Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-14
Daily Brief·2026-07-14·27 Sources·22 Items

Rosetta Daily · Jul 14, 2026

Generated automatically · 27 sources scanned · 22 items selected

Critical Vulnerabilities

  • 🔴🔥 iCagenda & Balbooa Forms Joomla flaws exploited as zero-days — Joomla extensions, CVE-2026-48939 / CVE-2026-56291, CVSS 10.0
    Both are unrestricted file-upload flaws (arbitrary file upload → RCE) reportedly exploited in the wild before patch. Added to CISA KEV on 07-10; FCEB remediation deadline was 07-13. Audit any Joomla site running iCagenda or Balbooa Forms now.
    The Hacker News · CISA 07-10

  • ⚠️ RoguePlanet — Windows privilege escalation (CVE-2026-50656) — Microsoft Windows
    Race-condition LPE with public PoC on GitHub that can yield a SYSTEM shell. Disclosed amid the ongoing Nightmare-Eclipse ↔ Microsoft dispute; addressed in today's Patch Tuesday. Prioritize this one across the July rollout.
    Help Net Security

In-the-Wild Exploitation (CISA KEV)

  • Still top-priority from early July: SharePoint Server RCE (CVE-2026-45659)and Adobe ColdFusion path traversal (CVE-2026-48282, CVSS 10.0)— both KEV, both past their FCEB due dates. Confirm remediation if not already done.
    The Hacker News· CISA KEV

Vendor Advisories

  • Microsoft July Patch Tuesday — today (07-14)— ~116 CVEs for Windows 11 / 104 for Windows 10, plus Office, SharePoint Server, Visual Studio and .NET fixes. No out-of-band updates; a smaller release than June's record 206. No newly actively-exploitedzero-day this month, but RoguePlanet (public PoC) is the standout.
    Zecurit Patch Tuesday· News4Hackers
  • Kerberos RC4 hardening — full enforcement today (07-14)— Phase 2 complete: RC4 disabled by default for Kerberos auth. Legacy apps still requesting RC4 will break — inventory before/after. Also today: SQL Server 2016exits free extended support into paid ESU.
    Senserva CVE reference

Web Security Research

  • PortSwigger — "HTTP/1.1 must die: the desync endgame"— New classes of HTTP request-smuggling / desync attacks capable of mass credential compromise, with case studies subverting core infrastructure at Akamai, Cloudflare and Netlify (tens of millions of sites exposed). Reinforces 2025's theme that side channels and desync are core exploitation primitives.
    PortSwigger Research

AI Security

  • Prompt injection named #1 AI security threat of 2026— Now the top OWASP LLM risk, with a reported 340% YoY increase in attacks; researchers treat it as unsolved (filters aren't reliable). Guidance converges on containment: least privilege, human approval for risky actions, sandboxed tools.
    CSO Online· Help Net Security
  • Zscaler ThreatLabz — indirect prompt injection in the wild— Two documented campaigns plant instructions in web content an agent reads (fake software docs → payment scam; crypto-service impersonation), using SEO poisoning to rank the malicious pages. Researchers warn the IPI surface is extending to visual channels.
    Zscaler ThreatLabz· Infosecurity

Threat Intelligence

  • Unit 42 — "Screening Serpens" (Iran-nexus) espionage— AppDomainManager hijacking and new RAT variants targeting aerospace, defense manufacturing and telecom, notably expanding into Western Europe.
    Unit 42
  • Unit 42 2026 Global IR Report— AI is now a force multiplier compressing the attack lifecycle from access to impact; fastest-attack exfiltration speeds quadrupled in 2025.
    Unit 42 IR Report

Supply Chain Focus

  • jscrambler npm compromise — payload IDed as IronWorm (Shai-Hulud lineage)— Follow-up to the 07-11 incident: JFrog attributes the Rust infostealer across 5 trojanized versions (8.14.0, 8.16.0–8.18.0, 8.20.0) to IronWorm. Target list notably includes config files for Claude Desktop, Cursor, Windsurf, VS Code and Zed— i.e., API keys and MCP server credentials — plus AWS/Azure/GCP creds, MetaMask/Phantom/Exodus wallets and Bitwarden vaults. Paired with the Injective Labs SDK poisoning (07-08).
    The Hacker News· Security Boulevard

Chinese-Language Community Picks

  • AI agent finds 21 0-days in FFmpeg— depthfirst's autonomous security agent scanned roughly 1.5 million lines of C, confirming 21 0-days with reproducible PoCs; some had lain dormant for 15–20 years (the earliest stack overflow traces back to 2003). In the same period Chrome shipped a record 429 defect fixes.
    Infosec Knowledge Base

Ransomware Today

RansomLook API/RSS was unreachable from the runner today (network-restricted); summary compiled from open reporting. Qilin remains the dominant leak-site operator — ~141 orgs across 25+ countries in the trailing 30 days, far ahead of Akira (~64). SafePay recently posted 3 healthcare victims in 24h. U.S. orgs are ~65% of listings; legal services, manufacturing, construction, tech and healthcare are the most-hit sectors.
Full ransomware note

Bug Bounty

Bug Bounty coverage now updates as its own daily track (deep dive + themed recent disclosures).
Open the Bug Bounty daily track


AI Frontier

OpenAI

  • GPT-5.6 (Sol / Terra / Luna) shipped 07-09across ChatGPT, API and Codex, ending a 13-day preview. Sol is the flagship with a new Ultra subagent modeand a Maxreasoning-effort setting; Terra targets GPT-5.5-level quality at ~half the cost; Luna is the fast tier. Continued attention to agent injection mitigations as subagent autonomy grows.

Anthropic

  • Claude Fable 5 returned 07-01, retaking the coding crown at 80.3% on SWE-Bench Pro— a Mythos-class flagship built for long-horizon agentic runs at $10 / $50 per 1M tokens. Builds on the Claude Science push (10× life-sciences R&D) announced earlier this month.

Google DeepMind / AI

  • Gemini 3.5 Pro delayed to 07-17for a full architectural rebuild (scrapping the 2.5 Pro base): 2M-token context, a Deep Think Reasoning Layer, and autonomous-workflow features, aimed at GPT-5.6 and Fable 5. Focus areas: math reasoning, SVG generation, image quality.

Failed Sources (if any)

  • RansomLook API (/api/posts?days=1) & RSS — unreachable from runner (sandbox network restricted); ransomware section compiled from open web reporting.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 13, 2026
Next →
Rosetta Daily · Jul 15, 2026