Rosetta Daily · Jul 13, 2026
Generated automatically · 27 sources scanned · 23 items selected
Critical Vulnerabilities
-
⚠️ Zimbra Classic Web Client — critical stored XSS — Zimbra ZCS, no CVE assigned yet
A crafted email runs malicious script in the victim's session when opened, exposing mailbox contents, session data and account settings. Reported by Google's Threat Analysis Group (often state-actor-linked). Patch: upgrade to ZCS 10.1.19 now.
The Hacker News · BleepingComputer -
🔴 Oracle E-Business Suite / Payments — unauthenticated RCE (CVE-2026-46817) — Oracle Payments, CVSS 9.8
Unauthenticated attacker with HTTP network access can fully compromise Oracle Payments. Patch immediately; internet-exposed EBS instances are prime targets.
Threat-Modeling.com -
🔴⚠️ Fortinet FortiSandbox — CVE-2026-25089 / CVE-2026-26083 — FortiSandbox, CVSS 9.8
OS command injection (25089, patched June 9) and missing authorization (26083); both let an unauthenticated attacker run arbitrary commands via crafted HTTP. Reported under active exploitation — verify FortiSandbox assets.
Senserva KEV tracker
In-the-Wild Exploitation (CISA KEV)
- SharePoint Server RCE (CVE-2026-45659, CVSS 8.8)and Adobe ColdFusion path traversal (CVE-2026-48282, CVSS 10.0)remain the top fix-first KEV entries from early July; FCEB deadlines have passed. Confirm patching if not already done.
CISA KEV Catalog - Also on KEV from 07-07: Joomla SP/Page Builder upload (CVE-2026-48908 / CVE-2026-56290) and Langflow authorization bypass (CVE-2026-55255).
CISA 07-07 alert
Vendor Advisories
- Microsoft Patch Tuesday — July 14 (tomorrow)— Forecast ~100–140 CVEs (down from June's record 200). Watch RoguePlanet (CVE-2026-50656), a race-condition privilege escalation with public PoC yielding a SYSTEM shell.
Help Net Security - Kerberos RC4 hardening — full enforcement July 14— Phase 2 completes; RC4 in Kerberos auth is disabled by default. Legacy apps still requesting RC4 will break — inventory before the cutover.
Help Net Security
Web Security Research
- PortSwigger Top 10 Web Hacking Techniques of 2025— #1 is Successful Errors: New Code Injection & SSTI Techniques(error-based blind SSTI + polyglot detection); ORM Leakinggeneralizes ORM leaks into a reusable search/filter exploitation methodology. Side-channels emerged as a core exploitation primitive in 2025.
PortSwigger Research
AI Security
- AI browsers tricked into stealing their own users' credentials— Research (late June–early July) showed six widely used AI browsers could be manipulated into exfiltrating user credentials. Indirect prompt injection remains the #1 agentic-AI failure mode.
Innovaiden - Zscaler ThreatLabz — indirect prompt injection targeting AI agents— New research on injection payloads planted in websites, documents and email that hijack embedded AI agents through unmonitored data channels.
Zscaler ThreatLabz
Threat Intelligence
- China- & India-aligned espionage vs. Pakistani law enforcement— Sustained campaign against several Pakistani law-enforcement bodies from Feb 2024 to Apr 2026, attributed to suspected China- and India-aligned actors.
The Hacker News - PolinRider (North Korea-aligned) supply-chain campaign— 108 malicious packages plus a Chrome extension across open-source registries; uses VS Code auto-run tasks and hidden JS loaders to deploy DEV#POPPER and OmniStealer.
The Hacker News - Injective Labs SDK GitHub compromise (07-08)— Attackers published a malicious package stealing crypto wallet private keys and seed phrases.
The Hacker News
Threat Intelligence — Supply Chain Spotlight
- jscrambler npm compromise (07-11)— The official jscrambler CLI (~60K monthly downloads) was trojanized across fivereleases (8.14.0, 8.16.0–8.18.0, 8.20.0). Early versions use a
preinstallhook dropping a Rust infostealer; 8.18.0/8.20.0 pivot torequire()-time injection, bypassing--ignore-scripts. Payload steals wallets, cloud creds, browser profiles, keyrings and installs persistence. Socket flagged it 6 minutes after publish.
Socket· The Hacker News
Chinese-Language Community Picks
- OdysseyStealer hits macOS again, reaching 100+ countries— spread through deceptive software and update prompts, using social-engineering lures to get users to run malicious commands.
FreeBuf - FreeBuf weekly— June's must-patch vulnerability list, the first fully automated AI ransomware attack, and a major APT warning.
Infosec Knowledge Base
Ransomware Today
RansomLook (window 07-10 → 07-11, API lagging one day): 16 new leak-site posts across 7 groups. Qilin dumped 8 victims in a day (real estate, hotels, construction, BPO, finance; LATAM + APAC). Interlock hit Borger ISD (US K-12 district). Watchlist hits: 9 (qilin ×8, akira ×1 — Vandalia Rental).
Full victim table
Bug Bounty
The Bug Bounty track updates daily on its own (deep-dive + themed recent disclosures).
Open the Bug Bounty daily track
AI Frontier
OpenAI
- Preparing to file confidentially for an IPO(potentially as soon as Sept 2026; ~$730B private valuation). Custom "Jalapeño" inference chipannounced; GPT-5.6 expected shortly. ChatGPT Lockdown Mode remains the injection-mitigation reference.
Anthropic
- Claude Sciencelaunched — part of a stated goal to 10x life-sciences R&D, building on the Coefficient Bio acquisition and the hire of AlphaFold lead John Jumper. Claude Sonnet 5 (near-Opus 4.8, intro pricing through 8/31) continues to expand agentic tool use.
Google DeepMind / AI
- Gemini 3.5 Pro delayed to July 17— full architectural rebuild targeting math reasoning, SVG generation and image quality. NanoBanana 2 Liteimage model ships (<4s, from $0.034/1K images).
🛡 = security-relevant
Failed Sources (if any)
- RansomLook API returns a one-day-lagged window (07-10 → 07-11); reported as-is.
- Sandbox has no outbound network — all fetches done via WebSearch / web_fetch.
Sources used: see intel/sources.yaml