Rosetta Daily · Jul 28, 2026
Generated automatically · 30 sources configured · 22 items selected
⚠️ Note: primary RSS/Atom feeds were unreachable this run (provenance-gated); items below compiled via web search + RansomLook API. Freshness skews to the past ~5 days rather than a strict 24h window.
Critical Vulnerabilities
-
Check Point SmartConsole Authentication Bypass — Check Point, CVE-2026-16232, CVSS 9.3 🔥
Unauthenticated remote attacker can obtain an application login token and authenticate with full admin privileges, then modify security policies. Added to CISA KEV on Jul 22.
The Hacker News · CISA KEV -
SonicWall SMA 1000 Zero-Days (chained) — SonicWall, CVE-2026-15409 (CVSS 10.0, SSRF) + CVE-2026-15410 (CVSS 7.2, post-auth code injection) 🔥 ⚠️
Attackers chain the two flaws to gain root/admin command execution on internet-facing SMA6210/7210/8200v appliances; exploited as zero-days since late June. Patch to 12.4.3-03453 / 12.5.0-02835.
BleepingComputer · Volexity -
WordPress Core SQL Injection → "wp2shell" RCE — WordPress, CVE-2026-60137 (SQLi) chained with CVE-2026-63030 🔥 ⚠️
Improper sanitisation ofauthor__not_ininWP_Query; chainable to unauthenticated RCE on default installs. Affects 6.8.x <6.8.6, 6.9.x <6.9.5, 7.0.x <7.0.2. Added to CISA KEV Jul 21; FCEB deadline Aug 4.
GBHackers · NetSPI -
Microsoft SharePoint Deserialization RCE — Microsoft, CVE-2026-58644, CVSS 9.8 🔥
Deserialization of untrusted data enables network RCE on SharePoint Server 2016/Enterprise 2016; part of an ongoing SharePoint exploitation wave (CISA hardening guidance issued Jul 14).
CISA -
"Certighost" AD CS Domain Controller Impersonation — Microsoft AD CS, CVE-2026-54121 ⚠️
A working exploit published Jul 24 lets a low-privileged AD user obtain a certificate for a Domain Controller and authenticate as that machine, enabling full domain takeover.
CyberSecurityNews
In-the-Wild Exploitation (CISA KEV)
-
AD FS Elevation of Privilege — Microsoft, CVE-2026-56155, CVSS 7.8 ⚠️
Insufficient access-control granularity lets a low-privileged local attacker elevate to admin with no user interaction; confirmed exploited.
CrowdStrike Patch Tuesday -
Oracle E-Business Suite Improper Privilege Management — CVE-2026-46817 (KEV Jul 15); KNX Protocol lockout weakness — CVE-2023-4346 (KEV Jul 15). Both under active exploitation.
OpenText
Vendor Advisories
-
Microsoft July 2026 Patch Tuesday — 570 flaws fixed, including 3 zero-days. One of the largest Patch Tuesdays on record.
BleepingComputer · ZDI -
Fortinet FortiSandbox OS Command Injection — CVE-2026-25089 & CVE-2026-39808, CVSS 9.1
Unauthenticated command execution via crafted HTTP requests. Patch immediately.
Rapid7 Patch Tuesday
Web Security Research
-
CSS-in-Email Account Takeover — PortSwigger Research
Novel techniques abusing CSS and HTML in email to achieve end-to-end account takeovers on multiple major email providers.
PortSwigger Research -
Notepad++ plugin abuse & HTTP/2 flaw — highlighted in this week's community roundup as notable offensive techniques.
CyberSecurityNews weekly
AI Security
-
Prompt Injection remains the #1 AI risk (OWASP LLM01) — reported up 340% YoY; success rates 50–84% depending on config. No complete fix — frontier models from OpenAI/Google/Anthropic remain vulnerable after best defenses; defense-in-depth is the only viable strategy. ⚠️
ECCU · Vectra -
Coding-assistant CVEs — Microsoft Copilot (CVSS 9.3), GitHub Copilot (CVSS 9.6), and Cursor IDE (CVSS 9.8) cited as production prompt-injection exploitation cases. ⚠️
Axis Intelligence
Threat Intelligence
-
New East-Asia-linked campaign vs Middle East governments — Zscaler ThreatLabz
Multi-stage chain deploying previously unreported malware TELESHIM, MIXEDKEY, and BINDCLOAK; TELESHIM abuses the Telegram API for C2 to blend with legitimate traffic.
The Hacker News – Threat Intel -
Cl0p exploiting PTC Windchill / FlexPLM — affiliates targeting internet-exposed PLM deployments in engineering/manufacturing for data theft & extortion.
SWK recap -
ShinyHunters → Abbott Laboratories — healthcare giant added to leak site mid-July after a voice-phishing (vishing) intrusion.
TechCrunch
Ransomware Today
RansomLook returned 25 fresh victim posts across ~13 groups; 12 hit the watchlist. Most active: Qilin (6, incl. Stryker, Kean University, Highline CC, Ejército Argentino), Play (3), INC Ransom (2, incl. a US health provider). Qilin and "The Gentlemen" are trading places for the #1 spot in 2026, and the Anubis group listed Coca-Cola subsidiary Fairlife on Jul 20.
⚠️ Data caveat: the days=1 API returned posts dated Jul 23–24 (feed appears to lag), not strictly the last 24h.
Full victim table · Ransomware trends 2026
Bug Bounty
Bug Bounty coverage is now a standalone weekly feature (deep dives + themed recent disclosures).
View the Bug Bounty weekly section
AI Frontier
OpenAI
- Previewed GPT-5.6(Sol, Terra, Luna) to a small group of government-vetted orgs ahead of a broader July release; GPT-5.6 Sol Ultraclaimed a proof of the 50-year-old Cycle Double Cover Conjecture using 64 subagents.
Anthropic
- Launched Claude Sonnet 5; hired Nobel laureate John Jumper(former AlphaFold lead) and researcher Andrej Karpathyto work on frontier LLMs. Continues model-welfare research alongside DeepMind and Meta.
Google DeepMind / AI
- Gemini Robotics-ER 1.6integrated into Boston Dynamics' Spot robot and Orbit inspection platform; Gemini 3.6 Flashreleased later in the month.
Failed Sources
- All RSS/Atom feeds (CISA KEV XML, NVD, GitHub Advisories, MSRC, PortSwigger, Project Zero, THN, BleepingComputer, Mandiant, DFIR, Unit 42, FreeBuf, anquanke, arXiv, OpenAI/DeepMind RSS) — blocked by web_fetch provenance gate; content reconstructed via WebSearch.
- Chinese community feeds (FreeBuf, 安全客, 先知) — not directly reachable this run; no items surfaced.
- RansomLook
days=1API — reachable but returned lagging data (Jul 23–24).
Sources used: see intel/sources.yaml