Rosetta Daily · Jul 21, 2026
Generated automatically · 20+ sources scanned · 16 items selected
Critical Vulnerabilities
-
ServiceNow AI Platform pre-auth RCE — ServiceNow, CVE-2026-6875 ⚠️🔥
Unauthenticated sandbox-escape RCE (reported by Searchlight Cyber). Full instance compromise possible: table data access, admin account creation, command execution on connected MID Servers. Patched for self-hosted on July 13; now exploited in the wild with a public PoC available.
Help Net Security · BleepingComputer · PoC coverage -
SharePoint Server RCE cluster — Microsoft, CVE-2026-58644 (CVSS 9.8) + CVE-2026-32201 / -45659 / -56164 ⚠️🔥
CISA confirms active exploitation across all supported on-prem SharePoint (Subscription Edition, 2019, 2016). Chains to RCE plus post-exploitation: IIS machine-key theft, deserialization for persistence, malware deployment. Microsoft had rated CVE-2026-45659 "exploitation less likely" before CISA added it to KEV.
CISA hardening alert · The Register -
nginx heap buffer overflow — F5/nginx, CVE-2026-42533 🔴
Remote, unauthenticated heap buffer overflow. Fixed July 15 in nginx 1.30.4 and 1.31.3. Given nginx's footprint, patch promptly on edge-facing instances.
The Hacker News (roundup) -
7-Zip XZ decoder heap overflow — 7-Zip, CVE-2026-14266 🔴
High-severity heap overflow in the XZ decoder; a crafted archive can run code when opened. Fixed in 7-Zip 26.02.
The Hacker News
In-the-Wild Exploitation (CISA KEV)
-
Microsoft July Patch Tuesday — record volume + zero-days ⚠️🔥
Record-breaking release (reported as 570–622 flaws across trackers), including two zero-days under active attack and one publicly disclosed. Confirmed exploited: CVE-2026-56155 (AD FS elevation of privilege, CVSS 7.8) grants admin via a low-priv local attacker, no user interaction.
The Hacker News · BleepingComputer · ZDI review -
CISA KEV additions this month 🔥
Multiple batches added in July (3 on 7/7, 4 on 7/14, 2 on 7/15, plus SharePoint CVE-2026-45659 on 7/1). Prioritize BOD 22-01 remediation for internet-facing assets.
CISA KEV catalog
Vendor Advisories
-
Apple security releases — iOS, macOS Tahoe, Safari
Apple shipped its latest round of OS/Safari security patches (late-June cycle); verify fleets are on current builds ahead of any new July drop.
Apple Support · Malwarebytes -
Microsoft MSRC — July rollup
Full July guidance and rollup details in the Security Update Guide.
MSRC
Web Security Research
- PortSwigger Research — ongoing
Track the Research feed and the newly published "Top 10 web hacking techniques of 2025" writeups for technique deep-dives worth reproducing.
PortSwigger Research· Top 10 2025
AI Security
-
Prompt injection remains OWASP LLM #1 ⚠️
Prompt injection has held the top OWASP LLM spot across every 2026 edition. Production systems from Microsoft, Google, GitHub and OpenAI have all been exploited via injection in 2025–2026; notable CVEs include Microsoft Copilot (CVSS 9.3), GitHub Copilot (9.6) and Cursor IDE (9.8). Reported attack success rates of 50–84%; no complete fix exists even for frontier models. July telemetry (Unit 42 / Google) shows web-based injection observed in the wild.
OWASP guide · Vectra -
AI-agent-driven intrusions surface ⚠️
Reports of an autonomous AI agent breaching Hugging Face production infrastructure, and a solo actor ("bandcampro") outsourcing botnet operations to Google's Gemini CLI — early signals of AI agents used offensively at scale.
TechCrunch — worst breaches 2026 -
SleeperGem — Ruby supply-chain attack ⚠️
Three malicious gems published to RubyGems in a supply-chain campaign dubbed SleeperGem. Audit Ruby dependency pipelines.
The Hacker News
Threat Intelligence
-
Armored Likho / Eagle Werewolf — LLM-generated loaders ⚠️
Targeting government and electric-power operators in Russia, Kazakhstan and Brazil via spear-phishing exploiting CVE-2025-9491. Kaspersky found LLM-generated first-stage loader code that erases the stylistic fingerprints used to attribute malware.
SOC Prime / research roundup -
APT-C-60 — SpyGlace against Japan
Spear-phishing with Proton Drive links / weaponized RAR → LNK → mshta.exe JS → SpyGlace (v3.1.15–3.1.18) via legitimate developer services.
SOC Prime -
Screening Serpens (Iran) — six new RAT variants
Feb–Apr 2026 deployment targeting US, Israel, UAE and Middle East entities.
Unit 42 -
Check Point — 20 July threat intel report
Weekly roundup of top attacks, breaches and CVEs.
Check Point Research
Chinese-Language Community Picks
- Searches of FreeBuf / Anquanke in this window returned mostly stale results; no new 7/21 items were confirmed. Check the FreeBuf vulnerabilities channeldirectly for the latest.
Ransomware Today
5 new leak-site posts across 4 groups (RansomLook, days=1). qilin double-tap — Famesa (manufacturing/defense) and City Ambulance Service (healthcare/emergency), both watchlist hits. Also: krybit → euroins.bg (insurance), gunra → a US law firm, blackout → bluebellgroup.com.
Full victim table
Bug Bounty
Bug Bounty coverage is now a standalone daily (deep-dive + themed recent disclosures).
Open the Bug Bounty daily section
AI Frontier
OpenAI
- GPT-5.6 (Sol/Terra/Luna)publicly released; billed as OpenAI's "strongest cybersecurity model yet." New GPT-Livevoice models (simultaneous listen/speak). TechCrunch
Anthropic
- Claude Sonnet 5now default for Free/Pro. Claude Codesecurity update: tighter permission checks, safer Bash/PowerShell handling, EndConversation tool. Also Claude for Teachers + self-serve HIPAA config. Releasebot
Google DeepMind / AI
- Gemini 3.5 Pro delayed(unofficial 7/17 target); full architectural rebuild, 2M-token context, Deep Think layer. Talent exodus + ~$225B Alphabet market-cap hit. The Agent Report
Full AI Frontier archive: ai-frontier/daily/2026-07-21.html
Failed Sources (if any)
- Direct RSS/Atom/HTML feed fetching unavailable in this run (provenance gate + sandbox network block); brief assembled via WebSearch per category + RansomLook API. Chinese-community (FreeBuf / 安全客) search surfaced mostly stale results this window — no fresh 7/21 items confirmed.
Sources used: see intel/sources.yaml