Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-21
Daily Brief·2026-07-21·20 Sources·16 Items

Rosetta Daily · Jul 21, 2026

Generated automatically · 20+ sources scanned · 16 items selected

Critical Vulnerabilities

  • ServiceNow AI Platform pre-auth RCE — ServiceNow, CVE-2026-6875 ⚠️🔥
    Unauthenticated sandbox-escape RCE (reported by Searchlight Cyber). Full instance compromise possible: table data access, admin account creation, command execution on connected MID Servers. Patched for self-hosted on July 13; now exploited in the wild with a public PoC available.
    Help Net Security · BleepingComputer · PoC coverage

  • SharePoint Server RCE cluster — Microsoft, CVE-2026-58644 (CVSS 9.8) + CVE-2026-32201 / -45659 / -56164 ⚠️🔥
    CISA confirms active exploitation across all supported on-prem SharePoint (Subscription Edition, 2019, 2016). Chains to RCE plus post-exploitation: IIS machine-key theft, deserialization for persistence, malware deployment. Microsoft had rated CVE-2026-45659 "exploitation less likely" before CISA added it to KEV.
    CISA hardening alert · The Register

  • nginx heap buffer overflow — F5/nginx, CVE-2026-42533 🔴
    Remote, unauthenticated heap buffer overflow. Fixed July 15 in nginx 1.30.4 and 1.31.3. Given nginx's footprint, patch promptly on edge-facing instances.
    The Hacker News (roundup)

  • 7-Zip XZ decoder heap overflow — 7-Zip, CVE-2026-14266 🔴
    High-severity heap overflow in the XZ decoder; a crafted archive can run code when opened. Fixed in 7-Zip 26.02.
    The Hacker News

In-the-Wild Exploitation (CISA KEV)

  • Microsoft July Patch Tuesday — record volume + zero-days ⚠️🔥
    Record-breaking release (reported as 570–622 flaws across trackers), including two zero-days under active attack and one publicly disclosed. Confirmed exploited: CVE-2026-56155 (AD FS elevation of privilege, CVSS 7.8) grants admin via a low-priv local attacker, no user interaction.
    The Hacker News · BleepingComputer · ZDI review

  • CISA KEV additions this month 🔥
    Multiple batches added in July (3 on 7/7, 4 on 7/14, 2 on 7/15, plus SharePoint CVE-2026-45659 on 7/1). Prioritize BOD 22-01 remediation for internet-facing assets.
    CISA KEV catalog

Vendor Advisories

  • Apple security releases — iOS, macOS Tahoe, Safari
    Apple shipped its latest round of OS/Safari security patches (late-June cycle); verify fleets are on current builds ahead of any new July drop.
    Apple Support · Malwarebytes

  • Microsoft MSRC — July rollup
    Full July guidance and rollup details in the Security Update Guide.
    MSRC

Web Security Research

  • PortSwigger Research — ongoing
    Track the Research feed and the newly published "Top 10 web hacking techniques of 2025" writeups for technique deep-dives worth reproducing.
    PortSwigger Research· Top 10 2025

AI Security

  • Prompt injection remains OWASP LLM #1 ⚠️
    Prompt injection has held the top OWASP LLM spot across every 2026 edition. Production systems from Microsoft, Google, GitHub and OpenAI have all been exploited via injection in 2025–2026; notable CVEs include Microsoft Copilot (CVSS 9.3), GitHub Copilot (9.6) and Cursor IDE (9.8). Reported attack success rates of 50–84%; no complete fix exists even for frontier models. July telemetry (Unit 42 / Google) shows web-based injection observed in the wild.
    OWASP guide · Vectra

  • AI-agent-driven intrusions surface ⚠️
    Reports of an autonomous AI agent breaching Hugging Face production infrastructure, and a solo actor ("bandcampro") outsourcing botnet operations to Google's Gemini CLI — early signals of AI agents used offensively at scale.
    TechCrunch — worst breaches 2026

  • SleeperGem — Ruby supply-chain attack ⚠️
    Three malicious gems published to RubyGems in a supply-chain campaign dubbed SleeperGem. Audit Ruby dependency pipelines.
    The Hacker News

Threat Intelligence

  • Armored Likho / Eagle Werewolf — LLM-generated loaders ⚠️
    Targeting government and electric-power operators in Russia, Kazakhstan and Brazil via spear-phishing exploiting CVE-2025-9491. Kaspersky found LLM-generated first-stage loader code that erases the stylistic fingerprints used to attribute malware.
    SOC Prime / research roundup

  • APT-C-60 — SpyGlace against Japan
    Spear-phishing with Proton Drive links / weaponized RAR → LNK → mshta.exe JS → SpyGlace (v3.1.15–3.1.18) via legitimate developer services.
    SOC Prime

  • Screening Serpens (Iran) — six new RAT variants
    Feb–Apr 2026 deployment targeting US, Israel, UAE and Middle East entities.
    Unit 42

  • Check Point — 20 July threat intel report
    Weekly roundup of top attacks, breaches and CVEs.
    Check Point Research


Chinese-Language Community Picks

  • Searches of FreeBuf / Anquanke in this window returned mostly stale results; no new 7/21 items were confirmed. Check the FreeBuf vulnerabilities channeldirectly for the latest.

Ransomware Today

5 new leak-site posts across 4 groups (RansomLook, days=1). qilin double-tap — Famesa (manufacturing/defense) and City Ambulance Service (healthcare/emergency), both watchlist hits. Also: krybit → euroins.bg (insurance), gunra → a US law firm, blackout → bluebellgroup.com.
Full victim table

Bug Bounty

Bug Bounty coverage is now a standalone daily (deep-dive + themed recent disclosures).
Open the Bug Bounty daily section


AI Frontier

OpenAI

  • GPT-5.6 (Sol/Terra/Luna)publicly released; billed as OpenAI's "strongest cybersecurity model yet." New GPT-Livevoice models (simultaneous listen/speak). TechCrunch

Anthropic

  • Claude Sonnet 5now default for Free/Pro. Claude Codesecurity update: tighter permission checks, safer Bash/PowerShell handling, EndConversation tool. Also Claude for Teachers + self-serve HIPAA config. Releasebot

Google DeepMind / AI

  • Gemini 3.5 Pro delayed(unofficial 7/17 target); full architectural rebuild, 2M-token context, Deep Think layer. Talent exodus + ~$225B Alphabet market-cap hit. The Agent Report

Full AI Frontier archive: ai-frontier/daily/2026-07-21.html


Failed Sources (if any)

  • Direct RSS/Atom/HTML feed fetching unavailable in this run (provenance gate + sandbox network block); brief assembled via WebSearch per category + RansomLook API. Chinese-community (FreeBuf / 安全客) search surfaced mostly stale results this window — no fresh 7/21 items confirmed.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 20, 2026
Next →
Rosetta Daily · Jul 22, 2026