Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-06
Daily Brief·2026-07-06·14 Items

Rosetta Daily · Jul 6, 2026

Generated automatically · ~28 sources scanned · 14 items selected · Window: past 24–48h (weekend, lighter news volume)

Critical Vulnerabilities

  • SharePoint Server RCE — Microsoft SharePoint (Subscription Edition / 2019 / 2016), CVE-2026-45659, CVSS 8.8 🔴🔥⚠️
    Deserialization of untrusted data; an authenticated user with only Site Member permissions can achieve remote code execution. Patched out-of-band in late May but disclosed late; now actively exploited. In-the-wild post-exploitation has used Velociraptor, Cloudflare Tunnels, Zoho Assist and SSH-over-VS-Code for persistence and lateral movement.
    The Hacker News · SecurityOnline

  • Cisco Catalyst SD-WAN Controller/Manager auth bypass — CVE-2026-20182, CVSS 10.0 🔴🔥⚠️
    Flawed peering authentication lets a remote unauthenticated attacker become an authenticated peer, inject an SSH key into vmanage-admin, then issue arbitrary NETCONF commands over port 830. Tied to threat group UAT-8616 (active since 2023); the sixth SD-WAN zero-day patched in 2026. CISA mandated remediation under Emergency Directive 26-03.
    Help Net Security · Cisco advisory

In-the-Wild Exploitation (CISA KEV)

  • CVE-2026-45659 (SharePoint) remains the only July KEV addition; federal remediation deadline was 2026-07-04 (now passed — unpatched FCEB systems are out of compliance). Watch for opportunistic scanning against internet-facing SharePoint.
    CISA alert (7/1)

  • BlueHammer — Microsoft Defender EoP (CVE-2026-33825) 🔥 — CISA confirmed ransomware gangs are now exploiting this high-severity privilege-escalation flaw, which was leaked in April along with PoC code.
    BleepingComputer

Vendor Advisories

  • Microsoft — next Patch Tuesday is 2026-07-14. Context: the June 2026 cycle set a record at 206 CVEs (incl. three zero-days), so expect a large July rollup.
    The Hacker News

  • Google Chrome — Google has now patched its 5th Chrome zero-day of 2026; keep desktop channels current given the run of in-the-wild browser bugs this year.
    SecurityWeek

Web Security Research

  • Email account takeover via CSS + HTML — PortSwigger researchers demonstrate novel end-to-end account takeovers against multiple major email providers using only CSS/HTML primitives. A strong reminder that "static" rendering surfaces remain exploitable.
    PortSwigger Research

  • LLM-assisted blackbox research — James Kettle (PortSwigger) is previewing work on using LLMs to perform novel blackbox security research ahead of Black Hat USA — a signal of where offensive web tooling is heading in H2 2026.
    PortSwigger talks

AI Security

  • Prompt injection stays OWASP LLM #1 ⚠️ — No complete fix exists; even frontier models from OpenAI, Google and Anthropic remain bypassable after best-effort defenses. Production exploitation is documented via critical CVEs in Microsoft Copilot (CVSS 9.3), GitHub Copilot (CVSS 9.6) and Cursor IDE (CVSS 9.8). New OWASP 2025 entries: System Prompt Leakage (LLM07) and Vector/Embedding Weaknesses (LLM08).
    GetAstra guide · Vectra

  • Third-party chatbot plugins as an injection surface 🛡 — An IEEE S&P 2026 paper ("When AI Meets the Web") maps prompt-injection risk introduced by third-party AI chatbot plugins, quantifying cross-model transferability of attacks.
    arXiv 2511.05797

Threat Intelligence

  • Check Point VPN zero-day → Qilin (CVE-2026-50751) — Auth-bypass on Check Point Remote Access / Mobile Access VPN, exploited since early May and linked to Qilin ransomware affiliates; CISA gave feds a 3-day patch window. Only "a few dozen" orgs hit so far — a targeted, not mass, campaign.
    BleepingComputer

  • Ransomware sector reconsolidating — Q1 2026 saw Qilin (338 victims), LockBit 5.0 (163), Akira and "The Gentlemen" together claim ~41% of all victims, capitalizing on rivals' instability. July disclosure volume so far is consistent with this concentration.
    Check Point Research

Chinese-Language Community Picks

  • Community highlights this cycle track the international picture: SharePoint CVE-2026-45659 (KEV deadline already passed)and ransomware crews exploiting the BlueHammer / Check Point VPN zero-daywere the most frequently reposted topics across Chinese security accounts; worth watching FreeBuf / Anquanke for localised analysis of the SharePoint deserialization exploit chain and Qilin TTPs.
  • (FreeBuf / Anquanke / Xianzhi Community were not fetched item-by-item this run — see "restricted sources" at the end.)

Ransomware Today

Several groups were active over the past ~48 hours per open-source disclosure: Qilin (e.g. Chemco), INC_RANSOM (Carvalima Transportes, the City of Acworth, Georgia), ANUBIS (Ferrum Group, Quest Healthcare Solutions), Bashe (Flazio), and Krybit (listing Ford on a leak forum). Watchlist hits include Qilin, plus the healthcare / logistics / government sector tags. ⚠️ The RansomLook API returned 403 today, so this section falls back to open-source disclosure; treat the next day's ransomlook.io re-check as authoritative.
Full victim table

Bug Bounty

The Bug Bounty feature now updates daily on its own (deep dives plus recent disclosures grouped by theme).
View the Bug Bounty daily feature


AI Frontier (security-relevant highlights)

  • Anthropic Claude Sonnet 5(Jul 1) — most agentic model yet; can autonomously drive browsers/terminals. Agentic capability expands both defensive tooling and the prompt-injection attack surface.
  • OpenAI "Jalapeño" inference chip(Jul 1) — custom silicon; supply-chain and hardware-attestation implications for AI infra.

Failed / Rate-limited Sources

  • RansomLook API— /api/posts?days=1returned HTTP 403 from the sandbox egress today (tunnel forbidden). Ransomware section below is built from open-source disclosure reporting (Ransomware.live / Breachsense mirrors) instead; re-verify against ransomlook.io when network access is restored.
  • PortSwigger / FreeBuf / 安全客 / 先知社区 — not fetched item-by-item (fetch provenance limits); cross-source hot topics mirrored via WebSearch.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 5, 2026
Next →
Rosetta Daily · Jul 7, 2026