Rosetta Daily · Jul 12, 2026
Generated automatically · 27 sources scanned · 24 items selected
Critical Vulnerabilities
-
🔴🔥 SharePoint Server RCE (CVE-2026-45659) — Microsoft SharePoint, CVSS 8.8
Deserialization-of-untrusted-data RCE, added to CISA KEV after active exploitation. FCEB remediation was due July 4, 2026.
The Hacker News -
🔴🔥 Adobe ColdFusion Path Traversal (CVE-2026-48282) — Adobe ColdFusion, CVSS 10.0
Path traversal enabling arbitrary code execution; part of CISA's July 7 KEV batch (Adobe/Joomla/Langflow), FCEB fix due July 10.
The Hacker News -
🔴🔥 Joomla SP Page Builder Upload Flaws (CVE-2026-56290 / CVE-2026-48908) — JoomShaper / Joomlack Page Builder, CVSS 10.0
Improper access control + unrestricted dangerous file upload → unauthenticated RCE. Both added to KEV July 7.
The Hacker News -
⚠️🔥 Langflow Authorization Bypass (CVE-2026-55255) — Langflow (AI workflow builder), CVSS 6.1
Authenticated attacker can execute another user's flows; added to KEV July 7 on exploitation evidence.
CISA
In-the-Wild Exploitation (CISA KEV)
- CISA added twomore KEV entries on July 10, 2026(details still propagating; verify against the KEV catalog).
CISA alert - Recent KEV context: PTC Windchill/FlexPLM (CVE-2026-12569) and Cisco Unified CM SSRF (CVE-2026-20230) added late June.
Vendor Advisories
- Cisco (July 1 batch)— Catalyst Center Arbitrary File Read (CVE-2026-20191, CVSS 7.5) and ClamAV flaws affecting multiple Cisco products (High).
Cisco advisory notice - Fortinet / Ivanti (recent)— Critical OS command injection and auth-bypass fixes remain worth verifying in-fleet (e.g., Ivanti CVE-2026-10520 CVSS 10, CVE-2026-10523 CVSS 9.9).
SecurityWeek
Web Security Research
- PortSwigger — Black Hat / DEF CON USA 2026 previews— a "hacking hat-trick" of upcoming publications was teased; watch the Research feed for release. Reference back-catalog: Static Path Deceptionand the Top 10 Web Hacking Techniques of 2025.
PortSwigger Research
AI Security
- Indirect prompt injection still unsolved in agent contexts— Axis Intelligence Q2 2026 testing (312 attacks) reports agent-context attack success rates flat-to-worse across all six frontier models despite better single-turn jailbreak resistance; ~73% of production AI deployments show prompt-injection exposure.
Axis Intelligence - EchoLeak (M365 Copilot)and CVE-2025-53773 (GitHub Copilot RCE, CVSS 9.6)remain the canonical zero-click / hidden-injection references; OpenAI's "Lockdown Mode" (Feb 2026) concedes AI-browser injection "may never be fully patched."
Cycode
Threat Intelligence
- Mandiant M-Trends 2026— median time from initial access to hand-off to a secondary actor collapsed to 22 seconds(from 8+ hours in 2022); "prior compromise" is now the top initial vector in ransomware (30%), while email phishing fell to ~6% of intrusions.
Google Cloud Blog - APT41 (DUSTTRAP)sustained campaign across shipping/logistics, media, tech and automotive (IT, ES, TW, TH, TR, UK); Iranian "Screening Serpens"expanding to US/Israel/UAE targets.
Unit 42
Chinese-Language Community Picks
- FreeBuf — BitUnlocker: a BitLocker downgrade attack— exploits the gap between patch rollout and certificate revocation to physically crack the encrypted volume of a patched Windows 11 device within five minutes; derived from one of four 0-days found by Microsoft's STORM team (CVE-2025-48804).
FreeBuf - Pwn2Own Berlin 2026 registration full— capacity reached for the first time in 19 years, with rejected researchers launching "retaliatory disclosure"; the xchglabs team had prepared 86 vulnerabilities targeting NVIDIA, Docker, Linux KVM and PyTorch.
FreeBuf
Ransomware Today
16 new leak-site posts (07-10 → 07-11) across 7 groups. Qilin dominated with 8 victims (real estate, hotels, construction, BPO, finance; LatAm + APAC); Interlock hit Borger ISD (US K-12). Watchlist hits: 9 (qilin ×8, akira ×1). Off-board: Deutsche Bank breach claimed by "unsafe" (bank denies corporate-network compromise); Accenture confirmed an intrusion after actor "888" claimed 35GB of source code + cloud keys.
Full victim table
Bug Bounty
The Bug Bounty track now updates daily on its own (deep dives + themed recent disclosures).
Open the Bug Bounty daily track
AI Frontier
OpenAI
- GPT-5.6expected imminently (benchmarked for speed/reliability/accuracy); OpenAI also announced a custom "Jalapeño" inference chip. Security-relevant: Lockdown Modefor ChatGPT (Feb 2026).
Anthropic
- Claude Sonnet 5shipped — near-Opus-4.8 quality at intro pricing ($2/$10 per M through Aug 31), with autonomous browser/terminal tool use. (agentic tool use raises injection/abuse surface)
Google DeepMind / AI
- Gemini 3.5 Pro delayed to July 17— full architectural rebuild (2M-token context, "Deep Think" reasoning layer, autonomous workflows). Also NanoBanana 2 Liteimage model (<4s, from $0.034/1k).
🛡 = security-relevant
Failed Sources (if any)
- None hard-failed. Feeds were assembled via WebSearch per category (direct RSS/HTML fetch is provenance-gated in this environment) + RansomLook API for ransomware. Feed-level timestamps are approximate.
- CISA July 10 KEV entry-level CVE detail not yet fully indexed — flagged for verification against the KEV catalog.
Sources used: see intel/sources.yaml