Rosetta Daily · Jul 25, 2026
Generated automatically · ~20 sources scanned · 18 items selected
Critical Vulnerabilities
-
Certighost — Active Directory Certificate Services (AD CS) ⚠️, CVE-2026-54121
Researchers H0j3n and Aniq Fakhrul published a working exploit (Jul 24) that lets a low-privileged AD user enroll a certificate for a Domain Controller and authenticate as that machine. Microsoft patched the issue; domains that haven't rolled out the fix should treat this as urgent.
The Hacker News -
Microsoft SharePoint RCE 🔴🔥⚠️, CVE-2026-50522, CVSS 9.8
Deserialization-of-untrusted-data flaw in on-prem SharePoint. watchTowr reports active exploitation after a public PoC; attackers steal machine keys to persist. Separate SharePoint zero-day CVE-2026-56164 was fixed in July Patch Tuesday and is in CISA KEV.
The Hacker News -
Check Point SmartConsole Authentication Bypass 🔴🔥⚠️, CVE-2026-16232, CVSS 9.1
Unauthenticated remote attacker can obtain a login token and authenticate to the management server with full admin rights. Check Point confirms active in-the-wild exploitation.
Rapid7
In-the-Wild Exploitation (CISA KEV)
- Oracle E-Business Suite Improper Privilege Management, CVE-2026-46817 — added to KEV Jul 15.
CISA - SharePoint Server privilege-escalation zero-day, CVE-2026-56164 — actively exploited, patched in July Patch Tuesday.
BleepingComputer - ADFS Elevation of Privilege zero-day, CVE-2026-56155 — one of two exploited zero-days in the July batch.
BleepingComputer
Vendor Advisories
- Microsoft July 2026 Patch Tuesday— ~570 flaws fixed, 59 Critical (48 RCE), 3 zero-days (2 exploited). Many were reportedly AI-discovered.
BleepingComputer· ZDI review
Web Security Research
- New classes of web race conditions + single-packet attack— PortSwigger (Black Hat, Jul 9) introduced limit-overrun race-condition classes and a new Web Security Academy topic with Burp Suite tooling to test the surface.
PortSwigger
AI Security
- Prompt injection remains unsolved (OWASP LLM01)— Q2 2026 testing (Axis Intelligence, 312 attacks) finds no model has solved indirect prompt injection in agent contexts; success rates 50–84%. Critical CVEs shipped in Microsoft Copilot (9.3), GitHub Copilot (9.6), and Cursor IDE (9.8) during 2025–2026.
Axis Intelligence· Vectra - AI as attacker force-multiplier— Unit 42's 2026 IR report: identity weaknesses in ~90% of investigations; fastest-attack exfil speeds quadrupled; AI compresses the access-to-impact lifecycle.
Unit 42
Threat Intelligence
- Golden Chickens / TAG-195 resurfaces— MaaS operator returns with four new families: TinyEgg (ClickFix-delivered initial-access backdoor), ChonkyChicken + a modular variant, and ChromEggscalator (Chrome credential theft). Both TinyEgg and ChonkyChicken use a structured bidirectional WebSocket C2.
The Hacker News· Recorded Future - D1R extortion crew claims Synopsys & Bosch— group threatens to leak allegedly stolen data unless paid.
Cyber Security News - EY data breach— attackers accessed an IT support system and downloaded documents.
Cyber Security News
Chinese Community
- FreeBuf 周报— recent weekly roundups highlight June's must-patch list, the first publicly reported fully-automated AI ransomware attack, and APT early-warnings; guidance stresses patching, AI-ransomware defenses, and elevated monitoring.
FreeBuf
Ransomware Today
25 new leak-site posts in the last 24h across ~13 groups. Most active: Qilin (6), with Play, KillSec3, and Krybit at 3 each. Watchlist hits include Qilin → Stryker (Fortune-500 medical devices), two universities (Kean, Highline CC), and the Argentine Army; Play added Restaurant Depot; INC Ransom and Akira also posted. Full victim table
Bug Bounty
Bug Bounty coverage is now a standalone weekly feature (deep dives + themed recent disclosures). View the Bug Bounty weekly section
AI Frontier
OpenAI
- GPT-5.6 family (Sol / Terra / Luna)— 1M-token context, Feb 2026 cutoff, $1–$5 per M input tokens. Plus GPT-Live, simultaneous listen-and-speak voice with interruptions and real-time translation.
Anthropic
- AMD partnership (Jul 22)— up to 2 GW of AMD Instinct MI450 GPUs; AMD to invest up to $5B in Anthropic.
- Fable 5 / Mythos 5 restored globally (Jul 1)after export controls lifted, shipping cybersecurity classifiers described as its strongest safeguards. Voice mode expanded across Opus/Sonnet/Haiku with Gmail/Slack reach.
Google DeepMind / AI
- Gemini 3.5 Pro (Jul 17)— ground-up rebuild, 2M context, Deep Think reasoning layer, autonomous workflows. Gemini 3.6 Flashreleased Jul 21.
🛡 = security-relevant
Failed Sources (if any)
- None blocking. Chinese-community feeds (FreeBuf/先知/安全客) returned limited fresh 24h items via search; covered at summary depth.
Sources used: see intel/sources.yaml