Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-26
Daily Brief·2026-07-26·18 Items

Rosetta Daily · Jul 26, 2026

Generated automatically · ~29 sources scanned · 18 items selected
Window: past ~24–72h (some items from the current week surfaced via web search; direct feed fetch blocked in sandbox — see Failed Sources)

Critical Vulnerabilities

  • Critical SharePoint RCE under active exploitation 🔴🔥⚠️ — Microsoft SharePoint (on-prem), CVE-2026-50522, CVSS 9.8
    Deserialization flaw allowing unauthenticated network RCE. watchTowr observed active exploitation after a public PoC dropped; attackers steal machine keys to keep persistent access. Added to CISA KEV on 2026-07-22 (FCEB fix due 07-25).
    source · CISA KEV

  • 15-year-old NGINX heap overflow → pre-auth RCE 🔴 — F5 NGINX, CVE-2026-42533, CVSS 9.2
    Missing save/restore of PCRE capture state in NGINX's internal script engine lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker via crafted HTTP requests — worker crash/DoS, and RCE where ASLR is off/bypassable. Affects 0.9.6–1.31.2; fixed in 1.30.4 / 1.31.3 / NGINX Plus 37.0.3.1 (patched 07-15). Only surfaces with a specific regex-map config.
    source · analysis

  • 7-Zip crafted-archive code execution — 7-Zip, CVE-2026-14266
    Opening a maliciously crafted XZ archive can lead to code execution on the target machine. Update to the latest release.
    source

  • Ubuntu snap-confine local privilege escalation — Ubuntu Desktop, CVE-2026-8933
    Impacts default installs of Ubuntu Desktop 24.04, 25.10 and 26.04 — local attacker can escalate to root.
    source

In-the-Wild Exploitation (CISA KEV)

  • SharePoint deserialization chain keeps growing 🔥⚠️ — CVE-2026-50522, CVE-2026-56164, CVE-2026-58644, CVE-2026-45659
    Multiple SharePoint Server flaws added to KEV across July (07-01, 07-14, 07-16, 07-22). CISA issued a hardening advisory urging on-prem operators to rotate machine keys and apply July fixes.
    CISA advisory

  • Oracle E-Business Suite privilege management 🔥 — CVE-2026-46817 (added 07-15), plus CVE-2023-4346 (KNX)
    Actively exploited; patch and review exposed EBS instances.
    CISA KEV

Vendor Advisories

  • Microsoft July 2026 Patch Tuesday — record 570 flaws, 3 zero-days— Microsoft
    59 Critical (48 RCE). Includes actively exploited zero-days CVE-2026-56155 (AD FS admin-privilege) and CVE-2026-56164 (SharePoint EoP), plus one publicly disclosed. Prioritize AD FS and SharePoint.
    source· ZDI

Web Security Research

  • WordPress plugin flaws exploited at scale ⚠️ — CVE-2026-60137, CVE-2026-63030
    Actively exploited in production WordPress sites, enabling rapid attacker access with potential for sitewide takeover / malware deployment. Audit plugins and update.
    source

  • NGINX regex-map RCE (CVE-2026-42533) — config-conditional — see Critical section
    Notable for web infra teams: exploitation requires a regex-based map whose output variable is referenced in a string expression after an earlier capture. Review NGINX configs even after patching.
    analysis

AI Security

  • FakeAgent malvertising abuses claude.ai to push SectopRAT ⚠️ — malvertising campaign
    Between 07-21 and 07-22, ≥29 orgs were redirected to a malicious Claude Artifact hosted on the legitimate claude.ai domain, posing as a "Claude desktop app" download; payload was SectopRAT wrapped in VMProtect anti-analysis. Domain-reputation defenses fail when abuse rides a trusted host.
    source

  • Agentic AI weaponized against a government network (Hermes) ⚠️ — AI-agent misuse
    A threat actor stood up a popular AI assistant on a rented server with command execution enabled and pointed it at Thailand's Ministry of Finance; the agent enumerated hosts for root access and crawled staff records back to 2012.
    source

  • Prompt injection remains OWASP LLM01, surging ⚠️ — industry/OWASP
    OWASP's 2026 LLM report cites prompt-injection attacks up ~340% YoY; attack success 50–84% depending on config. Critical CVEs reported in Microsoft Copilot (9.3), GitHub Copilot (9.6) and Cursor IDE (9.8). No complete fix — defense in depth only.
    source

Threat Intelligence

  • Golden Chickens MaaS resurfaces with 4 new families — TAG-195 (Recorded Future / Insikt)
    New malware: TinyEgg, ChonkyChicken (+ a modularized variant) and ChromEggscalator, from the financially-motivated MaaS developer.
    source

  • Suspected China-nexus actor uses fake Indian tax-filing utility to deploy DcRAT — espionage/crimeware
    Trojanized tax utility drops DcRAT against Indian targets.
    source

  • Fake Microsoft Entra passkey enrollment → M365 access — credential/session abuse
    Attackers trick users into enrolling an attacker-controlled passkey to gain Microsoft 365 access — a novel twist on account takeover.
    source

  • Accenture confirms breach after data offered for sale — data breach
    Accenture confirmed a breach after a threat actor advertised stolen data.
    source

  • North Korean ClickFix phishing kit impersonates Zoom & Teams — DPRK social engineering
    Active phishing kit spoofs Zoom/Microsoft Teams to deliver malware via ClickFix-style lures.
    source

Chinese-Language Community Picks

  • Direct fetching of the Chinese-language sources (FreeBuf / Xianzhi / Anquanke) was blocked inside the sandbox this cycle, so no same-day items were retrieved. The SharePoint, NGINX and WordPress in-the-wild exploitation items above are equally high-priority for domestic red/blue teams and ops staff — worth checking your estate against them. (Source configuration in intel/sources.yaml.)

Ransomware Today

Web-sourced snapshot (RansomLook API/RSS blocked in sandbox): most active names this week include Qilin, INC_RANSOM, plus Gentlemen, Krybit and ShinyHunters. Notable claimed victims: Deutsche Bank (third-party breach claimed by "Unsafe"), Indra Group (Spanish defense/aerospace, "Gentlemen"), Ford (Krybit, forum listing), Abbott Laboratories (ShinyHunters + ShadowByt3$). Watchlist hits: Qilin, INC (groups) and financial / manufacturing sectors.
full victim table

Bug Bounty

Bug Bounty coverage is now a standalone weekly special (deep dives + themed recent disclosures).
View the Bug Bounty weekly special


AI Frontier

OpenAI

  • GPT-5.6 (Sol / Terra / Luna) + ChatGPT Work— GPT-5.6 released 07-09 in three tiers alongside "ChatGPT Work," an agent that takes an outcome, gathers info across connected apps, and executes multi-step jobs for hours. Desktop app rebuilt to merge Chat, Work and Codex.

Anthropic

  • Claude Opus 5 launched (07-24); Anthropic Economic Indexmade queryable for users (07-21); Coworkexpanded to mobile/web (beta); Claude for Governmentin beta.
  • See AI Security: FakeAgent malvertising abused a Claude Artifact on claude.ai to distribute SectopRAT — a reminder that trusted AI-hosting domains are now abuse surfaces.

Google DeepMind / AI

  • Nano Banana 2 Liteand Gemini Omni Flashshipped in early July, extending Google's multimodal/lightweight model lineup.

Failed Sources

  • Direct RSS/HTML/API feed fetch (RansomLook API + RSS, and all sources.yaml feeds) — sandbox network egress blocked (HTTP 000). Content compiled via web search instead; ransomware figures are indicative, not the full RansomLook daily set.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 25, 2026
Next →
Rosetta Daily · Jul 27, 2026