricted Upload Vulnerabilities in D-Link DNS-320
Read digest- Multiple Unrestricted Upload Vulnerabilities in D-Link DNS-320 — Several CVEs reveal unrestricted upload flaws in D-Link DNS-320 components, enabling potential remote code execution or system compromise.
- SQL Injection in itsourcecode Hospital Management System — A SQL injection vulnerability in the prescriptionorder.php of itsourcecode Hospital Management System could allow attackers to manipulate database queries.
- Post-Authentication Command Injection in LogServer — A command injection flaw in LogServer's file handling after authentication could lead to remote command execution.
- Heap Use-After-Free in TeX Live SyncTeX Parser — Malformed SyncTeX files can trigger a heap use-after-free in TeX Live's SyncTeX parser, risking crashes or code execution.
Threat Research & Deep Dives
Multiple use-after-free flaws in Google Chrome before 150.0.7871.128
Read digest- Multiple use-after-free flaws in Google Chrome before 150.0.7871.128 — Several critical use-after-free vulnerabilities affect Chrome on desktop, Linux, Android, and Mac, enabling heap corruption and code execution.
- CVE-2026-55833 Netty SPDY zlib header block expansion flaw — A CVSS 7.5 vulnerability in Netty SPDY can cause decoded expansion beyond maxHeaderSize, risking resource exhaustion.
- CVE-2026-16327 D-Link DNS-320 unrestricted upload vulnerability — An unrestricted file upload vulnerability in D-Link DNS-320's upload.php could allow attackers to upload malicious files.
Active Exploits & Incidents
SonicWall SMA1000 zero-days exploited to deploy custom malware
Read digest- SonicWall SMA1000 zero-days exploited to deploy custom malware — Two zero-day vulnerabilities in SonicWall SMA1000 VPN appliances are actively exploited to install custom malware.
- WP2Shell Exploit Enables Remote Takeover of Millions of WordPress Sites — Attackers exploit two WordPress vulnerabilities to achieve remote code execution and site takeover.
- Hackers steal $23.7M from Ostium via off-chain price feed manipulation — Attackers manipulated off-chain price feeds to steal $23.75 million from the Ostium decentralized trading platform.
Active Exploits & Incidents
FakeGit Campaign Uses 7,600 GitHub Repos to Spread SmartLoader Malware
Read digest- FakeGit Campaign Uses 7,600 GitHub Repos to Spread SmartLoader Malware — The campaign targets GitHub users with thousands of malicious repos delivering SmartLoader malware and secondary payload StealC.
- Multiple vulnerabilities in FreeScout prior to 1.8.224 enable account takeover, RCE, and DoS — Critical flaws in FreeScout help desk software allow account takeover, remote code execution, and denial of service.
- GPT-SoVITS 20250606v2pro vulnerable to OS command injection via webui.py — An OS command injection vulnerability in GPT-SoVITS allows unauthenticated attackers to execute arbitrary commands.
- ktransformers before 0.6.3 vulnerable to unauthenticated pickle deserialization RCE via ZMQ — ktransformers suffers from an unauthenticated remote code execution via crafted pickle payloads on its ZMQ interface.
Threat Research & Deep Dives
HollowGraph Malware Uses Microsoft 365 Calendar for Stealthy C2
Read digest- HollowGraph malware uses Microsoft 365 calendar for stealthy C2 communications — HollowGraph malware uses Microsoft 365 calendar events and Microsoft Graph API with hardcoded credentials for covert command and control.
- Authenticated RCE in EGroupware via Malicious eTemplate Upload (CVE-2026-40187) — Authenticated admins can execute OS commands on EGroupware servers by uploading malicious eTemplate XML files.
- Exposed Server Reveals AI-Assisted Phishing Toolkit Targeting Windows via WebDAV — An AI-assisted phishing toolkit delivers infostealers via WebDAV to Windows users, mainly in Mexico, exploiting a WebDAV vulnerability.
- Attackers Use 'TFF Trap' Fileless Loader to Deploy RATs in BEC Phishing Campaigns — Fileless loaders are used in business email compromise phishing campaigns to deploy multiple RATs and stealers with low detection.
Active Exploits & Incidents
SonicWall SMA1000 Zero-Days Exploited to Deploy Custom Malware
Read digest- SonicWall SMA1000 Zero-Days Exploited to Deploy Custom Malware — Threat actors exploited SonicWall SMA1000 zero-days remotely without authentication to deploy custom malware before patches were issued.
- Pre-authentication RCE in WordPress Core via CVE-2026-63030 and CVE-2026-60137 — Two chained WordPress Core vulnerabilities enable unauthenticated remote code execution on default installs, with active exploitation.
- Russian Intelligence Hacks IP Cameras to Spy on NATO and Ukraine Military Logistics — Russian intelligence hijacks internet-connected IP cameras using default passwords and obsolete firmware to monitor military logistics.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check