Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-03
Daily Brief·2026-07-03·14 Sources·18 Items

Rosetta Daily · Jul 3, 2026

Generated automatically · 14 sources scanned · 18 items selected

Critical Vulnerabilities

  • Oracle E-Business Suite unauth RCE — Oracle EBS (Oracle Payments / File Transmission), CVE-2026-46817, releases 12.2.3–12.2.15
    Unauthenticated, low-complexity HTTP takeover. Defused observed first exploitation on June 27 — before public PoC. 900+ EBS instances exposed online; Google/Mandiant tie it to a widespread extortion campaign.
    BleepingComputer · Mandiant

  • Adobe ColdFusion & Campaign Classic — 7 max-severity flaws — CVE-2026-48276/48277/48281/48282/48283/48316 (ColdFusion) + CVE-2026-48286 (Campaign Classic)
    Six carry CVSS 10.0: unauthenticated RCE, low complexity, no user interaction, all Priority 1. Fixed in ColdFusion 2025 Update 10 / 2023 Update 21. No in-the-wild exploitation reported yet — patch within 72h.
    BleepingComputer · SecurityWeek

  • Progress Kemp LoadMaster OS command injection — CVE-2026-8037, CVSS 9.6
    Exploitation attempts observed starting June 29 by a Canadian security firm. OS command injection → RCE on the load balancer.
    The Hacker News

  • PTC Windchill PDMLink / FlexPLM RCE — CVE-2026-12569, CVSS 9.3
    Improper input validation → arbitrary code execution via crafted request. Added to CISA KEV on evidence of active exploitation.
    CISA KEV

In-the-Wild Exploitation (CISA KEV)

  • Microsoft SharePoint Server RCE — CVE-2026-45659, CVSS 8.8
    Deserialization of untrusted data; an authenticated attacker with Site Member permissions can execute code remotely (no admin needed). Added to KEV July 1; federal patch deadline July 4, 2026.
    The Hacker News · CISA

  • SimpleHelp RMM exploited — CVE-2026-48558
    Attackers exploiting SimpleHelp to deploy the TaskWeaver backdoor and Djinn Stealer.
    The Hacker News

Vendor Advisories

  • Adobe— out-of-band ColdFusion / Campaign Classic fixes (see Critical above); Priority 1, 72-hour patch guidance.
    SecurityWeek
  • Oracle— EBS File Transmission fix for CVE-2026-46817; apply immediately, review Payments logs for compromise.
    Cybersecurity Dive

Web Security Research

  • Email account compromise via CSS/HTML trust boundaries— PortSwigger
    New techniques weaving vectors past CSS sanitization, hardened CSP, and HTML filtering libraries to compromise webmail accounts (upcoming conference disclosure).
    PortSwigger Research
  • 2025 theme carryover— side-channels as a core exploitation primitive, malformed-chunk request desync, and new SAML techniques enabling full auth bypass remain live research fronts.
    PortSwigger Research

AI Security

  • ChocoPoC RAT hidden in fake PoC repos— targets vulnerability researchers
    Weaponized GitHub PoC repos claiming to exploit hot CVEs drop a Python RAT that steals saved passwords, browser cookies and files, then hands the attacker shell access. Classic supply-chain/researcher-targeting play.
    The Hacker News· BleepingComputer
  • Prompt injection in third-party AI chatbot plugins— IEEE S&P 2026
    "When AI Meets the Web" paper shows indirect prompt injection risks in third-party chatbot plugins embedded in websites.
    arXiv
  • Weaponized AI 2026 (Group-IB)— jailbreak-framework-as-a-service sold for $50–200/month on dark-web forums; industrialization of guardrail bypass continues.
    Group-IB

Threat Intelligence

  • Microsoft 365 password-spraying at scale— 81M+ login attempts over two weeks against M365 tenants; enforce MFA / conditional access and watch for legacy-auth abuse.
    BleepingComputer
  • DHS HSIN breach under investigation— the Homeland Security Information Network, an inter-agency info-sharing platform, was compromised; scope still being assessed.
    BleepingComputer

Ransomware Today

20 new leak-site posts in the last 24h across ~11 groups. Most active: worldleaks (4), brain cipher (3), safepay (3). ⭐ Watchlist hits: qilin (Pennant Hills Golf Club), inc ransom (RoundShield; Colorado Rehab & Occupational Medicine), plus a healthcare cluster — Anubis hit Northeast Pediatrics and Quest Healthcare Solutions.
Full victim table

Bug Bounty

The Bug Bounty track now updates on its own daily schedule (deep-dive analysis + themed recent disclosures).
Open the Bug Bounty daily section


AI Frontier

OpenAI

  • Confidentially filed an S-1 with the SEC (June 8) ahead of a public debut; recent private valuation ~$852B. Dean Ball joins July 6 to lead a new "Strategic Futures" team.

Anthropic

  • Closed financing at a $965Bvaluation (surpassing OpenAI's private mark) and said it confidentially filed for IPO. Nobel laureate John Jumper (AlphaFold) joined from Google DeepMind.

Google DeepMind / AI

  • Gemini Robotics-ER 1.6 integrated into Boston Dynamics' Spot robot dog and the Orbit AI visual-inspection platform via a Google Cloud + DeepMind partnership.

Failed Sources (if any)

  • Chinese community sources (FreeBuf / 先知 / 安全客) — not individually fetched this run; no material selected.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 2, 2026
Next →
Rosetta Daily · Jul 4, 2026