Rosetta Daily · Jul 9, 2026
Generated automatically · 30+ sources scanned · 22 items selected · window: past ~24–48h
Critical Vulnerabilities
-
Ubiquiti UniFi Connect — command injection — UniFi Connect ≤3.4.16, CVE-2026-50746, CVSS 10.0 🔴
Unauthenticated, network-adjacent command injection (improper access control). Part of a 25-flaw disclosure across the UniFi ecosystem. Patch Connect ≥3.4.20.
The Hacker News · BleepingComputer -
Ubiquiti UniFi OS — command injection — UniFi OS ≤5.1.15, CVE-2026-54402, CVSS 9.9 🔴
Improper input validation lets a network attacker run commands on UDM/UNVR/UNAS devices. Update UniFi OS ≥5.1.19. Censys tracks 100k+ exposed UniFi OS instances (~50k in the US).
SecurityWeek · cybersecuritynews -
Microsoft SharePoint Server — deserialization RCE — SharePoint SE/2019/2016, CVE-2026-45659, CVSS 8.8 🔴🔥⚠️
Authenticated (Site Member) RCE; now actively exploited (see below). Patched May 2026 — apply if you haven't.
Help Net Security · The Register
In-the-Wild Exploitation (CISA KEV)
-
SharePoint RCE CVE-2026-45659 added to KEV (Jul 1) ⚠️
Exploited for initial access followed by ransomware/tooling (Velociraptor, Cloudflare Tunnels, Zoho Assist, SSH-via-VS Code). FCEB remediation deadline was Jul 4.
The Hacker News · SOCRadar -
Three flaws added to KEV (Jul 7) 🔥
CVE-2026-48908 (JoomShaper SP Page Builder, dangerous-file upload), CVE-2026-55255 (Langflow authorization bypass), CVE-2026-56290 (Joomlack Page Builder improper access control).
CISA -
Adobe ColdFusion — max-severity flaw actively exploited ⚠️
CISA ordered federal agencies to patch a maximum-severity, actively exploited ColdFusion flaw by end of week.
BleepingComputer
Vendor Advisories
-
Ubiquiti — 25 vulnerabilities across UniFi ecosystem
Connect, Talk, Access, Protect, Network Application and UniFi OS all patched; includes the 10.0 and 9.9 command-injection flaws above. Update all components.
Security Boulevard -
Microsoft SharePoint — patch shipped May 2026 for CVE-2026-45659; now KEV-listed, treat as urgent.
The Hacker News
Web Security Research
-
Device code phishing goes commodity ⚠️
Reporting notes 18 kits, a ~37x spike in detections, and every major AiTM vendor adding support — device-code phishing has moved from espionage-grade to criminal commodity. A concurrent M365 device-code campaign used collaboration lures + a backend broker polling Authentication Broker tokens.
BleepingComputer · The Hacker News -
Google Project Zero — mobile chipset research (context)
P0's ongoing Tensor/Pixel driver work (e.g., the /dev/vpu Wave677DV flaw, patched Feb 2026) and a reported zero-click chain against recent Pixel devices underline attacker interest in media/driver attack surface.
cybersecuritynews · Project Zero
AI Security
-
AI-generated browser ransomware abuses Chromium API ⚠️
Researchers flagged a DeepSeek-generated artifact that combines "unrealistic browser-malware concepts with a real browser capability" into working ransomware running entirely inside the browser on Windows, Linux, macOS and Android.
The Hacker News -
First fully-autonomous LLM ransomware (JADEPUFFER) ⚠️
An LLM agent chained CVE-2025-3248 (Langflow unauth RCE) to run arbitrary Python, map systems, and exfiltrate AI/cloud/crypto credentials with no human in the loop.
The Hacker News -
Indirect prompt injection via GitHub repos ⚠️
Mozilla research shows crafted repositories can attack AI coding tools (e.g., Claude Code) through indirect prompt injection — a reminder to sandbox agent tool use.
FreeBuf (single-source, verify)
Threat Intelligence
-
Accenture confirms breach after 35 GB source-code theft claim
Actor "888" advertised source code, RSA/SSH keys and Azure tokens from a private Azure DevOps repo. Accenture calls it an "isolated matter," says the source is remediated with no operational impact; scope unverified.
Help Net Security · BleepingComputer -
KDDI breach exposes up to 14.2M ISP email logins
~12.23M email addresses and ~7.61M passwords (some plaintext) across six ISPs (JCOM, Nifty, BIGLOBE, STNet, Chubu Telecom, KDDI Web Comms). Attackers used a third-party zero-day; reset passwords + enable 2FA.
The Japan Times · BleepingComputer -
DHS confirms breach of HSIN info-sharing platform
Homeland Security confirmed intruders accessed its Homeland Security Information Network.
BleepingComputer -
Brand-impersonation phishing hits marketers
A campaign impersonating 30+ brands (Adobe, Netflix, Coca-Cola, OpenAI) via fake job interviews harvests Google credentials from marketing professionals. New Android bank-fraud MaaS "RedWing" is also renting on Telegram.
BleepingComputer · The Hacker News
Chinese-Language Community Picks
- nginx heap overflow (CVE-2026-42945)— mentioned in the FreeBuf weekly; reported to be broadly impactful, upgrade to a patched version. (Via a secondary aggregator; pending direct verification.)
- Command injection across open-source AI agents— reporting claims that 10 of 11 popular open-source AI agents carry command injection, letting an attacker bypass protections to execute commands. (Single source; pending verification.)
FreeBuf
Ransomware Today
RansomLook API was unreachable this run (sandbox network blocked); figures below are from open reporting, not the live feed. Qilin remains the most prolific operation of 2026 (~1,871 tracked victims), ahead of Akira (~1,357) and RansomHub (~842); fresh Qilin/Akira victims were posted around Jul 7. Watchlist-relevant: continued healthcare/critical-infra targeting by Qilin.
Bug Bounty
The Bug Bounty deep-dive is now a standalone daily (themed recent disclosures + one deep analysis).
Open the Bug Bounty daily
AI Frontier
OpenAI
- Announced a custom Jalapeñoinference chip; previewed GPT-5.6(Sol / Terra / Luna) to government-vetted orgs ahead of a broader July release.
Anthropic
- Launched Sonnet 5with near-Opus-4.8 performance at intro pricing ($2/$10 per-M through Aug 31); can autonomously drive browsers/terminals. A DoS 0-day (CVE-2026-55407) was also reported in a Rust protobuf library — single-source, verify.
Google DeepMind / AI
- NanoBanana 2 Liteimage model (sub-4s, from $0.034/1k images); Gemini 3.5 Prodelayed to Jul 17 for an architectural rebuild (math reasoning, SVG, image quality).
Failed / Degraded Sources
- RansomLook API (
/api/posts?days=1) — sandbox egress blocked (curl exit 56); ransomware section built from web reporting instead. - Several Chinese-community items surfaced only via secondary aggregators; flagged inline as single-source pending direct confirmation.
Sources used: see intel/sources.yaml