Rosetta Daily · Jul 27, 2026
Generated automatically · ~29 sources scanned · 16 items selected
Time window: past ~24–72h. Sunday = lighter news day; some items surfaced via web search because direct fetch from the sandbox is network-blocked (see "Failed Sources").
Critical Vulnerabilities
-
Check Point SmartConsole improper authentication 🔴🔥 — Check Point SmartConsole, CVE-2026-16232
Authentication weakness in the management console; added to CISA KEV on 2026-07-22 (paired with the SharePoint RCE below). Patch management infrastructure and restrict console exposure.
CISA KEV -
SharePoint deserialization RCE still under active exploitation 🔴🔥⚠️ — Microsoft SharePoint (on-prem), CVE-2026-50522, CVSS 9.8
Unauthenticated remote code execution via unsafe deserialization; on CISA KEV since 2026-07-22. Attackers steal machine keys for persistence. Rotate keys and apply July patches.
The Hacker News · CISA KEV -
Second SharePoint RCE — CVE-2026-58644, CVSS 9.8 🔴🔥 — Microsoft SharePoint
Network-exploitable, unauthenticated, low complexity; added to KEV 2026-07-16. Part of the multi-CVE SharePoint exploitation wave CISA has been warning about all month.
CISA
In-the-Wild Exploitation (CISA KEV)
-
AD FS elevation of privilege — deadline TOMORROW 🔥⚠️ — Microsoft AD FS, CVE-2026-56155, CVSS 7.8
Confirmed exploited in the wild (no public PoC yet); successful exploitation grants admin. Federal agencies must patch by 2026-07-28. Prioritize identity infrastructure now.
BleepingComputer -
SharePoint EoP CVE-2026-56164 🔥 — Microsoft SharePoint, CVSS 5.3
Exploited in the wild; added to KEV 2026-07-14 (federal deadline was 07-17). Chains with the SharePoint RCEs above.
CISA
Vendor Advisories
- GitHub restructures bug bounty — public payouts halved, effective TODAY— GitHub / Microsoft
From 2026-07-27, public bug bounty payouts drop by ≥50% at every severity (critical: $20k–30k+ → flat $10k); a new invite-only VIP tier pays $30k+. Framed as a response to the flood of low-effort / AI-generated reports. Reports filed before today keep old terms.
The Hacker News· GitHub Blog· The Register
Web Security Research
-
PortSwigger — SAML authentication bypasses & parser differentials — PortSwigger Research
Recent research highlights novel SAML auth bypasses (Jan 2026) and parser-differential exploitation (mismatches in how components interpret the same input); side-channels are increasingly a core exploitation primitive. Upcoming work: compromising email accounts via CSS/HTML past CSS sanitization and hardened CSP.
PortSwigger Research -
OAuth grants: the quiet SaaS back door ⚠️ — SaaS security
The recent Klue breach shows attackers increasingly abusing OAuth grants for persistent, low-noise access into SaaS estates. Audit third-party app grants and token scopes.
BleepingComputer
AI Security
-
Prompt injection remains OWASP LLM01 — and is surging ⚠️ — OWASP / industry
Per OWASP's 2026 LLM report, prompt injection is up 340% YoY, with 50–84% attack success depending on config. Root cause unchanged: LLMs process privileged instructions and untrusted input in one context window with no reliable separation. No complete fix — even frontier models remain vulnerable; defense-in-depth only.
OWASP/summary -
SourTrade: browser-assembled malware to evade detection ⚠️ — Confiant / malvertising
Detailed 2026-07-23. Instead of serving one executable, the campaign ships a template, a clean Bun runtime, encrypted data and session-specific values so the victim's browser builds a unique payload locally — defeating static/URL-based detection. Impersonates TradingView/Solana/Luno; 12 countries, 25 languages, active since late 2024.
The Hacker News · Confiant -
AI-driven autonomous attacks going mainstream 🛡⚠️ — FreeBuf weekly (community)
Roundup notes a GPT Agent compromising Hugging Face via a 0-day, Anthropic shipping Claude security plugins for terminal code scanning, and Gemini 3.5 Flash Cyber for automated vuln discovery — both offense and defense accelerating.
FreeBuf weekly
Threat Intelligence
-
North Korea arrests former cyber elite over state-bank hacks — DPRK
Reported 2026-07-26: former cyber operatives arrested for hacking state banks — a rare glimpse of internal enforcement inside the DPRK cyber apparatus.
BleepingComputer -
Steam forums weaponized in ClickFix campaign → XMRig ⚠️ — malware
Surfaced 2026-07-25: attackers use throwaway Steam accounts to post fake "fixes" in crash/lost-item threads, luring gamers into PowerShell that installs XMRig. Adds a Defender exclusion, hides in C:\Windows\Background, and runs the miner as SYSTEM via a startup scheduled task.
BleepingComputer
Chinese-Language Community Picks
- FreeBuf weekly: AI-automated attacks become real— Infosec Knowledge Base (gm7.org)
This week centres on a GPT agent breaching Hugging Face, Anthropic's Claude security plugin, and Gemini 3.5 Flash Cyber doing automated bug hunting; it also covers WordPress wp2shell, a ServiceNow sandbox RCE, and a 15-year-old NGINX flaw, among other high-severity issues.
FreeBuf weekly· Cloud security skill / 30 CVEs in a week
Ransomware Today
Direct RansomLook fetch was network-blocked; figures cross-checked via search. Headline case: Anubis claims Fairlife (Coca-Cola's ~$4B dairy sub) — 1TB exfiltrated, Nutanix systems encrypted, US production briefly halted; extortion deadline is today (Mon 2026-07-27). Market context: Qilin continues to dominate RaaS (2026 hit ~7,551 disclosed victims across 146 groups; Qilin +443% YoY).
Full victim table
Bug Bounty
Bug Bounty coverage is now a standalone weekly feature (deep dives + themed recent disclosures). Note: GitHub's public-payout cut takes effect today, reshaping the economics for public researchers.
View the Bug Bounty weekly feature
AI Frontier
OpenAI
- Offers Washington a $42.6B stake— deepening lab–government ties.
- Community roundup: a GPT Agent reportedly compromised Hugging Face via a 0-day (autonomous-attack case study).
Anthropic
- Claude Sonnet 5launched; acquired Coefficient Bio (~$400M), hired John Jumper(AlphaFold), with Andrej Karpathy joining frontier LLM work.
- Open-sourced the J-lensinterpretability technique; reportedly preparing an S-1 for an IPO as early as Oct 2026.
- Shipping Claude security pluginsfor terminal code vulnerability scanning.
Google DeepMind / AI
- Released Nano Banana 2 Liteand Gemini Omni Flash; Boston Dynamicsintegrating Gemini Robotics-ER 1.6into Spot + Orbit AI.
- Gemini 3.5 Flash Cybertargets automated vulnerability discovery.
Full AI Frontier archive: ai-frontier/daily/2026-07-27.html
Failed Sources
- RansomLook API (
/api/posts?days=1) and RSS — network-blocked from the sandbox; ransomware figures backfilled via web search. - Most RSS/HTML feeds (PortSwigger, Mandiant, Bleeping, MSRC, FreeBuf, etc.) not fetched directly (sandbox network + provenance gate); items sourced via WebSearch. Consider a manual re-pull when direct fetch is available.
Sources used: see intel/sources.yaml