Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
Meta has filed a patent for an AI system that continuously analyzes users' voices to infer emotional states, logging timestamps, locations, activities, and phone usage for each read. The system could operate persistently or intermittently.
CVE-2026-49814: high vulnerability (CVSS 7.2)
CVE-2026-49814 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7 and several LTS releases. A high-privileged attacker with remote access could exploit an OS Command Injection flaw, enabling arbitrary command execution.
CVE-2026-49815: high vulnerability (CVSS 7.2)
CVE-2026-49815 affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7 and specific LTS releases, allowing high-privileged remote attackers to execute arbitrary OS commands via improper input neutralization. CVSS score is 7.2, marking it as a high-severity vulnerability.
CVE-2026-53905: high vulnerability (CVSS 7.1)
CVE-2026-53905 allows low-privileged users to access admin ACL structures via the /admin-view-hierarchy/get-acl-tree-structure endpoint in MCO v25.3.3.1, exposing sensitive permissions and configurations. Vendor contact attempts failed; other versions may be vulnerable.
CVE-2026-48276: critical vulnerability (CVSS 10.0)
CVE-2026-48276 affects ColdFusion versions 2025.9, 2023.20, and earlier, enabling arbitrary code execution via unrestricted file uploads. No user interaction is required, and the vulnerability carries a CVSS score of 10.0 due to its critical impact and scope change.
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
China-aligned hackers exploited critical flaws in Roundcube webmail to target physics and engineering departments at U.S. and Canadian universities. The attack leveraged CVE-2024-42009 to steal credentials.
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
AI in software supply chains introduces new risks, complicating security beyond traditional concerns like open-source dependencies. It challenges the integrity of code generation and the trustworthiness of AI models used in development.
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
Suspected China-nexus hackers are deploying DcRAT via spear-phishing emails impersonating India's Income Tax Department. The campaign, dubbed Operation DragonReturn, targets taxpayers, finance teams, and tax professionals to steal sensitive data.
CVE-2026-13552: high vulnerability (CVSS 7.3)
CVE-2026-13552 affects itsourcecode Online Hotel Management System 1.0, allowing remote SQL injection via /admin/mod_amenities/controller.php?action=edit. Public exploit availability heightens the risk of unauthorized data access or system compromise.
CVE-2026-13527: high vulnerability (CVSS 7.3)
CVE-2026-13527 affects SourceCodester Class and Exam Timetabling System 1.0 via SQL injection on /preview4.php. Remote exploitation is possible, and a public exploit is available, raising the risk of compromise.
Chinese LLMs Broaden the Gap Between Attackers & Defenders
Chinese firms have introduced advanced LLMs that rival US models, potentially amplifying cyber threats. These models could empower attackers with sophisticated tools, widening the gap between offensive and defensive capabilities.
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Researchers discovered AI-generated ransomware exploiting Chromium APIs to execute browser-based attacks on Windows and Android. The malware uses DeepSeek to craft innovative techniques combining theoretical concepts with real browser capabilities for in-browser encryption operations.
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA has mandated federal agencies to patch an actively exploited vulnerability in Cisco Unified Communications Manager Server by Sunday. The flaw poses significant risks to critical infrastructure if left unaddressed.
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
Gaslight, a Rust-based macOS malware, uses prompt injection to disrupt AI-assisted analysis, tricking automated tools into aborting or misinterpreting investigations. It doubles as an information stealer, targeting macOS systems with deceptive strategies.
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
This week's bulletin highlights Smart TV proxyware misuse, a 24-year-old curl vulnerability, and emerging AI crime forums, alongside other security stories. Threats range from credential misuse to trusted apps behaving maliciously, with phishing tactics evolving through unconventional workflows.
Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
Richard Bejtlich emphasizes the critical role of Network Detection and Response (NDR) in addressing gaps in incident investigations, where alerts alone often fail to provide full context or actionable insights. He advocates for deeper telemetry analysis to answer key investigative questions effectively.
CVE-2026-34909: Ubiquiti UniFi OS Path Traversal Vulnerability (Ubiquiti UniFi OS)
CVE-2026-34909 in Ubiquiti UniFi OS enables path traversal, allowing attackers with network access to exploit file access and potentially compromise accounts. Immediate patching per vendor and CISA BOD 26-04 guidelines is critical to mitigate risks.
CVE-2026-46802: critical vulnerability (CVSS 9.9)
CVE-2026-46802 is a critical vulnerability (CVSS 9.9) in Oracle WebCenter Portal's Security Framework, affecting versions 12.2.1.4.0 and 14.1.2.0.0. A low-privileged attacker can exploit it remotely via HTTP, leading to portal takeover and potential impacts on other products.
FortiBleed Attackers Turn Firewalls Into Credentials Stealers as Heist Persists
FortiBleed attackers use a Golang-based sniffer to exploit 430,000 FortiGate firewalls globally, stealing 110 million credentials in an ongoing campaign. This attack highlights significant risks in firewall security configurations.
LastPass confirms data breach in Klue supply chain attack
LastPass disclosed a breach where attackers accessed customer data via stolen OAuth tokens from the Klue supply chain attack, exploiting its Salesforce environment. The incident highlights third-party risks in SaaS integrations.
The Exploit Doesn't Exist. You Can Still Prove It Works Against You
Attackers are exploiting newly disclosed vulnerabilities faster than organizations can patch. Picus Security highlights methods for validating exploitability before public exploits emerge.
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
GitHub has updated 'actions/checkout' to block pwn request attacks exploiting 'pull_request_target' workflows. This change aims to secure the software supply chain by preventing malicious code execution with elevated privileges.
Stop Your Legacy Infrastructure from Hijacking Your AI Agents
Legacy infrastructure is being exploited by attackers to hijack AI agents, bypassing AI security measures. With 71% of organizations piloting AI agents, this blind spot poses a critical risk to security programs.
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
This week's threats highlight recurring issues: browser vulnerabilities, EDR-targeting malware, botnets exploiting IoT devices, critical OpenBSD flaws, and Android trojans demanding excessive permissions. Attack vectors include weak credentials, malicious downloads, and over-privileged browser extensions.
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices
Canada's spy agency, CSIS, obtained a groundbreaking warrant to neutralize foreign-operated botnets by accessing infected servers, routers, and IoT devices within Canada. This is the first use of CSIS's threat reduction powers in this manner.
AryStinger botnet infected thousands of D-Link routers worldwide
The AryStinger botnet has infected over 4,000 outdated D-Link routers globally, leveraging them as proxies for malicious traffic. This malware exploits vulnerabilities in older firmware versions to gain control and spread its network of compromised devices.
New Prinz Eugen ransomware prioritizes recent files for encryption
The Prinz Eugen ransomware targets recently modified files for encryption and avoids leaving a ransom note, complicating detection and recovery efforts. Its stealthy approach suggests a focus on operational disruption over financial extortion.
CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability (Splunk Enterprise)
CVE-2026-20253 in Splunk Enterprise allows unauthenticated users to create or truncate files via a PostgreSQL sidecar service endpoint. Immediate mitigation is required per CISA BOD 26-04 guidelines to prevent exploitation.
Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
An unknown threat actor uses fake reviews, AI narrators, and promoted posts on legitimate sites to spread malicious crypto clipper campaigns. They leverage WordPress phishing pages, GitHub/SourceForge projects, and YouTube videos to amplify reach.
Sweeping Credential-Harvesting Heist Compromises +30K Fortinet Devices
Attackers have harvested credentials from over 30,000 Fortinet devices across nearly 200 countries, targeting critical sectors globally. Active exploitation suggests widespread compromise and a growing threat landscape.
Why Account Takeovers Are Rising and How to Stop Them
Account takeovers are surging due to phishing, session hijacking, and MFA fatigue attacks. Specops Software emphasizes device trust and continuous verification as key defenses against these threats.
Microsoft confirms Office apps launch issues after June updates
Microsoft is investigating an issue where third-party apps fail to launch Office applications or open documents on updated Windows systems after June updates. Affected users are advised to monitor for patches or workarounds.
CISA warns of another cPanel plugin flaw exploited in attacks
CISA issued a directive for U.S. agencies to patch CVE-2026-54420, a vulnerability in the LiteSpeed cPanel plugin, actively exploited in the wild. Agencies have 72 hours to secure servers and mitigate risks tied to this flaw.
New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds
Rokarolla, a new Android banking trojan, targets 217 financial apps and uses 137 remote commands to steal PINs, SMS codes, and cryptocurrency funds. It also disables Google Play protections and manipulates clipboard data to hijack crypto transactions.
Chinese hackers breach REDCap servers, steal medical research
Chinese hackers exploited vulnerable REDCap servers, deploying InfiniteRed malware to exfiltrate sensitive medical research data from a North American institution. The attack is linked to espionage activities targeting healthcare and research sectors.
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
This week's threats include a Chrome 0-day exploit, UniFi vulnerabilities, macOS stealers, and a critical VPN flaw. Attackers exploited outdated tools, deprecated features, and abandoned software, while phishing kits and AI-themed lures gained traction.
FBI disrupts massive AI-powered phishing service using a million URLs
The FBI, alongside Google and Black Lotus Labs, dismantled Outsider Enterprise, a Chinese phishing-as-a-service operation leveraging AI to manage over a million phishing URLs targeting sensitive data like passwords and credit card information.
CVE-2026-11577: high vulnerability (CVSS 7.2)
CVE-2026-11577 impacts Keycloak, enabling limited admins to exploit improper access controls via the partialImport endpoint. This bypasses Fine-Grained Admin Permissions, allowing privilege escalation to full realm administrator by importing users with elevated role mappings.
CVE-2026-50752: high vulnerability (CVSS 7.4)
CVE-2026-50752 exposes a flaw in IKEv1's certificate validation logic, enabling MITM attackers to bypass authentication in VPN site-to-site connections. This could lead to traffic interception or modification within the VPN tunnel.
Chinese hackers hijack auth flow, spy on isolated network for a decade
Chinese hackers compromised an organization's authentication infrastructure, maintaining covert access for a decade. This allowed them to monitor administrative activities within an isolated network environment.
CVE-2026-49777: critical vulnerability (CVSS 10.0)
CVE-2026-49777 in Product Slider Pro for WooCommerce (pre-3.5.4) allows attackers to exploit improper input validation, enabling malicious software injection. CVSS score: 10.0 (critical).
Check Point VPN Flaw Exploited Since Early May
A critical zero-day vulnerability in Check Point VPN has been exploited since May, with Qilin ransomware affiliates linked to at least one attack. This flaw poses significant risks to enterprise networks relying on the affected VPN solution.
AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload
AI-powered phishing campaigns are overwhelming SOC Tier 1 analysts with high alert volumes, leveraging automation to craft convincing lures rapidly. This surge increases risks of overlooked threats like credential theft or malware delivery.
CVE-2026-10227: high vulnerability (CVSS 7.3)
CVE-2026-10227 affects raisulislamg4's student_management_system_by_php, allowing SQL injection via the 'role' parameter in add_user_check.php. Remote exploitation is possible, and a public exploit exists. The project has been informed but remains unresponsive.
Silent Ransom Group targets law firms with fake IT support calls
The Silent Ransom Group is targeting U.S. law firms and professional services with fake IT support calls, exploiting social engineering tactics to steal sensitive data within hours of contact, per Mandiant's report.
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
An AI agent uncovered 21 zero-days in FFmpeg, a widely-used media library. Separately, Google released Chrome 149, patching a record 429 security bugs in a single update. Only the FFmpeg vulnerabilities were AI-discovered.
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
CISA reports active exploitation of a patched high-severity SolarWinds Serv-U flaw, enabling attackers to crash servers. The vulnerability poses significant risks to affected systems.
CVE-2026-10191: high vulnerability (CVSS 8.8)
CVE-2026-10191 affects Tenda W12 3.0.0.7(4763), allowing remote exploitation via cgiWifiMacFilterSet in /bin/httpd, leading to stack-based buffer overflow. Public exploit code is available, posing high risk (CVSS 8.8).
CVE-2026-46137: critical vulnerability (CVSS 9.8)
CVE-2026-46137 is a critical Linux kernel vulnerability (CVSS 9.8) affecting the Multipath TCP (MPTCP) protocol. A data race issue in the ADD_ADDR timer callback was resolved by enforcing socket locks with bh_lock_sock().
FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads
Operation FlutterBridge leverages malicious Google and YouTube ads to distribute a macOS backdoor named FlutterShell. This campaign, linked to the JSCoreRunner cluster, signals a sophisticated evolution in malware targeting Apple systems.
Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
Gamaredon (Russia-nexus APT) is weaponizing CVE-2025-8088, a WinRAR path traversal flaw, to deliver GammaPhish HTA payloads that chain-load GammaWorm and GammaSteel against Ukrainian targets. The campaign focuses on credential harvesting and USB-based lateral propagation.
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited
Google's June 2026 Android update addresses 124 CVEs, with CVE-2025-48595 (CVSS 8.4) in the Framework component confirmed actively exploited — a zero-interaction privilege escalation requiring immediate patching.
CVE-2026-40817: high vulnerability (CVSS 7.5)
CVE-2026-40817 is an unauthenticated SQLi in the getAlarmProfiles function, exploitable remotely with no credentials required. CVSS 7.5 reflects full confidentiality loss—attackers can exfiltrate the entire dataset reachable by the query. No integrity or availability impact is listed, but data exposure alone is critical in alarm/monitoring contexts.
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones," security researcher Ammar Askar said. GitHub supports a feature called GitHub.dev that runs as
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
The Fragmented State of Modern Enterprise Identity Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams, machine identities, and autonomous systems. The result is Identity Dark Matter: identity activity that sits outside the visibility of centralized IAM and beyond the reach of
Microsoft's Coreutils project brings Linux commands to Windows
Microsoft's Build 2026 debut of Coreutils for Windows ships native GNU-equivalent binaries (grep, find, curl, chmod, etc.) directly into the Windows ecosystem. This expands the living-off-the-land binary (LOLBin) surface and introduces Unix permission semantics onto NTFS, creating potential ACL confusion. Defenders must update detection baselines immediately.
Instagram users locked out after Meta AI abused to steal accounts
Attackers exploited Meta's AI-powered account recovery tools by constructing convincing ownership narratives, bypassing identity verification and seizing Instagram accounts. The AI's intent to be helpful became its attack surface — social engineering shifted from humans to LLMs.
Regional credit union says ransomware gang stole member data
A regional credit union confirmed a ransomware gang exfiltrated member PII prior to encrypting systems, following the now-standard double-extortion playbook. Operations have been shifted to backups while the breach is investigated. Member financial and personal data is at risk of dark-web exposure or sale.
Critical unauthenticated RCE in widely-deployed edge VPN appliance (CVSS 9.8)
A pre-auth remote code execution flaw in a popular SSL-VPN appliance is now on CISA's KEV list with confirmed in-the-wild exploitation. Patch or disconnect immediately.
Regional US bank discloses breach exposing ~1.2M customer records
A mid-size regional bank confirmed attackers exfiltrated customer PII and partial account data after compromising a third-party file-transfer appliance. Notifications begin this week.
Healthcare network diverts ambulances after ransomware hits scheduling systems
A multi-site healthcare provider took clinical systems offline following a ransomware intrusion, reverting to paper workflows and diverting emergency traffic while it rebuilds from backups.
Researchers demonstrate indirect prompt injection that hijacks tool-using AI agents
A new write-up shows how a poisoned web page or document can silently redirect an autonomous agent's tool calls — exfiltrating data or triggering unintended actions — without the user noticing.
New open-source tool auto-converts CISA KEV entries into detection rules
A community project released a utility that watches the KEV catalog and generates draft Sigma/Splunk detections for newly-listed vulnerabilities, shortening the gap between disclosure and coverage.
KEV→Sigma Generator — turns newly-exploited CVEs into tuned detection drafts
A tool I built that watches the CISA KEV catalog and produces validated Sigma rule drafts with false-positive guardrails baked in, plus a Splunk/Sentinel export. Tested against sample telemetry before it emits anything.