Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-27
Daily Brief·2026-07-27·16 Items

Rosetta Daily · Jul 27, 2026

Generated automatically · ~29 sources scanned · 16 items selected
Time window: past ~24–72h. Sunday = lighter news day; some items surfaced via web search because direct fetch from the sandbox is network-blocked (see "Failed Sources").

Critical Vulnerabilities

  • Check Point SmartConsole improper authentication 🔴🔥 — Check Point SmartConsole, CVE-2026-16232
    Authentication weakness in the management console; added to CISA KEV on 2026-07-22 (paired with the SharePoint RCE below). Patch management infrastructure and restrict console exposure.
    CISA KEV

  • SharePoint deserialization RCE still under active exploitation 🔴🔥⚠️ — Microsoft SharePoint (on-prem), CVE-2026-50522, CVSS 9.8
    Unauthenticated remote code execution via unsafe deserialization; on CISA KEV since 2026-07-22. Attackers steal machine keys for persistence. Rotate keys and apply July patches.
    The Hacker News · CISA KEV

  • Second SharePoint RCE — CVE-2026-58644, CVSS 9.8 🔴🔥 — Microsoft SharePoint
    Network-exploitable, unauthenticated, low complexity; added to KEV 2026-07-16. Part of the multi-CVE SharePoint exploitation wave CISA has been warning about all month.
    CISA

In-the-Wild Exploitation (CISA KEV)

  • AD FS elevation of privilege — deadline TOMORROW 🔥⚠️ — Microsoft AD FS, CVE-2026-56155, CVSS 7.8
    Confirmed exploited in the wild (no public PoC yet); successful exploitation grants admin. Federal agencies must patch by 2026-07-28. Prioritize identity infrastructure now.
    BleepingComputer

  • SharePoint EoP CVE-2026-56164 🔥 — Microsoft SharePoint, CVSS 5.3
    Exploited in the wild; added to KEV 2026-07-14 (federal deadline was 07-17). Chains with the SharePoint RCEs above.
    CISA

Vendor Advisories

  • GitHub restructures bug bounty — public payouts halved, effective TODAY— GitHub / Microsoft
    From 2026-07-27, public bug bounty payouts drop by ≥50% at every severity (critical: $20k–30k+ → flat $10k); a new invite-only VIP tier pays $30k+. Framed as a response to the flood of low-effort / AI-generated reports. Reports filed before today keep old terms.
    The Hacker News· GitHub Blog· The Register

Web Security Research

  • PortSwigger — SAML authentication bypasses & parser differentials — PortSwigger Research
    Recent research highlights novel SAML auth bypasses (Jan 2026) and parser-differential exploitation (mismatches in how components interpret the same input); side-channels are increasingly a core exploitation primitive. Upcoming work: compromising email accounts via CSS/HTML past CSS sanitization and hardened CSP.
    PortSwigger Research

  • OAuth grants: the quiet SaaS back door ⚠️ — SaaS security
    The recent Klue breach shows attackers increasingly abusing OAuth grants for persistent, low-noise access into SaaS estates. Audit third-party app grants and token scopes.
    BleepingComputer

AI Security

  • Prompt injection remains OWASP LLM01 — and is surging ⚠️ — OWASP / industry
    Per OWASP's 2026 LLM report, prompt injection is up 340% YoY, with 50–84% attack success depending on config. Root cause unchanged: LLMs process privileged instructions and untrusted input in one context window with no reliable separation. No complete fix — even frontier models remain vulnerable; defense-in-depth only.
    OWASP/summary

  • SourTrade: browser-assembled malware to evade detection ⚠️ — Confiant / malvertising
    Detailed 2026-07-23. Instead of serving one executable, the campaign ships a template, a clean Bun runtime, encrypted data and session-specific values so the victim's browser builds a unique payload locally — defeating static/URL-based detection. Impersonates TradingView/Solana/Luno; 12 countries, 25 languages, active since late 2024.
    The Hacker News · Confiant

  • AI-driven autonomous attacks going mainstream 🛡⚠️ — FreeBuf weekly (community)
    Roundup notes a GPT Agent compromising Hugging Face via a 0-day, Anthropic shipping Claude security plugins for terminal code scanning, and Gemini 3.5 Flash Cyber for automated vuln discovery — both offense and defense accelerating.
    FreeBuf weekly

Threat Intelligence

  • North Korea arrests former cyber elite over state-bank hacks — DPRK
    Reported 2026-07-26: former cyber operatives arrested for hacking state banks — a rare glimpse of internal enforcement inside the DPRK cyber apparatus.
    BleepingComputer

  • Steam forums weaponized in ClickFix campaign → XMRig ⚠️ — malware
    Surfaced 2026-07-25: attackers use throwaway Steam accounts to post fake "fixes" in crash/lost-item threads, luring gamers into PowerShell that installs XMRig. Adds a Defender exclusion, hides in C:\Windows\Background, and runs the miner as SYSTEM via a startup scheduled task.
    BleepingComputer

Chinese-Language Community Picks

  • FreeBuf weekly: AI-automated attacks become real— Infosec Knowledge Base (gm7.org)
    This week centres on a GPT agent breaching Hugging Face, Anthropic's Claude security plugin, and Gemini 3.5 Flash Cyber doing automated bug hunting; it also covers WordPress wp2shell, a ServiceNow sandbox RCE, and a 15-year-old NGINX flaw, among other high-severity issues.
    FreeBuf weekly· Cloud security skill / 30 CVEs in a week

Ransomware Today

Direct RansomLook fetch was network-blocked; figures cross-checked via search. Headline case: Anubis claims Fairlife (Coca-Cola's ~$4B dairy sub) — 1TB exfiltrated, Nutanix systems encrypted, US production briefly halted; extortion deadline is today (Mon 2026-07-27). Market context: Qilin continues to dominate RaaS (2026 hit ~7,551 disclosed victims across 146 groups; Qilin +443% YoY).
Full victim table

Bug Bounty

Bug Bounty coverage is now a standalone weekly feature (deep dives + themed recent disclosures). Note: GitHub's public-payout cut takes effect today, reshaping the economics for public researchers.
View the Bug Bounty weekly feature


AI Frontier

OpenAI

  • Offers Washington a $42.6B stake— deepening lab–government ties.
  • Community roundup: a GPT Agent reportedly compromised Hugging Face via a 0-day (autonomous-attack case study).

Anthropic

  • Claude Sonnet 5launched; acquired Coefficient Bio (~$400M), hired John Jumper(AlphaFold), with Andrej Karpathy joining frontier LLM work.
  • Open-sourced the J-lensinterpretability technique; reportedly preparing an S-1 for an IPO as early as Oct 2026.
  • Shipping Claude security pluginsfor terminal code vulnerability scanning.

Google DeepMind / AI

  • Released Nano Banana 2 Liteand Gemini Omni Flash; Boston Dynamicsintegrating Gemini Robotics-ER 1.6into Spot + Orbit AI.
  • Gemini 3.5 Flash Cybertargets automated vulnerability discovery.

Full AI Frontier archive: ai-frontier/daily/2026-07-27.html


Failed Sources

  • RansomLook API (/api/posts?days=1) and RSS — network-blocked from the sandbox; ransomware figures backfilled via web search.
  • Most RSS/HTML feeds (PortSwigger, Mandiant, Bleeping, MSRC, FreeBuf, etc.) not fetched directly (sandbox network + provenance gate); items sourced via WebSearch. Consider a manual re-pull when direct fetch is available.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 26, 2026
Next →
Rosetta Daily · Jul 28, 2026