This website uses cookies

Read our Privacy policy and Terms of use for more information.

Patch fatigue is the story today. Palo Alto's GlobalProtect bug is now confirmed feeding Qilin ransomware crews straight into domain-wide encryption, CISA just forced federal agencies to fix a Langflow RCE that's already being hit 220-plus times, and a fresh SharePoint deserialization flaw went from public PoC to active exploitation within hours. Check Point had its own management-console bypass added to the KEV list too. None of these are theoretical anymore — they're live breach paths, and the gap between patch and exploit keeps shrinking to nothing.

The AI angle cuts both ways. Researchers used Kimi K3 agents to find and weaponize Redis zero-days in under half an hour, which is a good look for defenders — but attackers are running the same playbook, seeding over 7,600 fake GitHub repos designed to get AI coding assistants to recommend malware, and shipping an infostealer with its own "AI Profiler" to rank victims by value.

On the breach side, healthcare and identity data keep leaking at scale: DentaQuest's 23 million, MCBS's 1.2 million, plus Estée Lauder tracing straight back to last year's Clop Oracle campaign. And the Klue story is worth sitting with — a SaaS breach where a second gang stole the stolen data from the first gang and started its own extortion round, which is as good a sign as any that paying ransom buys nothing.

Redis pushed seven security releases on July 23 after researchers published authenticated RCE proof-of-concept exploits against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0, all requiring RESTORE access plus, in some chains, EVAL, XGROUP, or the bundled RedisBloom module. The bugs involve a Streams shared-NACK use-after-free and a RedisBloom/TDigest out-of-bounds write; fixes landed in versions 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, and 8.8.1. Researchers behind the finds, using Kimi K3 AI agents, claim to have surfaced 19 Redis zero-days in roughly 90 minutes and built the 8.8.0 exploit in 27 minutes, though those claims are self-reported and Redis's own advisories list no CVE or CVSS score, with no confirmed in-the-wild exploitation as of July 24, 2026.

Check Point has confirmed active exploitation of CVE-2026-16232, an authentication bypass affecting its Security Management and Multi-Domain Management products, letting attackers steal login tokens and gain full administrator access via SmartConsole. The company says a limited number of customers with internet-exposed management environments were hit, and has released patches, mitigations and IoCs; CISA added the flaw to its KEV catalog, giving federal agencies until July 25 to remediate. Check Point also patched two related internally discovered bugs, CVE-2026-62144 and CVE-2026-62145, though only CVE-2026-16232 has been exploited so far, with no attacker attribution confirmed.

Multiple Qilin ransomware affiliates are exploiting CVE-2026-0257, a critical authentication bypass in Palo Alto Networks' PAN-OS GlobalProtect VPN, to breach networks and deploy domain-wide encryption, according to Arctic Wolf Labs. Palo Alto patched the flaw May 13, but exploitation began May 17 and CISA added it to its Known Exploited Vulnerabilities catalog May 29; the agency confirmed ransomware use of the bug on Monday. Shadowserver and Shodan count more than 167,000 and 172,000 exposed GlobalProtect instances respectively, out of a customer base topping 70,000 organizations worldwide.

CISA has ordered federal agencies to patch CVE-2026-0770, a critical unauthenticated remote code execution flaw in the Langflow AI agent framework, by Friday. Vulnerability tracker KEVIntel recorded over 220 exploitation attempts from 64 unique IPs starting June 27, with attackers attempting to deploy malware, steal AWS credentials, and access container metadata. It's the fourth Langflow vulnerability CISA has flagged as actively exploited, following flaws already tied to ransomware attacks by the JadePuffer gang.

A patched flaw in the Adobe Acrobat Chrome extension, used by more than 314 million people, let malicious web pages silently pull data from a victim's open WhatsApp Web session. Tracked as CVE-2026-48294 (CVSS 7.4) and dubbed HermeticReader by Guardio Labs, the bug affected all extension versions through 26.5.2.2 and required only that a user visit a crafted page, letting attackers read chat lists, contact names, profile info and open conversation text without stealing credentials or cookies.

The threat group Golden Chickens, also tracked as TAG-195 or Venom Spider, has rolled out four new modular malware families as part of its malware-as-a-service platform, aimed at stealing Chrome credentials and hijacking browser sessions. The tools — TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator — reflect an architectural shift toward more flexible, post-exploitation capabilities for customers of the group's criminal services.

Researchers at ReliaQuest identified an ongoing campaign, active since at least June 2026, in which attackers compromise Wi-Fi gateways at hotels and conference centers in the US, India, and Saudi Arabia, then use DNS poisoning to redirect traveling employees in finance, law, healthcare, energy, and retail to fake Microsoft 365 login pages like m365-owa.com. The tradecraft resembles the APT28-linked "FrostArmada" campaign, with attackers also abusing Windows' WPAD proxy feature in about a third of cases and, in some instances, hijacking Microsoft's device-code sign-in flow to steal MFA-cleared session tokens without a password.

Attackers are actively exploiting CVE-2026-50522, a critical deserialization flaw in on-premises Microsoft SharePoint servers (CVSS 9.8), after public proof-of-concept code appeared on July 20. WatchTowr's honeypot network detected exploitation within hours, with attackers stealing SharePoint machine keys in a single request to maintain access even after patching. Researchers urge organizations to apply Microsoft's July patch and rotate machine keys and other credentials that may have been exposed.

Quick Hits

Reply

Avatar

or to participate

Keep Reading