Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-07
Daily Brief·2026-07-07·15 Items

Rosetta Daily · Jul 7, 2026

Generated automatically · ~20 sources scanned · 15 items selected

Critical Vulnerabilities

  • Ivanti Sentry OS command injection— Ivanti Sentry, CVE-2026-10520, CVSS 10.0
    Remote, unauthenticated OS command injection allowing arbitrary code execution as root. Paired with CVE-2026-10523 (CVSS 9.9), an auth bypass letting attackers self-create admin accounts. Patch immediately.
    SecurityWeek
  • FortiSandbox OS command injection— Fortinet, CVE-2026-25089, CVSS 9.8
    Command injection in the FortiSandbox / FortiSandbox Cloud / PaaS web UI. Fixed in FortiSandbox 5.0.6 & 4.4.9.
    SecurityWeek
  • SimpleHelp RMM— SimpleHelp, CVE-2026-48558, CVSS 10.0
    Maximum-severity flaw in SimpleHelp with MSP supply-chain blast radius; a compromise can cascade to downstream managed customers.
    The Hacker News
  • n8n workflow platform RCE— n8n, critical
    Critical RCE enabling full takeover of the n8n AI-workflow automation platform.
    CSO Online

In-the-Wild Exploitation (CISA KEV)

  • Microsoft SharePoint Server RCE— CVE-2026-45659, CVSS 8.8
    Deserialization-of-untrusted-data RCE; any authenticated user with minimal "Site Member" permissions can execute code. Patched by MS in May 2026; added to CISA KEV after confirmed exploitation, FCEB remediation deadline July 4, 2026.
    The Hacker News· CISA KEV
  • Google Chrome zero-day— CVE-2026-11645
    Chrome's latest update resolved 74 CVEs including an actively exploited zero-day. Update to the latest stable channel.
    SecurityWeek

Vendor Advisories

  • JetBrains IDE ecosystem— critical patches across IntelliJ, PyCharm, WebStorm, GoLand, etc., addressing authentication bypass, account takeover, and RCE.
    Threat-Modeling.com
  • Cisco advance notification— Cisco PSIRT July 1, 2026 batch covering Catalyst Center and Secure Endpoint Connectors for Linux/Mac/Windows.
    Cisco
  • Microsoft July Patch Tuesday preview— lands July 14, 2026 (est. 100–140 CVEs). Note the non-negotiable Kerberos RC4 hardening enforcement deadline the same day, impacting all domain-joined systems.
    Zecurit

Web Security Research

  • PortSwigger — email account takeover via CSS/HTML— new techniques for compromising email accounts using CSS and HTML, with demonstrated end-to-end ATOs on multiple major email providers; plus new HTTP desync triggers/gadgets.
    PortSwigger Research

AI Security

  • Cross-model "prompt laundering"— vulnerability (filed ~July 3, 2026) showing that when one model's output feeds another, safety refusals from the first model do not transfer to the second.
    Axis Intelligence
  • Agent tool-input injection remains unsolved— Axis Intelligence reproduced 47 confirmed attack vectors across 6 production LLMs (Jan–Jul 2026); agent tool-input injection succeeds 84% of the time. OWASP reports prompt injection up 340% YoY.
    Axis Intelligence· ECCU

Threat Intelligence

  • Armored Likho "BusySnake" campaign— spear-phishing against government and electric-power operators in Russia, Kazakhstan, and Brazil, exploiting patched LNK flaw CVE-2025-9491. Kaspersky found the first-stage loader was LLM-generated — an AI-assisted malware milestone.
    TechTimes
  • Iranian APT "Screening Serpens"— deployed six new RAT variants (incl. MiniUpdate, MiniJunk V2) Feb–Apr 2026 against US/Israel/UAE targets via spear-phishing and DLL sideloading.
    Unit 42
  • APT29 GRAPELOADER & Scattered Spider resilience— APT29 pushing a new stealth loader with identity-centric credential theft; Scattered Spider sustaining elevated tempo via decentralized cells despite arrests.
    Netlas

Chinese-Language Community Picks

  • FreeBuf vulnerability / threat sections— recent highlights include the downgrade attack on BitLocker (BitUnlocker), tools abusing the Windows file interface, and supply-chain poisoning aimed at the AI development community; useful as localised supplementary reading.
    FreeBuf vulnerabilities

Ransomware Today

9 new posts from 4 groups (qilin, play, the gentlemen, titan); 7 hit the watchlist. qilin dominated with a batch of 5 victims (financial / non-profit / manufacturing), play hit an insurance firm, and the gentlemen posted a healthcare/EMS victim (Medic Rescue). Feed timestamps cluster on Jul 3–4.
Full victim table

Bug Bounty

Bug Bounty coverage is now a standalone daily (deep dive + themed recent disclosures).
Open the Bug Bounty daily


AI Frontier

OpenAI

  • No major confirmed release captured this window. See the standalone AI Frontier daily.

Anthropic

  • Claude Fable 5 restored globally (July 1) after US lifted export controls; ships jailbreak-severity framework, >99% blocking classifier, and a HackerOne cyber-jailbreak program. Claude Sonnet 5 also live with lower undesirable-behavior rates.
    The Hacker News

Google DeepMind / AI

  • NanoBanana 2 Lite (image gen <4s) and OmniFlash (any-to-any video) launched; Interactions API GA.
    ThursdAI

Failed Sources (if any)

  • None hard-failed. Note: RansomLook days=1returned only Jul 3–4 entries (feed lag); most vendor RSS/Atom feeds accessed via WebSearch aggregation rather than direct fetch (provenance/sandbox constraints).

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 6, 2026
Next →
Rosetta Daily · Jul 8, 2026