Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-10
Daily Brief·2026-07-10·30 Sources·20 Items

Rosetta Daily · Jul 10, 2026

Generated automatically · 30+ sources scanned · 20 items selected · Window: past ~24h

Critical Vulnerabilities

  • Gitea Docker — Authentication Bypass — Gitea Docker images ≤1.26.2, CVE-2026-20896, CVSS 9.8 🔴⚠️
    Unauthenticated attacker can impersonate any user (incl. admin) by injecting a crafted X-WEBAUTH-USER header when reverse-proxy auth is enabled; default images allowed connections from any source IP. ~6,200 Gitea instances are internet-exposed. Fixed in 1.26.3 (reverse-proxy auth now opt-in) — patch now.
    SecurityWeek · The Hacker News

  • Adobe ColdFusion — Path Traversal → RCE — ColdFusion, CVE-2026-48282, CVSS 10.0 🔴🔥⚠️
    Path traversal enabling arbitrary code execution in the context of the current user. Added to CISA KEV this week; FCEB patch deadline July 10.
    The Hacker News · BleepingComputer

  • Microsoft Defender — "BlueHammer" RCE — Microsoft Defender, CVE-2026-33825 🔴⚠️
    CISA confirmed this (now-patched) Defender flaw was exploited in ransomware attacks. Originally dropped as a 0-day by an anonymous researcher ("Chaotic Eclipse") in April 2026. Separately, Microsoft patched a Defender 0-day dubbed "RoguePlanet" after June Patch Tuesday.
    The Hacker News

In-the-Wild Exploitation (CISA KEV)

  • CISA adds 4 actively-exploited flaws to KEV 🔥⚠️
    CVE-2026-48282 (Adobe ColdFusion path traversal, CVSS 10.0), CVE-2026-56290 (Joomlack Page Builder improper access control, 10.0), CVE-2026-48908 (JoomShaper SP Page Builder dangerous file upload, 10.0), CVE-2026-55255 (Langflow authorization bypass, 6.1). FCEB agencies advised to patch by July 10.
    The Hacker News · CISA KEV

  • Gitea CVE-2026-20896 under active exploitation ⚠️
    Probing began ~13 days after disclosure; initial recon traced to a ProtonVPN exit node. Full compromise of all repos and secrets possible.
    Security Affairs

Vendor Advisories

  • Microsoft — Defender "RoguePlanet" 0-day patched — out-of-band-style fix after June 2026 Patch Tuesday; pair with the BlueHammer KEV entry above.
    The Hacker News

  • Gitea — 1.26.3 security release — reverse-proxy authentication made opt-in; source-IP allowlist now enforced. Docker deployments should upgrade immediately.
    Hive Security

Web Security Research

  • Indirect prompt injection weaponized in real campaigns ⚠️
    Zscaler ThreatLabz documented two live campaigns hiding instructions in content AI agents read: one posed as software docs to run a payment scam, the other impersonated a crypto service — both used SEO poisoning to rank their sites. Prompt injection is now cited as the #1 AI security threat of 2026 (~340% YoY increase).
    Infosecurity Magazine · Zscaler

  • Malicious npm / PyPI packages target fintech users ⚠️
    Packages on npm and PyPI delivered stealer malware to developers and users of Paysafe, Skrill and Neteller payment apps — another open-source supply-chain hit on the fintech ecosystem.
    BleepingComputer

AI Security

  • Prompt-injection payment scams trick AI agents into paying ⚠️
    SecurityWeek details attacks that steer agentic assistants into making crypto payments via injected instructions — concrete financial impact from the "lethal trifecta" (private data + untrusted content + external comms).
    SecurityWeek

  • Misconfigured Ollama server abused as offensive-tool "brain" ⚠️
    Threat actors used an exposed, misconfigured Ollama model server as the reasoning engine for an automated multi-stage VAPT framework — a new evolution of LLMjacking (hijacking others' AI compute for attacks).
    The Hacker News

  • DeepMind "AI Agent Traps" taxonomy — six categories of agent-directed attacks (content injection, semantic manipulation, cognitive-state attacks, tool-misuse induction, goal hijacking, multi-agent collusion). Meta-analysis of 78 studies: attack success >85% against SOTA defenses under adaptive strategies.
    arXiv / research roundup

Threat Intelligence

  • China-aligned actors hit university Roundcube servers ("IceCube" stealer) ⚠️
    Cluster (first seen May 2026) targets admins/professors in national-security-linked and astrophysics/particle-physics departments at U.S. & Canadian universities. Opening a crafted email in a vulnerable Roundcube instance runs a JS loader that delivers IceCube — steals credentials, session tokens, cookies, and fingerprints the browser.
    The Register · BleepingComputer

  • UAT-7810 expands ORB network via unpatched Ruckus routers
    China-linked 'UAT-7810' is evolving malware to grow its Operational Relay Box network by compromising internet-facing networking gear, primarily unpatched Ruckus routers — building anonymizing infrastructure for follow-on ops.
    BleepingComputer

  • Mount Royal University breach
    The Calgary university says attackers stole and then deleted data from its file-storage systems after breaching the network.
    BleepingComputer

中文社区精选 (Chinese Community)

  • AI dual-agent attack → RCE via Claude Desktop
    FreeBuf (Jul 9) describes chaining a compromised email account into a victim's Claude account, planting a malicious prompt in the synced "personal preferences" field to achieve remote code execution across the victim's machines/sessions. (Single source; illustrates agent-config as attack surface — verify independently.)
    FreeBuf· gm7.org mirror

Ransomware Today

RansomLook API unreachable from the sandbox (network restricted); figures below are from public reporting rather than a live pull. Qilin remains the dominant RaaS operation (~16% market share; ~1,496 victims listed over the trailing 12 months) as the ecosystem re-consolidates after LockBit and RansomHub disruption — though The Gentlemen briefly knocked Qilin off the top spot in June 2026 (115 vs 78 victims). Recent watchlist-relevant victims: Akira — Wade's Dairy (2026-07-08), RISE Architecture (2026-07-07).

Full victim table

Bug Bounty

Bug Bounty coverage now updates on its own daily track (deep-dive + themed recent disclosures).
View the Bug Bounty daily section


AI Frontier

OpenAI

  • Custom Jalapeñoinference chip in production; GPT-5.6in limited/government-reviewed preview ahead of a broader July release.

Anthropic

  • Claude Sonnet 5shipping (near-Opus-4.8 performance, intro pricing $2/$10 per M tokens through Aug 31; autonomous browser/terminal use). U.S. government lifted national-security restrictions on Anthropic's Fable 5and Mythos 5models. Note: FreeBuf's "Claude Desktop RCE" claim (above) is an attacker-side abuse of agent config, not a product vuln — verify.

Google DeepMind / AI

  • NanoBanana 2 Liteimage model (<4s, from $0.034/1k images); Interactions APIhit GA. Gemini 3.5 Prodelayed to July 17for a full architectural rebuild (math reasoning, SVG, image quality).

Bonus: Grok 4.5 (SpaceXAI) released July 8, 2026.

🛡 = security-relevant


Failed / Degraded Sources

  • RansomLook API (/api/posts?days=1) — sandbox egress blocked (empty response); Ransomware section built from public reporting.
  • Several items (fintech npm/PyPI packages, UAT-7810, Mount Royal) verified via aggregate/homepage feeds; deep-link to specific article where available.
  • FreeBuf "Claude Desktop RCE" flagged single-source / verify.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 9, 2026
Next →
Rosetta Daily · Jul 12, 2026