Rosetta Daily · Jul 8, 2026
Generated automatically · ~20 sources scanned · 16 items selected
Critical Vulnerabilities
- Adobe ColdFusion path traversal → arbitrary code execution— Adobe ColdFusion, CVE-2026-48282, CVSS 10.0
Path traversal leading to arbitrary code execution; attackers began exploiting it within two hoursof public disclosure. Patched June 30 alongside five other max-severity ColdFusion flaws. Patch now — exposure window is effectively zero.
SecurityWeek - Citrix NetScaler "CitrixBleed" echo— NetScaler ADC / Gateway, CVE-2026-8451, CVSS 8.8
Pre-auth SAML memory overread: NetScaler's XML parser reads past its buffer and returns memory contents (session tokens, cleartext creds, TLS private keys) in theNSC_TASScookie. In-the-wild exploitation seen <24h after disclosure; CrowdSec flagged 71 malicious IPs / 424 signals in four days. Fixed in 14.1-72.61 / 13.1-63.18 (CTX696604).
CyberScoop· watchTowr - SimpleHelp RMM auth bypass— SimpleHelp, CVE-2026-48558, CVSS 10.0
Catastrophic authentication bypass in remote-support software with MSP supply-chain blast radius (carryover — still unpatched in many fleets).
Innovate Cybersecurity
In-the-Wild Exploitation (CISA KEV)
- Microsoft SharePoint Server RCE— CVE-2026-45659, CVSS 8.8
Deserialization RCE; a low-privileged authenticated user ("Site Member") can execute code. On CISA KEV since July 1 (FCEB deadline July 4). Attacks now attributed to Storm-2603, which drops Warlock ransomware via on-prem SharePoint flaws.
The Hacker News· CISA KEV - Microsoft Exchange Server zero-day— CVE-2026-42897
XSS/spoofing zero-day in Exchange Server exploited in the wild; Microsoft racing a patch. Restrict OWA exposure and monitor.
SecurityWeek - D-Link EoL DSL gateway zero-day— CVE-2026-0625
Command injection in thednscfg.cgiDNS endpoint of discontinued D-Link DSL gateways; actively exploited for arbitrary shell command execution. No fix (end-of-life) — replace the hardware.
Dark Reading
Vendor Advisories
- Citrix — six NetScaler flawspatched (file read + DoS), headlined by CVE-2026-8451 above. Review CTX696604 and rotate all secrets that may have been in appliance memory.
The Hacker News - Microsoft July Patch Tuesdaylands July 14, 2026 — plus the non-negotiable Kerberos RC4 hardening enforcement deadline the same day (affects every domain-joined system).
Innovate Cybersecurity
Web Security Research
- PortSwigger — Black Hat / DEF CON USA preview— James Kettle teases a "hacking hat-trick" of three research publications due at Black Hat / DEF CON USA, and reflects on how LLMs and agents will reshape the Top 10 Web Hacking Techniques. No standalone new technique dropped this window.
PortSwigger Research
AI Security
- JADEPUFFER — first end-to-end agentic ransomware— Sysdig's Threat Research Team documents what it assesses as the first fully LLM-driven extortion operation. The agent exploited Langflow RCE (CVE-2025-3248) to harvest cloud/LLM credentials, pivoted via a 2021 auth bypass to a production MySQL/Alibaba Nacos server, and encrypted 1,342 config items — leaving a ransom note whose key was never saved, making recovery impossible even after payment. Decoded payloads are annotated with natural-language ROI reasoning; the fail-to-fix window was 31 seconds. The skill floor for ransomware just dropped to "cost of running an agent."
Sysdig· The Register - Prompt injection remains OWASP #1 and architecturally unsolved— OWASP researchers reiterate there's no reliable way to enforce privilege boundaries between system prompts, user input, and agent-retrieved content since LLMs process one token stream. A 2026 survey found 88% of orgs reported confirmed/suspected AI-agent security incidents in the past year.
Infosecurity Magazine· Help Net Security
Threat Intelligence
- Unit 42 — 2026 Global Incident Response Report— attacks are 4× faster (data exfiltration in <1h in some cases), 65% of initial access is identity-based, and 87% span multiple attack surfaces, defeating single-signal correlation.
RH-ISAC / Unit 42 - DHS confirms breach of Homeland Security Information Network— U.S. DHS confirmed a compromise of HSIN, the platform used to share sensitive-but-unclassified info with state/local partners. Scope under investigation.
Innovate Cybersecurity - Iranian APT "Screening Serpens"— Unit 42 tracks AppDomainManager hijacking and new RAT variants against aerospace, defense-manufacturing and telecom targets, expanding into Western Europe.
Unit 42
Chinese-Language Community Picks
The following comes from the FreeBuf weekly aggregation; some items are not independently verified — cross-check before relying on them.
- nginx heap overflow dormant for 18 years— CVE-2026-42945; when a configuration uses both
rewriteandsetdirectives, inconsistent dual-engine state causes a buffer overflow. Reported to be broadly impactful; upgrade to 1.31.0+. (The scale figures look inflated — treat the vendor advisory as authoritative.)
FreeBuf weekly - Cursor IDE critical RCE "DuneSlide"— CVSS 9.8, breaking out of sandbox protections via prompt injection. The attack surface of AI coding tools keeps widening.
FreeBuf weekly - 10 of 11 open-source AI agents carry command injection— protections can be bypassed to execute dangerous commands, confirming the "agentic attack surface" trend noted above.
FreeBuf weekly
Ransomware Today
~10 new disclosures across ≥7 groups; 4 hit the watchlist. TheGentlemen (fastest-scaling group on record) added insurer Arabia Falcon; Wallstreet posted medical-assistance firm Asisken; BlackField claimed manufacturer Nidec; and Ford surfaced on a leak forum via Krybit. Japanese firms (Nidec, Aflac, Sapporo, KDDI) cluster this window. Note: RansomLook feeds unreachable from sandbox — figures are aggregated, not independently verified.
Full victim table
Bug Bounty
Bug Bounty coverage is now a standalone daily (deep dive + themed recent disclosures).
Open the Bug Bounty daily
AI Frontier
OpenAI
- GPT-5.6 previewed(June 26) as a three-tier family — Sol(flagship), Terra(mid), Luna(fast/cheap) — still limited to ~20 government-vetted partners, broad access expected mid-to-late July. OpenAI plans to run Sol on Cerebras wafer-scale hardware at up to 750 tok/s (~15× current GPU inference).
llm-stats
Anthropic
- Claude Enterprise admin controls(July 3) — richer analytics, model-level entitlements, and spend alerts. Follows the July 1 global restoration of Claude Fable 5 (with a >99% blocking safety classifier) after Commerce lifted export controls.
AI Tools Recap
Google DeepMind / AI
- Gemini 3.5 Proslipped from June to July after enterprise testers flagged reasoning/coding regressions; the cheaper Gemini 3.5 Flashshipped on time and beats the prior generation.
llm-stats
Failed Sources (if any)
- RansomLook
api/posts?days=1and RSS — unreachable from sandbox (Tunnel 403 Forbidden). Ransomware section built from WebSearch aggregation instead; treat victim claims as unverified. - Most vendor RSS/Atom feeds accessed via WebSearch aggregation rather than direct fetch (provenance/sandbox constraints).
Sources used: see intel/sources.yaml