Security Intel Feed
Cyber Hose
Page 8 of 44
Active Exploits & Incidents
Malicious Firefox Extensions Target Crypto Wallets With Secret Theft
Read digest- Malicious Firefox Extensions Target Crypto Wallets With Secret Theft — Forty malicious Firefox extensions impersonating Web3 wallet brands steal recovery phrases, private keys, and credentials from cryptocurrency users.
- Cross-Model Replay Exposes Encrypted Reasoning Traces From Major LLM APIs — Researchers recovered encrypted reasoning blocks from Anthropic, OpenAI, and Google LLM APIs by replaying them into weaker sibling models.
- Expired Visa Contactless Cards Can Be Reanimated for Purchases — UMass researchers demonstrated that expired Visa contactless cards can still authorize payments by rewriting the expiration date during NFC relay.
- CVE-2026-18776 — TrueBooker Appointment Booking before 1.2.7 - Unauthenticated Account Takeover — A CVSS 9.8 unauthenticated account takeover vulnerability affects the TrueBooker Appointment Booking WordPress plugin before version 1.2.7.
Threat Research & Deep Dives
U.S. Agencies Warn of AI-Assisted Attacks on Siemens S7 PLCs
Read digest- U.S. Agencies Warn of AI-Assisted Attacks on Siemens S7 PLCs — AI-assisted threat actors target Siemens S7 PLCs across multiple critical infrastructure sectors using advanced reconnaissance and exploitation techniques.
- Claude Opus uncovers SAML authentication bypasses across four projects — AI tool Claude Opus revealed multiple SAML authentication bypass vulnerabilities affecting widely used projects.
- Zimbra CVE-2026-73570 RCE Exploited in the Wild — Remote code execution vulnerability in Zimbra is actively exploited, prompting urgent advisories.
Threat Research & Deep Dives
T-Mobile Cut a Network Cable to Expel Salt Typhoon Hackers
Read digest- T-Mobile Cut a Network Cable to Expel Salt Typhoon Hackers — T-Mobile detected and physically disconnected a compromised router to stop Salt Typhoon hackers targeting telecom data.
- Post-training cuts excess authority in terminal and MCP agents — Researchers trained an LLM agent to reduce unnecessary authority in terminal and MCP tasks, improving safety and success rates.
- AUTOSIGMA automates Sigma rule generation from threat intelligence — AUTOSIGMA converts unstructured CTI reports into validated Sigma detection rules for better SIEM integration.
- Researcher proposes multi-agent cyber defense architecture for connected vehicles — A three-tier multi-agent system is proposed to secure V2X communications against fabricated emergency alerts.
- Detecting DCSync Attacks Through Directory Replication Event Logs — A detection method for DCSync attacks using Active Directory replication event logs that requires no malware on domain controllers.
Vulnerabilities & CVEs
Agno's PythonTools Path Traversal: Arbitrary File Access & RCE
Read digest- Agno's PythonTools Path Traversal: Arbitrary File Access & RCE — CVE-2026-76832 scores CVSS 8.5 and enables arbitrary file access and remote code execution via path traversal in Agno's PythonTools.
- NULL Pointer Dereference in Wireshark X.509IF protocol dissector crash — CVE-2026-76928 scores CVSS 7.5 and causes a crash in Wireshark's X.509IF protocol dissector via a NULL pointer dereference.
Vulnerabilities & CVEs
Critical RCE in LMDeploy via Unsafe Pickle Deserialization
Read digest- Critical RCE in LMDeploy via Unsafe Pickle Deserialization — CVE-2026-76850 enables remote code execution in LMDeploy through unsafe pickle deserialization, rated CVSS 9.3.
- Remote Code Execution in Splunk via Deserialization of Untrusted Data — CVE-2026-76404 allows RCE in Splunk by exploiting deserialization of untrusted data, with a CVSS score of 9.1.
- Stack-Based Buffer Overflow in TRENDnet TV-IP751WIC — CVE-2026-76584 is a CVSS 8.6 stack-based buffer overflow vulnerability affecting TRENDnet TV-IP751WIC devices.
- Server-Side Request Forgery in Cisco Talos Intelligence — CVE-2026-76389 allows SSRF attacks via the REST API in Cisco Talos Intelligence, rated CVSS 8.8.
Threat Research & Deep Dives
Elementor Pro flaw enables unauthenticated file upload and RCE
Read digest- Elementor Pro flaw enables unauthenticated file upload and remote code execution — CVE-2026-32475 allows unauthenticated attackers to upload executable PHP files via the Forms module, affecting Elementor Pro version 4.2.1 or earlier.
- AWS details user-authorization propagation for Bedrock AgentCore AI agents — AWS describes a pattern for passing user authorization context through Bedrock AgentCore agents to enforce least-privilege access in shared-agent scenarios.
- search-v2-operator Assigned Cluster-Admin-Equivalent Privileges — Red Hat disclosed CVE-2026-70496 involving cluster-admin-equivalent privileges assigned to the search-v2-operator.
- CVE-2026-55194 — FreeRDP Heap-buffer-overflow write in TS Gateway RPC RESPONSE reassembly — A CVSS 8.7 heap-buffer-overflow write in FreeRDP's TS Gateway RPC response reassembly headlines a batch of multiple FreeRDP CVEs this run.
Active Exploits & Incidents
U.S. Agencies Warn of Active Threat to Siemens S7 PLCs
Read digest- U.S. Agencies Warn of Active Threat to Siemens S7 PLCs — Threat actors are actively targeting Siemens S7 Series PLCs across U.S. manufacturing, energy, water, and chemical sectors using AI-generated tools.
- Critical NetScaler Flaws Enable Authentication Bypass and Denial of Service — Cloud Software Group disclosed two critical NetScaler vulnerabilities enabling authentication bypass on SSL VPN and denial of service via SIP ALG.
- China-Nexus Actor Uses JPEG-Masquerading VHDs to Deliver QUICAgent — A China-nexus actor targeted Myanmar government personnel with QUICAgent, a Go-based backdoor delivered via VHD files masquerading as JPEG images.
- Mirage2FA Steals Microsoft 365 Sessions After Users Complete MFA — An adversary-in-the-middle phishing platform is stealing Microsoft 365 session cookies after users complete MFA, targeting U.S. technology and manufacturing sectors.
Active Exploits & Incidents
Leak Exposes 669 Stripe Vendors and 1,033 Live API Keys
Read digest- Leak Exposes 669 Stripe Vendors and 1,033 Live API Keys — A threat actor published a 33GB release containing live API keys and customer data for 669 businesses using Stripe across multiple industries.
- SilkParasite Targets Central Asian Governments With Seven RAT Families — A China-nexus APT cluster deployed seven RAT families including five newly documented variants against government entities across six Central Asian countries.
- Password-spraying attacks surge 155x as MFA gaps leave logins exposed — Huntress observed a 155-fold increase in password-spraying attacks during H1 2026 exploiting legacy authentication and incomplete MFA coverage.
- Balonx Sistema Uses AI Voice Calls to Bypass MFA and Steal Bank Accounts — Banking customers are being targeted with AI-generated voice calls and fake banking pages that capture login credentials and MFA codes.
Threat Research & Deep Dives
RAVEN Demonstrates Elasticsearch Data Theft and Persistent Backdoor
Read digest- RAVEN Demonstrates Elasticsearch Data Theft and Persistent Backdoor Access — RAVEN can export Elasticsearch data and create rogue users and API keys to maintain persistent access.
- Fake Crypto AML Checkers Trick Users Into Draining Their Wallets — Scammers use fake AML-checking sites to trick crypto users into approving wallet access and draining funds.
- NIST Releases Cybersecurity Tips for Building Automation Systems — NIST guidance targets building automation systems to reduce cyberattack risks in commercial and federal buildings.
- StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites for Malware Operations — The StopAndProtect malware campaign leveraged thousands of compromised WordPress sites for its operations.
- CVE-2026-52813: Fixed Critical RCE in Gogs — A critical remote code execution vulnerability in Gogs has been fixed, rated CVSS 10.0.
Active Exploits & Incidents
CISA warns of active exploitation of critical Windows IKE RCE flaw
Read digest- CISA says attackers are exploiting critical Windows IKE RCE flaw — CVE-2026-33824 is a CVSS 9.8 double-free vulnerability enabling unauthenticated remote code execution on Windows IKE Service Extensions.
- CISA flags exploited Microsoft, VMware and Apple vulnerabilities — Four exploited vulnerabilities affecting Microsoft, VMware, and Apple products were added to CISA's KEV catalog.
- Cursor Windows Flaw Enables Code Execution via Malicious Repository Files — A Cursor IDE flaw allows arbitrary code execution on Windows through malicious repository-root git.exe.
- BeyondTrust Windows EPM Flaws Enable Local Privilege Escalation — Two Windows EPM flaws allow local attackers to escalate privileges and bypass anti-tamper controls.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check