Security Intel Feed
Cyber Hose
Page 36 of 44
Vendor Bulletins & Advisories
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
Read digest- F5 Patches Multiple NGINX, BIG-IP Vulnerabilities — F5 released critical patches addressing multiple vulnerabilities in NGINX and BIG-IP products that allow code execution and configuration changes.
- CVE-2026-58078: Unauthenticated SQL Injection in Joomla Quix Page Builder Pro — Critical unauthenticated SQL injection in Joomla extension can lead to data exfiltration and full site compromise.
- OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 — OpenAI developed GPT-Red, an AI tool to automatically discover and exploit prompt injection vulnerabilities for adversarial training.
- Multiple WordPress Plugin Vulnerabilities Allow SQLi, XSS, and Privilege Escalation — Numerous WordPress plugins have authenticated and unauthenticated vulnerabilities including SQL injection, XSS, and privilege escalation requiring urgent patching.
Vulnerabilities & CVEs
Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
Read digest- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover — Zoom released urgent patches for a critical vulnerability affecting Windows clients that could allow attackers to take over accounts.
- China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans — Leading Chinese cybersecurity companies face increasing military procurement bans likely tied to geopolitical or policy shifts.
Vulnerabilities & CVEs
Old UEFI Shims Expose Systems to Secure Boot Bypass
Read digest- Old UEFI Shims Expose Systems to Secure Boot Bypass — Outdated Microsoft-signed UEFI shim bootloaders contain vulnerabilities that allow attackers to bypass Secure Boot, risking persistent malware.
- Ransomware uses AI to amp up negotiations — The FulcrumSec ransomware group leverages AI to enhance extortion tactics after simple initial access breaches.
- Police Disrupt a €140M Cyber Fraud Ring in Spain — Spanish law enforcement dismantled a cybercrime syndicate laundering €140 million, disrupting significant fraud infrastructure.
- AI Agent for Reconnaissance — A new AI-powered reconnaissance tool automates target information gathering, signaling growing AI use in offensive recon.
Vulnerabilities & CVEs
CVE-2026-53366: ipv4 frag gap handling flaw in Linux kernel
Read digest- CVE-2026-53366: ipv4 frag gap handling flaw in Linux kernel — A critical Linux kernel IPv4 bug can cause memory corruption or denial of service; patch recommended for affected versions.
Threat Research & Deep Dives
The npm Threat Landscape: Attack Surface and Mitigations
Read digest- The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) — Unit 42 details evolving npm supply chain threats including wormable malware and multi-stage attacks targeting JavaScript ecosystems.
Active Exploits & Incidents
Dutch police bust investment fraud ring stealing over €100 million
Read digest- Dutch police bust investment fraud ring stealing over €100 million — Dutch authorities arrested multiple suspects in an international investment fraud scheme impacting tens of thousands of victims.
- Forgotten Bootloaders Expose Secure Boot Blind Spot — Revoked UEFI shim bootloaders remained trusted for years, allowing attackers to bypass Secure Boot protections.
- listmonk: SQL Injection in `/api/subscribers/export` — A user-controlled query parameter in listmonk allows SQL injection, risking data exfiltration.
- Multiple critical vulnerabilities in 9Router AI router & token saver — Several severe flaws in 9Router AI allow remote code execution, SSRF, authentication bypass, and persistent unauthorized changes.
Vulnerabilities & CVEs
Zoom warns of critical account takeover vulnerability
Read digest- Zoom warns of critical account takeover vulnerability — Zoom disclosed a critical vulnerability in its Windows desktop client and SDK that allows unauthenticated attackers to hijack user accounts.
- Security researchers find stalkers abusing Chrome’s sync feature — Researchers revealed that Google Chrome’s sync feature is being exploited by stalkers to monitor victims’ online activity covertly.
- Identity Attacks Overtake Exploits as Top Ransomware Cause — Email-based identity attacks surpassed software exploits as the leading cause of ransomware incidents despite widespread MFA use.
Vulnerabilities & CVEs
Multiple Critical Vulnerabilities in TDengine IoT Time-Series Database
Read digest- Multiple Critical Vulnerabilities in TDengine IoT Time-Series Database — TDengine versions up to 3.4.1.15 have multiple flaws including remote code execution, denial of service, and info disclosure risks.
- Supply Chain Compromise in SAP CAP-js/cds-dbs Packages — Malicious package versions published in April 2026 pose supply chain risks for SAP Cloud Application Programming Model users.
- AIDR: CrowdStrike’s Next-Gen Cybersecurity Framework — CrowdStrike introduces an AI-driven detection and response framework to modernize SOC operations and reduce analyst fatigue.
- Ogma: Open-Source Next-Gen Web Security Proxy Seeking Pentesters — A new Rust/Vue.js proxy tool offers advanced pentesting features and AI-assisted copilot capabilities as a Burp Suite alternative.
Active Exploits & Incidents
SonicWall customers under threat as attackers exploit 2 zero-days
Read digest- SonicWall customers under threat as attackers exploit 2 zero-days — Attackers are chaining two zero-day vulnerabilities in SonicWall devices, exploited in the wild before vendor patches.
- Google Gemini CLI abused as a hacking agent, malware botnet operator — A Russian-speaking threat actor is weaponizing Google’s Gemini CLI AI tool to automate hacking and run a botnet.
- OpenWrt ACL bypass and arbitrary root file read (CVE-2026-62947) — OpenWrt versions prior to 25.12.5 allow ACL bypass enabling arbitrary root file reads on embedded devices.
- TuxBot v3 Evolution shows signs of LLM-assisted IoT botnet development — New IoT botnet framework TuxBot v3 appears partially generated with large language model assistance.
Active Exploits & Incidents
CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities
Read digest- CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities — CISA warns of active exploitation of three SharePoint vulnerabilities, including two zero-days currently used in targeted attacks.
- Unpatched Cursor Vulnerability Exposes Users to Code Execution — A critical flaw in Cursor allows automatic execution of a malicious git.exe placed in a project root, enabling remote code execution.
- We built a vulnerability vending machine: AI tokens in, zero-days out — Researchers detail an AI-powered system that autonomously discovers complex zero-day vulnerabilities, marking a new evolution in automated exploitation.
- Establishing a Coordinated Vulnerability Disclosure Program — Joint guidance from CISA, NSA, and partners outlines best practices for implementing coordinated vulnerability disclosure programs.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check