View Ridge Security

Security Intel Feed

Cyber Hose

Page 37 of 44

Active Exploits & Incidents

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch

Read digest
  • Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch TuesdayA new PoC exploit named LegacyHive targets a Windows User Profile Service (ProfSvc) arbitrary hive load elevation of privilege vulnerability. This zero-day allows attackers to escalate privileges by loading malicious user profile hives. Immediate patching and monitoring for exploit attempts are critical.
  • Windows Bind Link Attacks Can Hide Malware From EDR ToolsBitdefender researchers reveal a novel technique abusing Windows bind links to create conflicting filesystem views, effectively hiding malware from endpoint detection and response (EDR) tools. This evasion tactic complicates detection and requires updated EDR heuristics and monitoring for suspicious bind link activity.
  • SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.Traditional SASE inspection models fail to address risks introduced by AI-driven workflows, unsanctioned browser extensions, and autonomous agents operating in SaaS and browser environments. Security teams must evolve beyond packet inspection to include behavioral and AI-contextual analysis to prevent data exfiltration and IP leakage.
  • PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-DiscoveryPraisonAI’s plugin manager loads and executes arbitrary Python files from project and user directories without validation, enabling remote code execution. Upgrade to 1.6.78 or later to mitigate.
  • US Court Denies Warrant for Mass Phone Snooping Using StingrayA recent U.S. court ruling rejected a government warrant that sought to use a cell-site simulator ("stingray") to collect data on thousands of uninvolved Ohio residents. This sets a precedent limiting bulk surveillance via IMSI catchers and highlights ongoing privacy and legal challenges in law enforcement surveillance technology.
Active Exploits & Incidents

Two Men Indicted for ATM Jackpotting Scheme in Nevada

Read digest
Active Exploits & Incidents

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code

Read digest
  • Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code ExecutionA critical flaw in Cursor on Windows allows automatic execution of a malicious git.exe binary placed in a project root without user interaction or warnings. This enables attackers to execute arbitrary code with the user’s privileges, accessing source code, SSH keys, and cloud tokens persistently while the project remains open. Immediate review of Cursor usage and environment hygiene is advised.
  • KFC Faces Possible Closures After Cyberattack on Japan's NichireiA cyberattack on Nichirei, a major Japanese food supplier, is causing operational disruptions impacting KFC outlets in Japan. This incident highlights risks in food supply chain cybersecurity and potential cascading effects on retail operations. Monitoring for further details and supply chain risk mitigation is recommended.
  • TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted DevelopmentUnit 42 analyzed TuxBot v3, an IoT botnet framework developed with large language model (LLM) assistance. The report details its cross-compiled binaries, command-and-control architecture, and embedded bugs, revealing how AI is accelerating malware sophistication in IoT environments. This signals a new wave of AI-augmented malware development requiring updated detection strategies.
  • OkoBot: New Sophisticated Malware Framework Targets Cryptocurrency UsersKaspersky GReAT uncovered OkoBot, a complex malware framework targeting crypto users by stealing seed phrases and monitoring Chromium-based browsers. It deploys multiple payloads including the Rilide stealer and TookPS backdoor, indicating a multi-stage infection chain designed for persistent crypto asset theft. Crypto custodians and wallet providers should prioritize detection and mitigation of these tactics.
  • White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination InitiativeFollowing the June 2 AI-focused Executive Order, the White House introduced the Gold Eagle program to leverage AI for faster vulnerability coordination across government and private sectors. This initiative aims to accelerate patch deployment and threat intelligence sharing, signaling increased federal emphasis on AI-powered vulnerability management. Security teams should watch for integration opportunities and compliance impacts.
Active Exploits & Incidents

CISA warns admins to patch actively exploited SharePoint flaws

Read digest
Vendor Bulletins & Advisories

Microsoft: Some Dell PCs shut down after recent Windows updates

Read digest
Active Exploits & Incidents

US charges alleged operators of Russian bulletproof hosting service

Read digest
  • US charges alleged operators of Russian bulletproof hosting serviceU.S. prosecutors charged three Russian nationals running a bulletproof hosting (BPH) service that supported ransomware gangs responsible for over $62M in global damages. This takedown disrupts a critical infrastructure node enabling ransomware operations.
  • CVE-2026-15583: SSRF (confused deputy) in Grafana MCP ServerUnauthenticated remote attackers can exploit a confused-deputy SSRF flaw via the X-Grafana-URL header to exfiltrate environment-configured Grafana service-account tokens. This allows potential privilege escalation and lateral movement in compromised environments. Patch or mitigate immediately.
  • CVE-2026-15804: SQL Injection in MetaGuru HCMAuthenticated remote attackers can inject SQL commands through specific parameters, risking data confidentiality and integrity. Affects MetaGuru’s Human Capital Management software. Prioritize patching and review database access controls.
  • CVE-2026-14251: Missing allowednamespace check in OpenShift GitOps operatorNamespace-scoped Argo CD instances can trigger unauthorized reconciliation of ClusterRole objects due to lack of ownership validation, enabling privilege escalation within Kubernetes clusters. Critical for organizations using OpenShift GitOps to apply fixes or implement compensating controls.
  • Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 UpdatesGoogle Chrome 150 and Firefox 152 address multiple critical vulnerabilities, including publicly available exploit code for Firefox flaws (no in-the-wild exploitation reported yet). Immediate patching recommended to close attack vectors.
Active Exploits & Incidents

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin

Read digest
  • Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin CommandsSonicWall warns of active exploitation targeting SMA 1000 series appliances via two zero-days, including CVE-2026-15409 (CVSS 10.0), a critical SSRF vulnerability enabling remote unauthenticated attackers to execute arbitrary commands. Immediate patching or mitigation is critical to prevent full system compromise.
Active Exploits & Incidents

SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits

Read digest
Vulnerabilities & CVEs

Microsoft July 2026 Patch Tuesday fixes 569 CVEs including 3 zero-days

Read digest

Assess Your Exposure

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check