Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-25
Daily Brief·2026-07-25·18 Items

Rosetta Daily · Jul 25, 2026

Generated automatically · ~20 sources scanned · 18 items selected

Critical Vulnerabilities

  • Certighost — Active Directory Certificate Services (AD CS) ⚠️, CVE-2026-54121
    Researchers H0j3n and Aniq Fakhrul published a working exploit (Jul 24) that lets a low-privileged AD user enroll a certificate for a Domain Controller and authenticate as that machine. Microsoft patched the issue; domains that haven't rolled out the fix should treat this as urgent.
    The Hacker News

  • Microsoft SharePoint RCE 🔴🔥⚠️, CVE-2026-50522, CVSS 9.8
    Deserialization-of-untrusted-data flaw in on-prem SharePoint. watchTowr reports active exploitation after a public PoC; attackers steal machine keys to persist. Separate SharePoint zero-day CVE-2026-56164 was fixed in July Patch Tuesday and is in CISA KEV.
    The Hacker News

  • Check Point SmartConsole Authentication Bypass 🔴🔥⚠️, CVE-2026-16232, CVSS 9.1
    Unauthenticated remote attacker can obtain a login token and authenticate to the management server with full admin rights. Check Point confirms active in-the-wild exploitation.
    Rapid7

In-the-Wild Exploitation (CISA KEV)

  • Oracle E-Business Suite Improper Privilege Management, CVE-2026-46817 — added to KEV Jul 15.
    CISA
  • SharePoint Server privilege-escalation zero-day, CVE-2026-56164 — actively exploited, patched in July Patch Tuesday.
    BleepingComputer
  • ADFS Elevation of Privilege zero-day, CVE-2026-56155 — one of two exploited zero-days in the July batch.
    BleepingComputer

Vendor Advisories

  • Microsoft July 2026 Patch Tuesday— ~570 flaws fixed, 59 Critical (48 RCE), 3 zero-days (2 exploited). Many were reportedly AI-discovered.
    BleepingComputer· ZDI review

Web Security Research

  • New classes of web race conditions + single-packet attack— PortSwigger (Black Hat, Jul 9) introduced limit-overrun race-condition classes and a new Web Security Academy topic with Burp Suite tooling to test the surface.
    PortSwigger

AI Security

  • Prompt injection remains unsolved (OWASP LLM01)— Q2 2026 testing (Axis Intelligence, 312 attacks) finds no model has solved indirect prompt injection in agent contexts; success rates 50–84%. Critical CVEs shipped in Microsoft Copilot (9.3), GitHub Copilot (9.6), and Cursor IDE (9.8) during 2025–2026.
    Axis Intelligence· Vectra
  • AI as attacker force-multiplier— Unit 42's 2026 IR report: identity weaknesses in ~90% of investigations; fastest-attack exfil speeds quadrupled; AI compresses the access-to-impact lifecycle.
    Unit 42

Threat Intelligence

  • Golden Chickens / TAG-195 resurfaces— MaaS operator returns with four new families: TinyEgg (ClickFix-delivered initial-access backdoor), ChonkyChicken + a modular variant, and ChromEggscalator (Chrome credential theft). Both TinyEgg and ChonkyChicken use a structured bidirectional WebSocket C2.
    The Hacker News· Recorded Future
  • D1R extortion crew claims Synopsys & Bosch— group threatens to leak allegedly stolen data unless paid.
    Cyber Security News
  • EY data breach— attackers accessed an IT support system and downloaded documents.
    Cyber Security News

Chinese Community

  • FreeBuf 周报— recent weekly roundups highlight June's must-patch list, the first publicly reported fully-automated AI ransomware attack, and APT early-warnings; guidance stresses patching, AI-ransomware defenses, and elevated monitoring.
    FreeBuf

Ransomware Today

25 new leak-site posts in the last 24h across ~13 groups. Most active: Qilin (6), with Play, KillSec3, and Krybit at 3 each. Watchlist hits include Qilin → Stryker (Fortune-500 medical devices), two universities (Kean, Highline CC), and the Argentine Army; Play added Restaurant Depot; INC Ransom and Akira also posted. Full victim table

Bug Bounty

Bug Bounty coverage is now a standalone weekly feature (deep dives + themed recent disclosures). View the Bug Bounty weekly section


AI Frontier

OpenAI

  • GPT-5.6 family (Sol / Terra / Luna)— 1M-token context, Feb 2026 cutoff, $1–$5 per M input tokens. Plus GPT-Live, simultaneous listen-and-speak voice with interruptions and real-time translation.

Anthropic

  • AMD partnership (Jul 22)— up to 2 GW of AMD Instinct MI450 GPUs; AMD to invest up to $5B in Anthropic.
  • Fable 5 / Mythos 5 restored globally (Jul 1)after export controls lifted, shipping cybersecurity classifiers described as its strongest safeguards. Voice mode expanded across Opus/Sonnet/Haiku with Gmail/Slack reach.

Google DeepMind / AI

  • Gemini 3.5 Pro (Jul 17)— ground-up rebuild, 2M context, Deep Think reasoning layer, autonomous workflows. Gemini 3.6 Flashreleased Jul 21.

🛡 = security-relevant


Failed Sources (if any)

  • None blocking. Chinese-community feeds (FreeBuf/先知/安全客) returned limited fresh 24h items via search; covered at summary depth.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 23, 2026
Next →
Rosetta Daily · Jul 26, 2026