Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-09
Daily Brief·2026-07-09·30 Sources·22 Items

Rosetta Daily · Jul 9, 2026

Generated automatically · 30+ sources scanned · 22 items selected · window: past ~24–48h

Critical Vulnerabilities

  • Ubiquiti UniFi Connect — command injection — UniFi Connect ≤3.4.16, CVE-2026-50746, CVSS 10.0 🔴
    Unauthenticated, network-adjacent command injection (improper access control). Part of a 25-flaw disclosure across the UniFi ecosystem. Patch Connect ≥3.4.20.
    The Hacker News · BleepingComputer

  • Ubiquiti UniFi OS — command injection — UniFi OS ≤5.1.15, CVE-2026-54402, CVSS 9.9 🔴
    Improper input validation lets a network attacker run commands on UDM/UNVR/UNAS devices. Update UniFi OS ≥5.1.19. Censys tracks 100k+ exposed UniFi OS instances (~50k in the US).
    SecurityWeek · cybersecuritynews

  • Microsoft SharePoint Server — deserialization RCE — SharePoint SE/2019/2016, CVE-2026-45659, CVSS 8.8 🔴🔥⚠️
    Authenticated (Site Member) RCE; now actively exploited (see below). Patched May 2026 — apply if you haven't.
    Help Net Security · The Register

In-the-Wild Exploitation (CISA KEV)

  • SharePoint RCE CVE-2026-45659 added to KEV (Jul 1) ⚠️
    Exploited for initial access followed by ransomware/tooling (Velociraptor, Cloudflare Tunnels, Zoho Assist, SSH-via-VS Code). FCEB remediation deadline was Jul 4.
    The Hacker News · SOCRadar

  • Three flaws added to KEV (Jul 7) 🔥
    CVE-2026-48908 (JoomShaper SP Page Builder, dangerous-file upload), CVE-2026-55255 (Langflow authorization bypass), CVE-2026-56290 (Joomlack Page Builder improper access control).
    CISA

  • Adobe ColdFusion — max-severity flaw actively exploited ⚠️
    CISA ordered federal agencies to patch a maximum-severity, actively exploited ColdFusion flaw by end of week.
    BleepingComputer

Vendor Advisories

  • Ubiquiti — 25 vulnerabilities across UniFi ecosystem
    Connect, Talk, Access, Protect, Network Application and UniFi OS all patched; includes the 10.0 and 9.9 command-injection flaws above. Update all components.
    Security Boulevard

  • Microsoft SharePoint — patch shipped May 2026 for CVE-2026-45659; now KEV-listed, treat as urgent.
    The Hacker News

Web Security Research

  • Device code phishing goes commodity ⚠️
    Reporting notes 18 kits, a ~37x spike in detections, and every major AiTM vendor adding support — device-code phishing has moved from espionage-grade to criminal commodity. A concurrent M365 device-code campaign used collaboration lures + a backend broker polling Authentication Broker tokens.
    BleepingComputer · The Hacker News

  • Google Project Zero — mobile chipset research (context)
    P0's ongoing Tensor/Pixel driver work (e.g., the /dev/vpu Wave677DV flaw, patched Feb 2026) and a reported zero-click chain against recent Pixel devices underline attacker interest in media/driver attack surface.
    cybersecuritynews · Project Zero

AI Security

  • AI-generated browser ransomware abuses Chromium API ⚠️
    Researchers flagged a DeepSeek-generated artifact that combines "unrealistic browser-malware concepts with a real browser capability" into working ransomware running entirely inside the browser on Windows, Linux, macOS and Android.
    The Hacker News

  • First fully-autonomous LLM ransomware (JADEPUFFER) ⚠️
    An LLM agent chained CVE-2025-3248 (Langflow unauth RCE) to run arbitrary Python, map systems, and exfiltrate AI/cloud/crypto credentials with no human in the loop.
    The Hacker News

  • Indirect prompt injection via GitHub repos ⚠️
    Mozilla research shows crafted repositories can attack AI coding tools (e.g., Claude Code) through indirect prompt injection — a reminder to sandbox agent tool use.
    FreeBuf (single-source, verify)

Threat Intelligence

  • Accenture confirms breach after 35 GB source-code theft claim
    Actor "888" advertised source code, RSA/SSH keys and Azure tokens from a private Azure DevOps repo. Accenture calls it an "isolated matter," says the source is remediated with no operational impact; scope unverified.
    Help Net Security · BleepingComputer

  • KDDI breach exposes up to 14.2M ISP email logins
    ~12.23M email addresses and ~7.61M passwords (some plaintext) across six ISPs (JCOM, Nifty, BIGLOBE, STNet, Chubu Telecom, KDDI Web Comms). Attackers used a third-party zero-day; reset passwords + enable 2FA.
    The Japan Times · BleepingComputer

  • DHS confirms breach of HSIN info-sharing platform
    Homeland Security confirmed intruders accessed its Homeland Security Information Network.
    BleepingComputer

  • Brand-impersonation phishing hits marketers
    A campaign impersonating 30+ brands (Adobe, Netflix, Coca-Cola, OpenAI) via fake job interviews harvests Google credentials from marketing professionals. New Android bank-fraud MaaS "RedWing" is also renting on Telegram.
    BleepingComputer · The Hacker News


Chinese-Language Community Picks

  • nginx heap overflow (CVE-2026-42945)— mentioned in the FreeBuf weekly; reported to be broadly impactful, upgrade to a patched version. (Via a secondary aggregator; pending direct verification.)
  • Command injection across open-source AI agents— reporting claims that 10 of 11 popular open-source AI agents carry command injection, letting an attacker bypass protections to execute commands. (Single source; pending verification.)
    FreeBuf

Ransomware Today

RansomLook API was unreachable this run (sandbox network blocked); figures below are from open reporting, not the live feed. Qilin remains the most prolific operation of 2026 (~1,871 tracked victims), ahead of Akira (~1,357) and RansomHub (~842); fresh Qilin/Akira victims were posted around Jul 7. Watchlist-relevant: continued healthcare/critical-infra targeting by Qilin.

Full victim table

Bug Bounty

The Bug Bounty deep-dive is now a standalone daily (themed recent disclosures + one deep analysis).
Open the Bug Bounty daily


AI Frontier

OpenAI

  • Announced a custom Jalapeñoinference chip; previewed GPT-5.6(Sol / Terra / Luna) to government-vetted orgs ahead of a broader July release.

Anthropic

  • Launched Sonnet 5with near-Opus-4.8 performance at intro pricing ($2/$10 per-M through Aug 31); can autonomously drive browsers/terminals. A DoS 0-day (CVE-2026-55407) was also reported in a Rust protobuf library — single-source, verify.

Google DeepMind / AI

  • NanoBanana 2 Liteimage model (sub-4s, from $0.034/1k images); Gemini 3.5 Prodelayed to Jul 17 for an architectural rebuild (math reasoning, SVG, image quality).

Failed / Degraded Sources

  • RansomLook API (/api/posts?days=1) — sandbox egress blocked (curl exit 56); ransomware section built from web reporting instead.
  • Several Chinese-community items surfaced only via secondary aggregators; flagged inline as single-source pending direct confirmation.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 8, 2026
Next →
Rosetta Daily · Jul 10, 2026