Vulnerabilities & PatchesEmerging1 src
Voting machine researchers say federal work abruptly ended after Trump ally pushed back on their findings
LAS VEGAS — After spending roughly six weeks analyzing Dominion voting systems used in Puerto Rico’s 2024 elections, Mojave Research came back to the Trump administration with findings that startled its researchers.
The systems contained at least a dozen high- or critical-severity software vulnerabilities. Passwords were reused, firewalls were disabled and basic cryptographic protections were poorly implemented. And in Puerto Rico, active cellular hardware modems opened additional pathways into underlying software that was thought to be isolated.
But the small cybersecurity firm found no evidence that any of those weaknesses had actually been exploited, or that votes had been changed. The company still wanted more time to be certain.
Federal officials initially seemed willing to give them considerably more of it.
Vulnerabilities & PatchesEmerging1 src
Meeting Bank of Italy AI Guidance in the Post-Mythos Era with Picus
Key Takeaways
• The Bank of Italy warns that advanced AI models find and exploit software vulnerabilities in very little time.
• Attackers no longer need the skill or time once required, shrinking exploitation windows from months to hours.
• Bank of Italy guidance spans governance, cyber hygiene, exposure management, patching, monitoring, resilience testing, and third-party risk.
• Severity alone does not predict breaches, so validation evidence should drive patch, mitigate, monitor, or accept decisions.
• Picus Swarm connects BAS, Autonomous Pentesting, Exposure Validation, threat intelligence, and response in one governed workflow.
The Bank of Italy has warned financial institutions that advanced AI models can find software vulnerabilities and generate ways to exploit them in very little time. Attackers no longer need the same level of skill or time they once did [1].
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
CSS attacks on major webmail services can steal credentials, hijack sessions and manipulate AI tools connected to users’ inboxes.
PortSwigger researcher Gareth Heyes demonstrated something that should make every webmail team a little nervous: plain CSS, the styling language that’s supposed to just make text look nice, can be weaponized to steal passwords, hijack sessions, and manipulate AI tools reading your inbox. The research covers real attack chains against Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail.
The core idea is that email clients let HTML and CSS through with the assumption that styling can’t reach outside the message it’s attached to.
Vulnerabilities & PatchesEmerging1 src
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions
China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe.
China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing national security law and cybersecurity law as the basis for the review, and offers essentially nothing beyond that.
Vulnerabilities & PatchesEmerging1 src
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims.
Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own advisory says the vulnerability carries a CVSS score of 10. 0, and it let an unauthenticated attacker inject arbitrary SQL straight into the Metabase application database.
“We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1. 58 and above.” reads the advisory. “We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability.”
Vulnerabilities & PatchesEmerging1 src
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog.
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9. 6), to its Known Exploited Vulnerabilities (KEV) catalog .
The vulnerability is an OS Command Injection Remote Code Execution issue that resides in API in Progress ADC Products. An unauthenticated attacker can trigger the flaw to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints
In early July, cybersecurity firm eSentire observed exploitation attempts targeting CVE-2026-8037. Activity began June 29, 2026, but the attacks failed and no post-compromise activity was detected.
Vulnerabilities & PatchesEmerging1 src
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
Vulnerabilities & PatchesEmerging1 src
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn. ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.
Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity
Vulnerabilities & PatchesEmerging1 src
Kali365 Exploits Microsoft Device Login to Access US Corporate Data - Hackread
Kali365 Exploits Microsoft Device Login to Access US Corporate Data Hackread
Vulnerabilities & PatchesEmerging1 src
“Adult TikTok” searches lead to scams
Search for certain combinations of “TikTok” and adult content, and sooner or later you’ll land on a page promising exactly what you searched for: an endless feed of explicit clips, no signup required, just tap and watch.
There isn’t one.
On the other side of that click is an ad funnel dressed up as exclusive content.
These pages aren’t connected to TikTok itself. They simply exploit the platform’s name to attract search traffic. TikTok’s huge user base, and the number of people searching for adult content associated with the platform, make it an attractive lure both for advertisers and scammers.
What you need to know right away
Nothing on these pages is genuine content pulled from TikTok. Their entire business model is get you to click, sign up, or install something.
The operators don’t need to host any videos to make money.
Threat Actors & CampaignsEmerging1 src
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure
Vulnerabilities & PatchesEmerging1 src
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Overview
On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9. 8 .
An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.
In the blog post that JetBrains shared in tandem with CVE publication, they stated that attackers who exploit the vulnerability can read stored credentials and compromise CI/CD pipeline integrity. The impact of successful exploitation depends on the operating system privileges granted to the TeamCity server process.
Vulnerabilities & PatchesEmerging1 src
How AI is Rewriting the Zero-Day Playbook for Preemptive Security
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”
Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The data is siloed, context is missing, and time rapidly slips away.
Today, the window between a vulnerability’s disclosure and its active exploitation in the wild has essentially collapsed, making predictive lead time a thing of the past.
Vulnerabilities & PatchesEmerging1 src
Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)
Overview
On July 22, 2026, Check Point published a security advisory for CVE-2026-16232 , an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS).
By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting.
This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure.
Breaches & RansomwareEmerging1 src
The Next Evolution of MDR: Preemptive Defense and Agentic Investigation
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next.
In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days .
As the time between initial access and attacker movement continues to contract, security teams are being asked to operate within a much narrower window. AI is accelerating reconnaissance, vulnerability discovery, and campaign execution, while defenders are responsible for growing volumes of data across cloud, identity, endpoint, SaaS, and AI environments, often without equivalent growth in analyst capacity.
Vulnerabilities & PatchesEmerging1 src
Socket Releases Free Certified Patches for Nuxt Security Vulnerabilities
Nuxt has released security updates for multiple vulnerabilities affecting Nuxt 3. x and 4. x, along with a separate critical development-only vulnerability in @nuxt/devtools .
Nuxt 4. 5. 1 and 3. 21. 10 address issues including server-side remote code execution, authorization bypass, denial of service, and cross-user payload disclosure. @nuxt/devtools 3. 3. 1 fixes a critical remote code execution vulnerability affecting development servers.
Socket has published Certified Patches for two of the disclosed Nuxt advisories and is preparing patches for the remaining issues. Certified Patches for Critical and High severity vulnerabilities are free to use, including for teams that are not Socket customers.
Impact
#
The Nuxt release addresses eight GitHub Security Advisories across Nuxt and Nuxt DevTools.
Vulnerabilities & PatchesEmerging1 src
Modern Attack Vectors | Recorded Future
Key Takeaways
• Modern threat actors have shifted from brute-forcing firewalls to compromising digital identities via stolen session cookies and credential stuffing to bypass MFA entirely
• Adversaries increasingly target unpatched edge infrastructure like VPNs for zero-day access while exploiting open-source repositories to launch upstream supply chain attacks
• Traditional internal security telemetry may miss critical pre-attack signals, making real-time, outside-in threat intelligence essential to neutralizing modern vectors before a breach occurs
For today’s Chief Information Security Officers (CISOs) and security team leaders, defending your business can feel like trying to hold back the ocean.
Policy & RegulationEmerging1 src
The Shift: A New Era of AI Regulation
The export controls imposed on Anthropic’s Fable model mark a significant shift in United States (US) artificial intelligence (AI) policy. The controls set a precedent for treating frontier AI models as strategic assets rather than ordinary software products, creating uncertainty for enterprises adopting advanced AI.
Security leaders should respond by investing in resilient, interoperable AI strategies rather than simply chasing the most powerful model available.
The Saga of the Fable Export Controls
Because the US is home to most of the companies building leading models, US AI policy has an outsized impact on global access. The Trump administration’s public posture on AI has largely favored accelerating the frontier.
Vulnerabilities & PatchesEmerging1 src
June 2026 CVE Landscape
In June 2026, Insikt Group® identified 59 high-impact vulnerabilities that should be prioritized for remediation , 30 of which had a Very Critical Recorded Future Risk Score. This represents a 47% increase from last month.
23 of the 59 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 33 were reported by vendors, and three were primarily surfaced through honeypot data.
The 59 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 17% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.
Breaches & RansomwareEmerging1 src
JCPenney - 368,418 breached accounts
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees.
The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and
Vulnerabilities & PatchesEmerging1 src
[tl;dr sec] #331 - How Adversaries Use AI, Skill Issues, Using IDEs for C2
Hey there,
I hope you’ve been doing well!
👩❤️👨 Repo-mantic Comedy
Recently I had one of those moments where you remember that LLMs are trained on the vast, beautiful, complicated collection of human knowledge.
I was using Codex to port a feature from one code base to another, and it said:
“…I’m reading the exact code paths now so the port preserves behavior instead of inventing a prettier cousin .” 😂
Dear reader, I had questions. Like: how many bodice ripper novels and country music lyrics are in the training corpus? What other secrets lie in the weights?
I didn’t think I read anything about dating preferences in its model card.
[tl;dr sec] #330 - AWS Pathfinding Labs, Running Codex Safely at OpenAI, Glasswing Updates
Hey there,
I hope you’ve been doing well!
⛰️ Ain’t No Mountain High Enough
To keep me from sending to you bae.
Literally as I was starting to write this intro, my home Internet went out. After a moment I realized I had gotten a text a few days ago- scheduled maintenance with my Internet provider 😅
So now I’m finishing this issue via hot spotting with my phone.
I’ve wondered sometimes what I’d do if there was some sort of force majeure world or personal event that put my ability to finish the newsletter in jeopardy.
We cut to- *Movie trailer voice* In a world, where there’s too much security news…
Vulnerabilities & PatchesEmerging1 src
[tl;dr sec] #328 - Shai-Hulud's Source Code Leaked, Break Into Buildings for $, Reversing EDRs with AI
Hey there,
I hope you’ve been doing well!
☀️ My Least Favorite Type of Tan(Stack)
I had a fun personal anecdote to share but I didn’t have time to write it up this week.
For now, #HugOps to everyone dealing with yet another supply chain attack.
I hope you’re getting the support you need 🫂
Sponsor
📣 Cloud Security Has Changed. Has Your Strategy?
Vulnerabilities & PatchesEmerging1 src
[tl;dr sec] #327 - Finding Zero-days with Any Model, Practical Package Security, Measuring the AI Offense-Defense Gap
Hey there,
I hope you’ve been doing well!
🫶 Friend Visit
Last weekend I visited my good friend Aaron and his partner, staying at their place in southern California, and it was delightful .
There’s something special about meeting a friend’s partner and seeing their place, you get such a lovely insight into who they are and what they value. The bookshelves, the photos from their couple trips, the unique items they’ve picked up along the way.
We played a few rounds of this board game, Forbidden Island, which was a lot of fun, would recommend. Clint analytical brain was fully engaged, and people were amused 😅
I managed to delay doing an AI-powered Deep Research about optimal strategies until I was at the airport on the way back. It wasn’t easy.
Aaron was a work friend who became a normal friend over many Wednesday dinners.
Vulnerabilities & PatchesEmerging1 src
[tl;dr sec] #326 - AI Auto Exploiting Vulnerabilities, GitHub RCE, Autonomous Cloud Hacking Agent
Hey there,
I hope you’ve been doing well!
🤘 Hackathon
This week Semgrep friends have flown in from all over the world to crazily build together.
Engineers, security researchers, designers, and, as we are generous of spirit, even product managers.
The fact that we do this every few quarters is one of my favorite things about Semgrep.
A number of our coolest features came from a hack week: new engine features, AI triage before it was cool, and even Semgrep itself (back before that was the company’s focus, or name).
I also really appreciate the in person time for learning about who people are outside of work.
Vulnerabilities & PatchesEmerging1 src
[tl;dr sec] #325 - Dissecting Mythos, The $0 Security Stack, GitHub Action Red Team Framework
Hey there,
I hope you’ve been doing well!
😅 Bug Hunters Be Like
I was going to open with a fun, personal story, but then I got caught up trying to cover a round-up of what a bunch of folks are saying about Mythos and frontier of LLM-driven vulnerability discovery, and now it’s past midnight 😅
So for now I leave you this meme, H/T buherator :
Sponsor
📣 (Free!) Community Edition: Ready your attack surface for AI with runZero
Gearing up for a deluge of AI-powered exploits? You’re gonna need fast, accurate visibility into all your assets.
Vulnerabilities & PatchesEmerging1 src
TeamPCP Supply Chain Attacks
TeamPCP is exploiting trusted npm and PyPI packages to compromise developer environments, steal credentials, and extend attacks across software supply chains.
Vulnerabilities & PatchesEmerging1 src
CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform
Zerobot, a Mirai-based botnet known for targeting Internet of Things (IoT) devices, has leveraged a critical vulnerability tracked as CVE-2025-68613 to compromise instances of the n8n workflow automation platform.
Vulnerabilities & PatchesEmerging1 src
CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild
CVE-2026-20127 is an improper authentication vulnerability impacting Cisco Catalyst SD-WAN Controller, formerly vSmart, and SD-WAN Manager, formerly vManage, components.
Perspectives on Cybersecurity
I'm not a fan of many podcasts. I do like a conversational style, and there are some podcasts that I listen to, albeit not on a regular basis, and not for technical content. They're mostly about either "easter eggs" in Marvel or DC movies, or the conspiracies or speculation about an upcoming movie. Yeah, I know what you're thinking... why spoil it?
The fact of the matter is that the way things are going with these superhero movies, it's going to be 2 or more years before the movie even comes out, and there's no way I'm going to remember the podcast.
When it comes to technical content, however, my podcast or video preferences are much more stringent. I'm not a big fan of gratuitous small talk and hilarity; for technical content, I take a more focused approach, and would tend to look for show notes, rather than sit through chatter, ads, and shoutz to sponsors.
Privacy Is Like Broccoli
Privacy Is Like Broccoli
Illustration: Em / Privacy Guides
If you are just starting the journey to improve your privacy online, you might feel overwhelmed by all the information you recently learned. This is normal, don't panic!
When we first start learning about how much data is collected on us, and all the things we need to do to protect it, it's very common to feel stressed and distressed.
In a state of panic, you might be tempted to try doing it all at once, driven by an urgent desire to delete yourself from the entire internet, like right now! While this feeling is very understandable, this is the wrong approach.
The right approach is to see privacy like broccoli. Yes, broccoli, you have not misread me.
Privacy is like good health habits
Good privacy is very similar to good health habits.
Vulnerabilities & PatchesEmerging1 src
Repeater Strike: manual testing, amplified
Manual testing doesn't have to be repetitive. In this post, we're introducing Repeater Strike - a new AI-powered Burp Suite extension designed to automate the hunt for IDOR and similar vulnerabilities
Vulnerabilities & PatchesEmerging1 src
Drag and Pwnd: Leverage ASCII characters to exploit VS Code
Control characters like SOH, STX, EOT and ETX were never meant to run your code - but in the world of modern terminal emulators, they sometimes do. In this post, I'll dive into the forgotten mechanics
SAML roulette: the hacker always wins
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
Vulnerabilities & PatchesEmerging1 src
Unenroll your Pixel from the Android 12 Beta Program to get November’s update immediately
The November security patch was announced on Monday as the first update to Android 12 following its launch a few weeks earlier. This update includes a series of bug fixes , but Pixel owners that are still on the Android Beta Program have yet to receive the November release until they opt out.
Vulnerabilities & PatchesEmerging1 src
Android 12 November security patch rolling out to Google Pixel, factory images & OTAs live
The first update to Android 12 is rolling out today with the November security patch for the Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a 5G, Pixel 5, Pixel 5a, Pixel 6, and Pixel 6 Pro.
Vulnerabilities & PatchesEmerging1 src
Android 12 with October security patch live, download Pixel factory images & OTAs
Alongside the new phones , Google today is launching Android 12 for current Pixel devices. In addition to Material You, revamped Quick Settings, and a slew of other Android 12 additions, it features the October security patch. If it hasn’t rolled out to your device yet, Google just posted the official OTA and factory images.
Vulnerabilities & PatchesEmerging1 src
Android 11 October security patch rolling out to Google Pixel, factory images & OTAs live
Android 12 is not launching today . As such, we only have the October security patch with another Android 11 update for the Pixel 3, Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a (5G), Pixel 5, and Pixel 5a.
Vulnerabilities & PatchesEmerging1 src
September security patch rolling out to Google Pixel, factory images & OTAs live
With Beta 4.1 , Android 12 is almost ready to launch, but until then Android 11 with the September security patch is now available for the Pixel 3, Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a (5G), Pixel 5, and Pixel 5a.
Vulnerabilities & PatchesEmerging1 src
August security patch rolling out to Google Pixel, factory images & OTAs live
While the Android 12 Beta has improved in stability over recent releases, Android 11 still provides the most reliable experience. Google is now rolling out the August security patch for the Pixel 3, Pixel 3a, Pixel 4, Pixel 4a, Pixel 4a (5G), and Pixel 5.