Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-15
Daily Brief·2026-07-15·27 Sources·21 Items

Rosetta Daily · Jul 15, 2026

Generated automatically · 27 sources scanned · 21 items selected

Critical Vulnerabilities

  • 🔴 JetBrains YouTrack / Hub — pre-auth account-takeover chain — JetBrains YouTrack & Hub, CVE-2026-50242 / CVE-2026-56141 / CVE-2026-56142 (+ sandbox-bypass RCE CVE-2026-33392)
    A cluster of critical flaws lets an attacker reach admin without valid creds: authentication bypass via direct database access (CVE-2026-50242), admin takeover via forged auth tokens from predictable restore codes (CVE-2026-56141), and full email-verification bypass (CVE-2026-56142). Several need no auth or user interaction. Self-hosted Hub / YouTrack / TeamCity operators should upgrade to the fixed builds now.
    Cyberpress · GBHackers

  • ⚠️ RoguePlanet — Defender / Malware Protection Engine LPE (CVE-2026-50656, CVSS 7.8) — Microsoft
    Privilege escalation in the Microsoft Malware Protection Engine that can yield SYSTEM. Fixed in engine build 1.1.26060.3008 (auto-updates for most); the standout fix of this month's Patch Tuesday since there was no newly actively-exploited zero-day. Confirm your engine version updated.
    The Hacker News

In-the-Wild Exploitation (CISA KEV)

  • CISA KEV — 07-13 addition: Cisco IOS CSRF (CVE-2008-4128)— a 2008 cross-site request forgery flaw added on evidence of fresh in-the-wild abuse (legacy gear still exposed). FCEB agencies are on the BOD clock; audit any long-lived Cisco IOS devices.
    CISA 07-13· CISA KEV
  • Still on the KEV clock from earlier this month: iCagenda / Balbooa Forms Joomla upload zero-days (CVE-2026-48939 / CVE-2026-56291, CVSS 10.0)and the 07-07 trio incl. Langflow auth bypass (CVE-2026-55255). Confirm remediation if you run any of these.
    CISA 07-10· CISA 07-07

Vendor Advisories

  • Microsoft July Patch Tuesday (07-14) — 127 CVEs— Framed as a "normalization" after June's record 206, but still above every pre-2026 monthly average. Includes 7 Visual Studio CVEs plus .NET SDK fixes; RoguePlanet (above) is the headline. No newly actively-exploited zero-day this cycle.
    byteiota· Help Net Security
  • Kerberos RC4 hardening — full enforcement reached (07-14)— The July cumulative update permanently removes the RC4DefaultDisablementPhaserollback control from all supported Windows Server DCs. Legacy apps still requesting RC4 will break — inventory Kerberos RC4 usage before it bites.
    Zecurit

Web Security Research

  • PortSwigger — "The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?"— Follow-up to the "HTTP/1.1 must die" thesis: an arsenal of new desync triggers, gadgets and exploits that compromised banks, security products and government infrastructure. Reinforces that HTTP/1.1 back-ends remain densely packed with easily-found desync bugs; front-end mitigations give false comfort.
    PortSwigger Research· HTTP/1.1 must die

AI Security

  • "GitLost" — GitHub Agentic Workflows leak private repos via prompt injection— Noma Labs showed an unauthenticatedattacker can plant hidden English instructions in a public GitHub Issue; once the agent is assigned, it fetches README.mdfrom private repos in the same org and posts them as a public comment. Guardrails were bypassed simply by prefixing the malicious ask with "additionally". Treat all user-controlled content as untrusted; minimize agent permissions and what agents can post publicly.
    The Hacker News· Noma Security· The Register
  • Prompt injection remains OWASP LLM #1 for 2026— ~340% YoY rise; a 2026 enterprise survey found 88% of orgs reported confirmed or suspected AI-agent incidents in the past year. GitLost is a live example of why researchers treat it as unsolved, not a bug awaiting a patch. Containment (least privilege, human approval, sandboxed tools) is the consensus mitigation.
    Help Net Security· SecurityWeek

Threat Intelligence

  • Unit 42 — "Screening Serpens" (Iran-nexus) espionage— AppDomainManager hijacking and new RAT variants targeting aerospace, defense manufacturing and telecom, expanding into Western Europe; timing tracks the Middle East conflict that began 2026-02-28.
    Unit 42
  • Unit 42 2026 Global IR Report— Attacks are 4× faster (data exfiltration in <1h in some cases), 65% of initial access is identity-based, and 87% of intrusions spanned multiple attack surfaces. AI is compressing the access-to-impact lifecycle.
    RH-ISAC summary

Supply Chain Focus

  • jscrambler npm compromise (IronWorm / Shai-Hulud lineage)— Malicious 8.14.0 / 8.16.0–8.18.0 / 8.20.0 (plus webpack/gulp/grunt/metro plugins) dropped a Rust infostealer during install; 1,479 downloads before takedown. Targets include cloud creds and AI-coding-assistant config (Claude Desktop, Cursor, VS Code) → API keys / MCP creds. Relatedly, npm v12 ships this month, blocking install scripts by default— the mechanism behind a year of these attacks.
    The Hacker News· TechTimes — npm v12

Ransomware Today

RansomLook API/RSS was again unreachable from the runner (network-restricted; 403 tunnel) — summary compiled from open reporting. Qilin remains the dominant leak-site operator (~1,500–1,870 victims over the trailing 12 months, well ahead of Akira ~1,205). Recent moves: The Gentlemen claimed ~18 victims in 24h (07-10, tech/software + construction); Qilin posted 7 in 24h (07-09) incl. Inter Power Engineering; fresh listings include Shuttle Meadow Country Club (Qilin, 07-13) and Transworld Signs (Akira, 07-13). Q1 2026: Qilin + Akira + The Gentlemen + LockBit together = ~41% of all victims.
Full ransomware note

Bug Bounty

Bug Bounty coverage now updates as its own daily track (deep dive + themed recent disclosures).
Open the Bug Bounty daily track

🀄 Chinese Community (FreeBuf etc.)

  • AI Agent finds 21 zero-days in FFmpeg; Chrome 149 fixes record 429 flaws— FreeBuf's weekly highlights the maturing of AI-assisted vuln discovery (some FFmpeg bugs 23 years old) and Chrome's largest single security release. Also circulating: reports of the "first fully-automated AI ransomware attack" and fallout from a fully-booked Pwn2Own Berlin 2026.
    FreeBuf 漏洞· 信息安全知识库

AI Frontier

OpenAI

  • GPT-5.6 (Sol / Terra / Luna)has been publicly available since 07-09 across ChatGPT, API and Codex — Terra as the default paid tier, Sol for Pro, Luna for high-volume/budget. OpenAI also unveiled its custom Jalapeño inference chipin early July. Agent-injection mitigations stay in focus as subagent autonomy grows.

Anthropic

  • Claude Sonnet 5 shipped 07-01— pitched as Anthropic's most agentic model yet (autonomous browser/terminal use at near-Opus-4.8 quality, lower cost), alongside the U.S. government lifting national-security restrictions on Fable 5 / Mythos 5. Reports note four senior Google researchers recently moved to Anthropic.

Google DeepMind / AI

  • Gemini 3.5 Pro GA slipped to 07-17after enterprise testers flagged reasoning/coding issues — a full architectural rebuild (2M-token context, Deep Think reasoning layer). Google also expanded its Gemini Enterpriseagent platform at Cloud Next '26.

Failed Sources (if any)

  • RansomLook API (/api/posts?days=1) & RSS — unreachable from runner (sandbox network restricted, 403 tunnel); ransomware section compiled from open web reporting.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 14, 2026
Next →
Rosetta Daily · Jul 16, 2026