Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-05
Daily Brief·2026-07-05·17 Items

Rosetta Daily · Jul 5, 2026

Generated automatically · ~28 sources scanned · 17 items selected · window: past 24–48h

Critical Vulnerabilities

  • SharePoint Server RCE — Microsoft SharePoint (Subscription Edition / 2019 / 2016), CVE-2026-45659, CVSS 8.8 🔴🔥⚠️
    Deserialization of untrusted data; an authenticated user with Site Member permissions can execute code remotely. Patched (out-of-band) in late May but disclosure lagged. Now under active exploitation.
    The Hacker News · SecurityWeek

  • Cisco Catalyst SD-WAN Manager privilege escalation — CVE-2026-20245, CVSS 7.8 ⚠️🔥
    Authenticated local attacker gains root via a crafted malicious CSV upload. Mandiant found exploitation ~2 months before disclosure (late 2025–Jan 2026, and again March 2026). Fixed builds shipped June 12.
    The Hacker News · Google Cloud / Mandiant

In-the-Wild Exploitation (CISA KEV)

  • CVE-2026-45659 (SharePoint) added to the CISA KEV catalog; FCEB remediation deadline July 4, 2026. One attack cluster attributed to Storm-2603, which deploys Warlock ransomware via on-prem SharePoint flaws.
    CISA alert (Jul 1)

  • Cisco Unified Communications Manager — attackers now exploiting a flaw patched in early June; Cisco confirmed active exploitation.
    BleepingComputer

Vendor Advisories

  • Microsoft — next Patch Tuesday is July 14, 2026. Context: June 2026 was a record 206 CVEs (39 Critical), including Hyper-V OOB reads and multiple RDP client RCEs.
    ZDI review

  • Opera — shipped Paste Protect, a browser feature to block ClickFix-style attacks that trick users into pasting/executing malicious commands.
    BleepingComputer

Web Security Research

  • Device code phishing + ClickFix — the combination bypasses MFA using legitimate Microsoft OAuth 2.0 device-authorization flow; victims paste a "verification code" into a real Microsoft page, handing the attacker access + refresh tokens for Outlook/Teams/OneDrive.
    Proofpoint · Push Security

  • ConsentFix + ClickFix — hijack Microsoft 365 accounts "in seconds" via fake prompts and OAuth consent abuse.
    BleepingComputer

AI Security

  • Prompt injection remains OWASP LLM #1 ⚠️ — no complete fix exists; even frontier models stay vulnerable after best defenses. Unit 42 documented the first large-scale indirect prompt-injection attacks in the wild earlier in 2026 (ad-review evasion, system-prompt leakage). Critical CVEs across Microsoft Copilot, GitHub Copilot, and Cursor IDE show production exploitation.
    Securance · Vectra

  • Anthropic ships a cybersecurity classifier + jailbreak severity framework ⚠️🛡 — alongside redeploying Claude Fable 5, Anthropic added a safety classifier that blocks a specific cyber-jailbreak technique >99% of the time (blocked requests reroute to Opus 4.8), plus a draft industry jailbreak-severity framework and a HackerOne program for reporting cyber jailbreaks.
    MarkTechPost

Threat Intelligence

  • Device code phishing goes mainstream — 37× spike in detections; ~18 kits available and every major AiTM vendor adding it. From espionage-grade (Storm-2372) to criminal commodity; 340+ M365 orgs targeted across five countries since February 2026.
    Infosecurity · The Hacker News

  • Mustang Panda (China-aligned) running two campaigns against Indian government and hydropower targets with new malware; active compromises inside senior administrative networks.
    Industrial Cyber

  • Screening Serpens (Iran-aligned) deployed six new RAT variants (incl. MiniJunk V2) Feb–Apr 2026 against US/Israel/UAE and Middle East targets.
    Unit 42

  • Supply chain (npm) — 2026 has seen node-ipc (10M weekly downloads) credential-stealer versions, a 32-package @redhat-cloud-services compromise, and a malicious @bitwarden/cli. npm v12 (security overhaul) is expected in July.
    Unit 42 · StepSecurity

Chinese-Language Community Picks

  • Community highlights this cycle track the international picture: SharePoint CVE-2026-45659 entering KEVand device code phishingwere the most frequently reposted topics across Chinese security accounts this week; worth watching FreeBuf / Anquanke for localised analysis of the SharePoint deserialization exploit chain and ClickFix variants.
  • (FreeBuf / Anquanke / Xianzhi Community were not fetched item-by-item this run — see "restricted sources" at the end.)

Ransomware Today

9 new leak-site posts in the last 24h across 4 groups. Most active: Qilin (5) — still 2026's most active operator — then Play (2), with The Gentlemen and Titan one each. 7 posts hit the watchlist (Qilin ×5, Play ×2); "TQ Financial Services" also flags the financial sector.
Full victim table

Bug Bounty

Bug Bounty has its own daily deep-dive track (analysis + themed recent disclosures).
Open the Bug Bounty daily track


AI Frontier

OpenAI

  • Announced a new custom Jalapeñoinference chip (July 1); staffing up ahead of a planned IPO.

Anthropic

  • Claude Sonnet 5launched July 1 — its most agentic model yet (autonomous browser/terminal use, near-Opus-4.8 performance at lower cost).
  • Claude Fable 5redeployed globally after US export controls lifted; added cyber safeguards, a draft jailbreak-severity framework (with Glasswing partners), and a HackerOne reporting program .
  • Claude Scienceworkbench for researchers launched (June 30).

Google DeepMind / AI

  • Nano Banana 2 Lite— fastest/most cost-efficient image-generation model.
  • Gemini Robotics-ER 1.6integrated into Boston Dynamics' Spot and Orbit inspection platform.

Failed / Limited Sources

  • PortSwigger Research, FreeBuf, 安全客, 先知社区 — HTML/RSS not individually retrieved this run (fetch provenance gate); cross-cutting hot topics (SharePoint KEV, device-code phishing) are widely mirrored in Chinese community feeds.
  • RansomLook — API OK (/api/posts?days=1).

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 4, 2026
Next →
Rosetta Daily · Jul 6, 2026