Security Intel Feed
Cyber Hose
Page 9 of 44
Vendor Bulletins & Advisories
Chrome 151 and Firefox 154 Patch Dozens of Security Flaws
Read digest- Chrome 151 and Firefox 154 Patch Dozens of Security Flaws — Google and Mozilla released browser updates fixing dozens of vulnerabilities including critical buffer overflows in Chrome and 20 high-severity flaws in Firefox.
- CVE-2026-75981 — TranslatePress through 3.2.5 — A CVSS 7.2 vulnerability affects the TranslatePress multilingual translation WordPress plugin through version 3.2.5.
- CVE-2026-15780 — WP Statistics through 14.16.8 — A CVSS 7.2 unauthenticated stored cross-site scripting flaw affects the WP Statistics WordPress plugin through version 14.16.8.
Active Exploits & Incidents
Clop Exploits Critical PTC Windchill and FlexPLM Flaw for Data Theft
Read digest- Clop Exploits Critical PTC Windchill and FlexPLM Flaw for Data Theft — Clop is actively exploiting CVE-2026-12569, an unsafe-deserialization RCE in PTC Windchill and FlexPLM, to deploy web shells and exfiltrate product data across manufacturing, aerospace, and defense sectors.
- Slovakia finds Russian components and security risks in speed cameras — Slovakia's Interior Ministry discovered Russian-made components in traffic speed cameras supplied through intermediaries, raising state-security concerns.
- CVE-2026-70408 — Incorrect authorization in acmailer — A CVSS 8.7 incorrect authorization vulnerability in acmailer could allow unauthorized access to affected systems.
Vendor Bulletins & Advisories
Oracle August 2026 CSPU Fixes 925 CVEs Across 23 Product Families
Read digest- Oracle August 2026 CSPU Fixes 925 CVEs Across 23 Product Families — Oracle's August 2026 CSPU delivers 943 patches for 925 CVEs across 23 product families, with Fusion Middleware and Hyperion receiving the most fixes.
Vendor Bulletins & Advisories
FortiWeb RADIUS Admin Flaw Enables Unauthenticated GUI and CLI Access
Read digest- FortiWeb RADIUS Admin Flaw Enables Unauthenticated GUI and CLI Access — CVE-2026-26035 allows unauthenticated attackers to gain administrative control of FortiWeb via RADIUS wildcard authentication settings.
- Fortinet appliances affected by HTTP/2 Bomb memory-exhaustion flaw — CVE-2026-49975 enables denial of service across FortiProxy, FortiPam, and FortiSwitch Manager with public proof-of-concept exploit code available.
- Dell discloses 88 third-party vulnerabilities in VPLEX — Dell rated the advisory Critical with a CVSS score of 9.8 covering 88 vulnerabilities in multiple third-party VPLEX components.
- Dell warns of two high-severity AMD fTPM BIOS vulnerabilities — CVE-2026-6726 and CVE-2026-6727 affect AMD fTPM across Ryzen, Threadripper, and EPYC families in Dell client platforms.
Threat Research & Deep Dives
CoSnitch flaws let one click hijack Microsoft Copilot Personal
Read digest- CoSnitch flaws let one click hijack Microsoft Copilot Personal — CVE-2026-24301 allowed crafted links to execute prompts in authenticated Copilot sessions and exfiltrate connected Gmail, Google Drive, and calendar data.
- AWS details custom authentication for AgentCore Gateway tool integrations — AWS described using a request Lambda interceptor to add custom authentication to AgentCore Gateway for legacy HTTP Basic Authentication environments.
Threat Research & Deep Dives
U.S. charges 17 Iranians over Mabna Institute cyber-theft campaign
Read digest- U.S. charges 17 Iranians over Mabna Institute cyber-theft campaign — Seventeen Iranian hackers-for-hire allegedly stole 31 TB of research from 144 U.S. universities, 42 companies, and five government agencies.
- Microsoft Copilot Personal flaws enabled one-click data exfiltration — Three CoSnitch flaws in Microsoft Copilot Personal allowed attackers to steal mail, calendar, and Drive data via a crafted link.
- CVE-2026-55166 — CVSS 9.9 — Lemur: Incomplete fix for ACME authority update endpoint — A critical Lemur vulnerability marked as an incomplete fix for a prior ACME authority update endpoint issue carries a CVSS 9.9 score.
- NVIDIA Triton Inference Server: Critical Path Traversal Leads to DoS — CVE-2026-47627 is a CVSS 9.8 path traversal flaw in NVIDIA Triton Inference Server that can cause denial of service.
Active Exploits & Incidents
CISA Flags Microsoft IKE Service Extensions Double-Free Flaw
Read digest- CISA Flags Microsoft IKE Service Extensions Double-Free Flaw CVE-2026-33824 — A double-free vulnerability in Microsoft IKE Service Extensions enabling remote code execution was added to CISA's KEV catalog with active exploitation.
- Operation CameraSwarm Compromised 14,530+ Dahua Cameras — Hunt.io observed an operator compromise over 14,000 Dahua cameras across Ukraine and Russia using credential brute force and authentication bypass exploits.
- Updated advisory details Medusa ransomware's expanding victim count and tactics — U.S. agencies report Medusa ransomware has surpassed 500 victims, leveraging access brokers and unpatched Fortra and BeyondTrust flaws for initial access.
Vendor Bulletins & Advisories
GitLab Issues Emergency Patch for Critical GraphQL Code-Injection Flaw
Read digest- GitLab Issues Emergency Patch for Critical GraphQL Code-Injection Flaw — CVE-2026-19478 allows remote unauthenticated code injection via GraphQL API to modify or delete public projects.
- BTMob Fraud Platform Uses 1,402 Servers for Android Device Takeovers — BTMob powers Android device takeovers through a fraud-as-a-service platform affecting users, banks, and providers.
- GEEKOM Mini PC Realtek LAN Driver Package Found Infected With Asruex Trojan — A Realtek LAN driver package on a legacy GEEKOM support page was found infected with the Asruex Trojan.
- Projextor Hides Malware in Trojanized Electron Productivity Apps — Projextor malware embedded in Electron apps can execute JavaScript, run commands, and capture screens.
Threat Research & Deep Dives
StopAndProtect Ransomware Targets Thousands of WordPress Sites
Read digest- Check Point Unmasks StopAndProtect Ransomware Operation Targeting WordPress Sites — Check Point Research identified a ransomware operation that has hacked thousands of WordPress sites using ClickFix social engineering to deliver PowerShell payloads.
- TWINLOOT Uses Microsoft Cloud Services for Stealthy C2 and Credential Theft — Ontinue uncovered a Python implant that hides C2 traffic inside SharePoint and Teams while stealing Windows credentials without requiring administrator rights.
- Audit finds RCE-by-design flaws across seven AI orchestration platforms — An audit of seven AI orchestration platforms including Flowise and Langflow found 14 security findings exposing multi-tenant services to remote code execution.
- CISA Says Ransomware Gangs Exploit Windows Task Host Flaw — CISA warns that ransomware gangs are actively exploiting a Windows Task Host vulnerability tracked as CVE-2025-60710.
Active Exploits & Incidents
CISA says ransomware gangs are exploiting a Windows Task Host flaw
Read digest- CISA says ransomware gangs are exploiting a Windows Task Host flaw — CISA flagged a high-severity Windows Task Host vulnerability as actively exploited by ransomware gangs targeting Windows users.
- Shadow hVNC Gives Attackers Invisible Control of a Second Windows Desktop — Shadow hVNC malware-as-a-service toolkit creates hidden Windows desktops to steal credentials, cookies, and financial data from enterprise environments.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check