Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-28
Daily Brief·2026-07-28·22 Items

Rosetta Daily · Jul 28, 2026

Generated automatically · 30 sources configured · 22 items selected
⚠️ Note: primary RSS/Atom feeds were unreachable this run (provenance-gated); items below compiled via web search + RansomLook API. Freshness skews to the past ~5 days rather than a strict 24h window.

Critical Vulnerabilities

  • Check Point SmartConsole Authentication Bypass — Check Point, CVE-2026-16232, CVSS 9.3 🔥
    Unauthenticated remote attacker can obtain an application login token and authenticate with full admin privileges, then modify security policies. Added to CISA KEV on Jul 22.
    The Hacker News · CISA KEV

  • SonicWall SMA 1000 Zero-Days (chained) — SonicWall, CVE-2026-15409 (CVSS 10.0, SSRF) + CVE-2026-15410 (CVSS 7.2, post-auth code injection) 🔥 ⚠️
    Attackers chain the two flaws to gain root/admin command execution on internet-facing SMA6210/7210/8200v appliances; exploited as zero-days since late June. Patch to 12.4.3-03453 / 12.5.0-02835.
    BleepingComputer · Volexity

  • WordPress Core SQL Injection → "wp2shell" RCE — WordPress, CVE-2026-60137 (SQLi) chained with CVE-2026-63030 🔥 ⚠️
    Improper sanitisation of author__not_in in WP_Query; chainable to unauthenticated RCE on default installs. Affects 6.8.x <6.8.6, 6.9.x <6.9.5, 7.0.x <7.0.2. Added to CISA KEV Jul 21; FCEB deadline Aug 4.
    GBHackers · NetSPI

  • Microsoft SharePoint Deserialization RCE — Microsoft, CVE-2026-58644, CVSS 9.8 🔥
    Deserialization of untrusted data enables network RCE on SharePoint Server 2016/Enterprise 2016; part of an ongoing SharePoint exploitation wave (CISA hardening guidance issued Jul 14).
    CISA

  • "Certighost" AD CS Domain Controller Impersonation — Microsoft AD CS, CVE-2026-54121 ⚠️
    A working exploit published Jul 24 lets a low-privileged AD user obtain a certificate for a Domain Controller and authenticate as that machine, enabling full domain takeover.
    CyberSecurityNews

In-the-Wild Exploitation (CISA KEV)

  • AD FS Elevation of Privilege — Microsoft, CVE-2026-56155, CVSS 7.8 ⚠️
    Insufficient access-control granularity lets a low-privileged local attacker elevate to admin with no user interaction; confirmed exploited.
    CrowdStrike Patch Tuesday

  • Oracle E-Business Suite Improper Privilege Management — CVE-2026-46817 (KEV Jul 15); KNX Protocol lockout weakness — CVE-2023-4346 (KEV Jul 15). Both under active exploitation.
    OpenText

Vendor Advisories

  • Microsoft July 2026 Patch Tuesday — 570 flaws fixed, including 3 zero-days. One of the largest Patch Tuesdays on record.
    BleepingComputer · ZDI

  • Fortinet FortiSandbox OS Command Injection — CVE-2026-25089 & CVE-2026-39808, CVSS 9.1
    Unauthenticated command execution via crafted HTTP requests. Patch immediately.
    Rapid7 Patch Tuesday

Web Security Research

  • CSS-in-Email Account Takeover — PortSwigger Research
    Novel techniques abusing CSS and HTML in email to achieve end-to-end account takeovers on multiple major email providers.
    PortSwigger Research

  • Notepad++ plugin abuse & HTTP/2 flaw — highlighted in this week's community roundup as notable offensive techniques.
    CyberSecurityNews weekly

AI Security

  • Prompt Injection remains the #1 AI risk (OWASP LLM01) — reported up 340% YoY; success rates 50–84% depending on config. No complete fix — frontier models from OpenAI/Google/Anthropic remain vulnerable after best defenses; defense-in-depth is the only viable strategy. ⚠️
    ECCU · Vectra

  • Coding-assistant CVEs — Microsoft Copilot (CVSS 9.3), GitHub Copilot (CVSS 9.6), and Cursor IDE (CVSS 9.8) cited as production prompt-injection exploitation cases. ⚠️
    Axis Intelligence

Threat Intelligence

  • New East-Asia-linked campaign vs Middle East governments — Zscaler ThreatLabz
    Multi-stage chain deploying previously unreported malware TELESHIM, MIXEDKEY, and BINDCLOAK; TELESHIM abuses the Telegram API for C2 to blend with legitimate traffic.
    The Hacker News – Threat Intel

  • Cl0p exploiting PTC Windchill / FlexPLM — affiliates targeting internet-exposed PLM deployments in engineering/manufacturing for data theft & extortion.
    SWK recap

  • ShinyHunters → Abbott Laboratories — healthcare giant added to leak site mid-July after a voice-phishing (vishing) intrusion.
    TechCrunch

Ransomware Today

RansomLook returned 25 fresh victim posts across ~13 groups; 12 hit the watchlist. Most active: Qilin (6, incl. Stryker, Kean University, Highline CC, Ejército Argentino), Play (3), INC Ransom (2, incl. a US health provider). Qilin and "The Gentlemen" are trading places for the #1 spot in 2026, and the Anubis group listed Coca-Cola subsidiary Fairlife on Jul 20.
⚠️ Data caveat: the days=1 API returned posts dated Jul 23–24 (feed appears to lag), not strictly the last 24h.
Full victim table · Ransomware trends 2026

Bug Bounty

Bug Bounty coverage is now a standalone weekly feature (deep dives + themed recent disclosures).
View the Bug Bounty weekly section


AI Frontier

OpenAI

  • Previewed GPT-5.6(Sol, Terra, Luna) to a small group of government-vetted orgs ahead of a broader July release; GPT-5.6 Sol Ultraclaimed a proof of the 50-year-old Cycle Double Cover Conjecture using 64 subagents.

Anthropic

  • Launched Claude Sonnet 5; hired Nobel laureate John Jumper(former AlphaFold lead) and researcher Andrej Karpathyto work on frontier LLMs. Continues model-welfare research alongside DeepMind and Meta.

Google DeepMind / AI

  • Gemini Robotics-ER 1.6integrated into Boston Dynamics' Spot robot and Orbit inspection platform; Gemini 3.6 Flashreleased later in the month.

Failed Sources

  • All RSS/Atom feeds (CISA KEV XML, NVD, GitHub Advisories, MSRC, PortSwigger, Project Zero, THN, BleepingComputer, Mandiant, DFIR, Unit 42, FreeBuf, anquanke, arXiv, OpenAI/DeepMind RSS) — blocked by web_fetch provenance gate; content reconstructed via WebSearch.
  • Chinese community feeds (FreeBuf, 安全客, 先知) — not directly reachable this run; no items surfaced.
  • RansomLook days=1API — reachable but returned lagging data (Jul 23–24).

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 27, 2026
Next →
Rosetta Daily · Jul 29, 2026