Rosetta Daily · Jul 5, 2026
Generated automatically · ~28 sources scanned · 17 items selected · window: past 24–48h
Critical Vulnerabilities
-
SharePoint Server RCE — Microsoft SharePoint (Subscription Edition / 2019 / 2016), CVE-2026-45659, CVSS 8.8 🔴🔥⚠️
Deserialization of untrusted data; an authenticated user with Site Member permissions can execute code remotely. Patched (out-of-band) in late May but disclosure lagged. Now under active exploitation.
The Hacker News · SecurityWeek -
Cisco Catalyst SD-WAN Manager privilege escalation — CVE-2026-20245, CVSS 7.8 ⚠️🔥
Authenticated local attacker gains root via a crafted malicious CSV upload. Mandiant found exploitation ~2 months before disclosure (late 2025–Jan 2026, and again March 2026). Fixed builds shipped June 12.
The Hacker News · Google Cloud / Mandiant
In-the-Wild Exploitation (CISA KEV)
-
CVE-2026-45659 (SharePoint) added to the CISA KEV catalog; FCEB remediation deadline July 4, 2026. One attack cluster attributed to Storm-2603, which deploys Warlock ransomware via on-prem SharePoint flaws.
CISA alert (Jul 1) -
Cisco Unified Communications Manager — attackers now exploiting a flaw patched in early June; Cisco confirmed active exploitation.
BleepingComputer
Vendor Advisories
-
Microsoft — next Patch Tuesday is July 14, 2026. Context: June 2026 was a record 206 CVEs (39 Critical), including Hyper-V OOB reads and multiple RDP client RCEs.
ZDI review -
Opera — shipped Paste Protect, a browser feature to block ClickFix-style attacks that trick users into pasting/executing malicious commands.
BleepingComputer
Web Security Research
-
Device code phishing + ClickFix — the combination bypasses MFA using legitimate Microsoft OAuth 2.0 device-authorization flow; victims paste a "verification code" into a real Microsoft page, handing the attacker access + refresh tokens for Outlook/Teams/OneDrive.
Proofpoint · Push Security -
ConsentFix + ClickFix — hijack Microsoft 365 accounts "in seconds" via fake prompts and OAuth consent abuse.
BleepingComputer
AI Security
-
Prompt injection remains OWASP LLM #1 ⚠️ — no complete fix exists; even frontier models stay vulnerable after best defenses. Unit 42 documented the first large-scale indirect prompt-injection attacks in the wild earlier in 2026 (ad-review evasion, system-prompt leakage). Critical CVEs across Microsoft Copilot, GitHub Copilot, and Cursor IDE show production exploitation.
Securance · Vectra -
Anthropic ships a cybersecurity classifier + jailbreak severity framework ⚠️🛡 — alongside redeploying Claude Fable 5, Anthropic added a safety classifier that blocks a specific cyber-jailbreak technique >99% of the time (blocked requests reroute to Opus 4.8), plus a draft industry jailbreak-severity framework and a HackerOne program for reporting cyber jailbreaks.
MarkTechPost
Threat Intelligence
-
Device code phishing goes mainstream — 37× spike in detections; ~18 kits available and every major AiTM vendor adding it. From espionage-grade (Storm-2372) to criminal commodity; 340+ M365 orgs targeted across five countries since February 2026.
Infosecurity · The Hacker News -
Mustang Panda (China-aligned) running two campaigns against Indian government and hydropower targets with new malware; active compromises inside senior administrative networks.
Industrial Cyber -
Screening Serpens (Iran-aligned) deployed six new RAT variants (incl. MiniJunk V2) Feb–Apr 2026 against US/Israel/UAE and Middle East targets.
Unit 42 -
Supply chain (npm) — 2026 has seen node-ipc (10M weekly downloads) credential-stealer versions, a 32-package @redhat-cloud-services compromise, and a malicious @bitwarden/cli. npm v12 (security overhaul) is expected in July.
Unit 42 · StepSecurity
Chinese-Language Community Picks
- Community highlights this cycle track the international picture: SharePoint CVE-2026-45659 entering KEVand device code phishingwere the most frequently reposted topics across Chinese security accounts this week; worth watching FreeBuf / Anquanke for localised analysis of the SharePoint deserialization exploit chain and ClickFix variants.
- (FreeBuf / Anquanke / Xianzhi Community were not fetched item-by-item this run — see "restricted sources" at the end.)
Ransomware Today
9 new leak-site posts in the last 24h across 4 groups. Most active: Qilin (5) — still 2026's most active operator — then Play (2), with The Gentlemen and Titan one each. 7 posts hit the watchlist (Qilin ×5, Play ×2); "TQ Financial Services" also flags the financial sector.
Full victim table
Bug Bounty
Bug Bounty has its own daily deep-dive track (analysis + themed recent disclosures).
Open the Bug Bounty daily track
AI Frontier
OpenAI
- Announced a new custom Jalapeñoinference chip (July 1); staffing up ahead of a planned IPO.
Anthropic
- Claude Sonnet 5launched July 1 — its most agentic model yet (autonomous browser/terminal use, near-Opus-4.8 performance at lower cost).
- Claude Fable 5redeployed globally after US export controls lifted; added cyber safeguards, a draft jailbreak-severity framework (with Glasswing partners), and a HackerOne reporting program .
- Claude Scienceworkbench for researchers launched (June 30).
Google DeepMind / AI
- Nano Banana 2 Lite— fastest/most cost-efficient image-generation model.
- Gemini Robotics-ER 1.6integrated into Boston Dynamics' Spot and Orbit inspection platform.
Failed / Limited Sources
- PortSwigger Research, FreeBuf, 安全客, 先知社区 — HTML/RSS not individually retrieved this run (fetch provenance gate); cross-cutting hot topics (SharePoint KEV, device-code phishing) are widely mirrored in Chinese community feeds.
- RansomLook — API OK (
/api/posts?days=1).
Sources used: see intel/sources.yaml