Rosetta Daily · Jul 29, 2026
Generated automatically · 30 sources scanned · 27 items selected · window: past ~24–48h
Critical Vulnerabilities
-
Arista VeloCloud Orchestrator — OS command injection 🔴🔥⚠️ — Arista VeloCloud Orchestrator (VCO), CVE-2026-16812, CVSS 10.0
Maximum-severity OS command injection in on-prem VCO enabling arbitrary code execution; actively exploited in the wild and added to CISA KEV. Patch or isolate management plane immediately.
thehackernews -
JetBrains TeamCity On-Premises — arbitrary code execution 🔴 — TeamCity On-Premises, CVE-2026-63077, CVSS 9.8
Critical flaw affecting all on-prem TeamCity versions; JetBrains urged immediate updates. CI/CD servers are high-value pivots into build/supply chains.
thehackernews -
WordPress "wp2shell" — unauthenticated RCE 🔴 — WordPress core/plugin, CVE-2026-63030 & CVE-2026-60137
Emergency updates issued for two chained critical flaws allowing unauthenticated remote code execution and full site takeover.
Check Point Research -
Microsoft AD FS & SharePoint zero-days 🔥⚠️ — CVE-2026-56155 (AD FS), CVE-2026-56164 (SharePoint)
Two zero-days exploited in the wild; federal agencies were mandated to patch CVE-2026-56155 by July 28. Attacks target identity and collaboration infrastructure.
securityonline.info -
Linux kernel LPE on CentOS Stream 9 ⚠️ — Linux kernel tc (traffic-control) subsystem, CVE-2026-53264, CVSS 7.8
STAR Labs published an exploit turning an ordinary local user into root via a use-after-free race; researchers noted AI assisted in finding the bug and accelerating exploit development.
thehackernews
In-the-Wild Exploitation (CISA KEV)
- CVE-2026-16812 — Arista VeloCloud Orchestrator(CVSS 10.0) — added to KEV amid active exploitation.
- CVE-2026-16232 — Check Point SmartConsole improper authentication— added July 22.
- CVE-2026-50522 — Microsoft SharePoint deserialization of untrusted data— added July 22.
- Fortinet FortiOS flaw— added to KEV alongside the VeloCloud entry.
CISA KEV· OpenText
Vendor Advisories
- Microsoft July 2026 Patch Tuesday— 570 vulnerabilities fixed (57 critical, 510 important), two zero-days exploited in the wild (AD FS, SharePoint). One of the largest monthly releases on record.
CrowdStrike· Rapid7 - JetBrains— out-of-band advisory for TeamCity On-Premises (CVE-2026-63077).
- WordPress— emergency core/plugin updates ("wp2shell").
- Arista— VCO OS command-injection fix (CVE-2026-16812).
Web Security Research
- vBulletin unauthenticated
eval()RCE— Public exploit shows an unauthenticated request reaching PHP'seval()inside vBulletin to execute code on unpatched forum servers.
thehackernews - HTTP/2 flaw & Notepad++ plugin abuse— Featured in this week's roundup alongside a Check Point 0-day and a "Certighost" exploit; worth watching for protocol- and supply-chain-level abuse.
cybersecuritynews
AI Security
- AI as an active operator in intrusions— Check Point Research: AI has moved from attack aid to active operator across live intrusions and malware development; high-risk GenAI prompts doubled to ~4%.
Check Point Research - MINJA memory-injection attack— Poisoning an LLM agent's memory through ordinary queries alone (no direct memory access): 98.2% injection success, 76.8% attack success.
MDPI review - International AI Safety Report 2026— Even best-defended models bypassed ~50% of the time within 10 attempts; Claude, GPT, Gemini, Grok and open models all shown vulnerable. Jailbreak-as-a-service sells for $50–200/mo.
Group-IB - EU AI Act GPAI enforcement— General-purpose-AI obligations apply now, with enforcement powers going live August 2026; continuous automated red-teaming becoming a compliance baseline.
unrot.co
Threat Intelligence
- East Asia-linked APT hits Middle East governments— Zscaler ThreatLabz reports previously unreported malware TELESHIM, MIXEDKEY and BINDCLOAK; TELESHIM abuses the Telegram API for C2 to blend with legitimate traffic.
thehackernews - Dysphoria IoT botnet— Adopted blockchain-based name services and infected-device relays after March law-enforcement action against JackSkid infrastructure.
thehackernews - VPN/firewall edge under siege— Palo Alto, Fortinet, Citrix and Check Point appliances are the dominant ransomware initial-access vector in mid-2026; Qilin affiliates chain auth-bypass, credential harvesting and legacy-protocol weaknesses.
cybersecuritynews
Chinese-Language Community Picks
- This run could not fetch FreeBuf / Xianzhi / Anquanke separately (web_fetch source-gate restriction). The cross-source topics most relevant to the Chinese-language web-security community are the vBulletin unauthenticated
eval()RCEand the WordPress wp2shell unauthenticated RCE— both common attack surfaces in the forum/CMS ecosystem, so check your asset versions.
Ransomware Today
The RansomLook API was unreachable from the run environment; today's picture is compiled from open reporting. Highlights: Qilin ⭐ listed medtech firm Stryker (Jul 24); Anubis hit care provider Eagle Crest Communities (WI) (Jul 27) and earlier Coca-Cola subsidiary Fairlife (Jul 20). Edge VPN/firewall exploitation remains the leading initial-access route.
Full victim notes
Bug Bounty
Bug Bounty coverage is now a standalone weekly (deep dives + themed recent disclosures).
View the weekly Bug Bounty feature
AI Frontier
OpenAI
- Previewed GPT-5.6(Sol / Terra / Luna) to a small group of government-vetted organizations ahead of a broader July release; reportedly floated giving Washington a 5% equity stake.
Anthropic
- Launched Claude Sonnet 5; announced Claude Science(building on the Coefficient Bio acquisition and hire of AlphaFold's John Jumper). Interpretability team identified an internal subspace behaving like a "global workspace" via a Jacobian-based technique. Andrej Karpathy joined to work on frontier LLMs; Commerce lifted export controls that had pulled Fable 5 / Mythos 5 offline.
Google DeepMind / AI
- Released Gemini 3.6 Flash, Nano Banana 2 Lite, and Gemini Omni Flash.
🛡 = security/safety-relevant
Failed / Limited Sources
- RansomLook API (
/api/posts?days=1) — unreachable from run environment; used open reporting instead. - Direct RSS/Atom feeds (CISA KEV, Bleeping, THN, PortSwigger, etc.) — blocked by web_fetch provenance gate; content gathered via WebSearch.
- Chinese community feeds (FreeBuf / 先知 / 安全客) — not individually retrievable this run; cross-cutting web items (vBulletin, WordPress) cover overlapping ground.
Sources used: see intel/sources.yaml