Security Intel Feed
Cyber Hose
Page 4 of 44
Threat Research & Deep Dives
Operation Jackal IV arrests 58 suspects in global cybercrime crackdown
Read digest- Operation Jackal IV arrests 58 suspects in global cybercrime crackdown — Authorities arrested 58 suspects linked to West African cybercrime networks involved in scams across 22 countries.
- EvilTokens Hijacks Microsoft 365 Sessions for AI-Assisted Fraud — EvilTokens steals Microsoft 365 tokens to conduct AI-assisted targeted financial fraud across 344 organizations.
- Malicious Rust Crates Delivered Build-Time Malware Across Developer Environments — Compromised Rust crates executed malware during builds, affecting developers on Windows, macOS, and Linux.
- Fake Codex ads trick Mac developers into running AMOS-like malware — Fake OpenAI Codex ads deliver macOS infostealer malware to developers via malicious Google ads and sites.
- Unit 42 Finds Most AI-Enabled Malware Samples Are Not Operational — Most AI-enabled malware samples remain in research stages, with few observed in production environments.
Active Exploits & Incidents
SEO-Poisoned Minecraft Client Sites Distribute WeedHack Malware
Read digest- SEO-Poisoned Minecraft Client Sites Distribute WeedHack Malware — McAfee found WeedHack malware distributed via fake Minecraft client sites using SEO poisoning, affecting many players with malicious Java files.
- Compass Security Details JavaScript Hooks for Passkey Penetration Tests — Compass Security developed JavaScript hooks to test and manipulate passkey authentication implementations in web applications.
- Anthropic Makes Enterprise-Managed Auth Available for Claude MCP Connectors — Anthropic launched enterprise-managed authorization for Claude MCP connectors, simplifying admin control over multiple supported tools.
Vulnerabilities & CVEs
The Events Calendar Unauthenticated PHP Object Injection
Read digest- The Events Calendar Unauthenticated PHP Object Injection — CVE-2026-78265 is a CVSS 9.8 unauthenticated PHP object injection vulnerability in a widely-used WordPress plugin.
- MasterStudy LMS Unauthenticated Arbitrary File Deletion (CVE-2026-78284) — CVE-2026-78284 is a CVSS 8.6 unauthenticated arbitrary file deletion vulnerability in the MasterStudy LMS plugin.
Threat Research & Deep Dives
Citizen Lab Uncovers Covert Exploitation of Global Telecom Networks
Read digest- Citizen Lab Uncovers Covert Exploitation of Global Telecom Networks — Covert surveillance actors maintained persistent access across telecom infrastructure in multiple countries, with confirmed victims in 80 nations.
- ClawHavoc Campaign Turns OpenClaw AI Agents Into Malware Delivery Tools — Attackers poisoned OpenClaw's ClawHub registry with 341 malicious skills delivering infostealers that exfiltrated credentials and developer secrets.
- CVE-2026-77635 — CVSS 9.2 — CakePHP SQL injection via FunctionsBuilder::jsonValue() — A high-severity SQL injection vulnerability in CakePHP's FunctionsBuilder::jsonValue() affects applications using PostgreSQL backends.
Vendor Bulletins & Advisories
U.S. sanctions alleged Iranian hackers after Mabna Institute
Read digest- U.S. sanctions alleged Iranian hackers after Mabna Institute indictment — The U.S. sanctioned alleged Iranian hackers who stole over 31 terabytes of academic data and intellectual property from hundreds of universities.
- CVE-2026-39975 — CVSS 9.4 — Combodo iTop: Remote code execution using external auth variable value — A critical remote code execution vulnerability in Combodo iTop allows attackers to exploit an external authentication variable value.
- CVE-2026-76835 — CVSS 9.3 — OAuth2 Proxy 7.15.2 through 7.15.4 Authentication Bypass via X-Forwarded-Uri — An authentication bypass in OAuth2 Proxy versions 7.15.2 through 7.15.4 can be exploited via a manipulated X-Forwarded-Uri header.
Active Exploits & Incidents
CISA adds critical Oracle proxy plug-in flaw to KEV catalog
Read digest- CISA adds critical Oracle proxy plug-in flaw to KEV catalog — CVE-2026-21962 is a CVSS 10.0 improper access control flaw in Oracle HTTP Server and WebLogic Server Proxy Plug-in, exploitable remotely by unauthenticated attackers.
- Fake GTA 6 Demo Sites Distribute Vidar Infostealer — Fraudulent Rockstar-branded GTA 6 sites deliver Vidar infostealer disguised as a game installer, stealing browser credentials and session data from fans.
- DrayTek VigorSwitch Multiple Models Missing Authorization in Syslog Functions — A cluster of 14 DrayTek VigorSwitch CVEs includes command injection, buffer overflow, and authorization flaws across multiple models with CVSS scores up to 8.8.
Active Exploits & Incidents
Dell discloses critical vulnerabilities in Networking OS10
Read digest- Dell discloses critical vulnerabilities in Networking OS10 — The advisory covers 67 CVEs with a maximum CVSS of 10.0 affecting command execution, session theft, and code execution in SmartFabric OS10 versions prior to 10.5.6.14.
- Dell ThinOS 10 Update Fixes 83 Critical Vulnerabilities — Dell patched 83 vulnerabilities in ThinOS 10 with a maximum CVSS of 9.8, all listed as known exploited vulnerabilities.
- ToxicPanda 2.0 Expands Android Banking and Device-Control Capabilities — The upgraded Android trojan targets 349 financial institutions across multiple countries with credential-stealing overlays and remote device-control commands.
- 40 Malicious Firefox Extensions Steal Crypto Wallet Secrets — Researchers identified 40 malicious Firefox add-ons impersonating Web3 wallets to steal recovery phrases, private keys, and clipboard data.
Active Exploits & Incidents
Latvia's CSDD Confirms Breach Affecting 1.2 Million People
Read digest- Latvia's CSDD Confirms Breach Affecting 1.2 Million People — Payment records of over 1.2 million people and 200,000 organizations were exposed, affecting roughly two-thirds of Latvia's population.
- 768 Exposed AWS Keys Still Grant Full Corporate Admin Access — Researchers found hundreds of company-linked AWS keys with root or AdministratorAccess privileges still active across Git, Docker, and CI/CD artifacts.
- Chameleon SEO Poisoning Delivers Cloaked Banking Phishing Pages — Attackers are poisoning Google and Bing search results to serve cloaked banking phishing pages targeting major financial institutions.
- South Korean startup platform breach exposed encryption key via API — A government-backed startup platform exposed data for about 5,000 applicants after its API returned an encryption key alongside encrypted data.
Vendor Bulletins & Advisories
Permissive GitHub Actions workflows expose tokens and secrets
Read digest- Permissive GitHub Actions workflows expose tokens and secrets to attackers — Attackers can abuse permissive GitHub Actions workflows to steal GITHUB_TOKEN credentials, secrets, and build artifacts.
- fake-captcha-clickfix-mac-backdoor — A fake captcha campaign tricks Mac users into installing a backdoor through clickfix-style social engineering.
- CVE-2026-78306 — DJI Drone Bluetooth Interface Unauthenticated DUML Command Execution — A CVSS 8.5 flaw in DJI drone Bluetooth allows unauthenticated DUML command execution.
Threat Research & Deep Dives
DOUBLECUP Appends a PowerShell Payload to PNG Files
Read digest- DOUBLECUP Appends a PowerShell Payload to PNG Files — A Russian loader-as-a-service active since June 2026 appends cleartext PowerShell scripts to PNG files to deliver CountLoader and DeviceManager RAT variants.
- Trojanized npm Packages Deliver RedC2 4.0 Linux Implant — Malicious npm packages are being used to distribute the RedC2 4.0 Linux implant to unsuspecting developers.
- CVE-2026-78168 — EFM ipTIME T24000M Critical Improper Authentication — A CVSS 8.9 improper authentication vulnerability affects the EFM ipTIME T24000M router.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check