Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-29
Daily Brief·2026-07-29·30 Sources·27 Items

Rosetta Daily · Jul 29, 2026

Generated automatically · 30 sources scanned · 27 items selected · window: past ~24–48h

Critical Vulnerabilities

  • Arista VeloCloud Orchestrator — OS command injection 🔴🔥⚠️ — Arista VeloCloud Orchestrator (VCO), CVE-2026-16812, CVSS 10.0
    Maximum-severity OS command injection in on-prem VCO enabling arbitrary code execution; actively exploited in the wild and added to CISA KEV. Patch or isolate management plane immediately.
    thehackernews

  • JetBrains TeamCity On-Premises — arbitrary code execution 🔴 — TeamCity On-Premises, CVE-2026-63077, CVSS 9.8
    Critical flaw affecting all on-prem TeamCity versions; JetBrains urged immediate updates. CI/CD servers are high-value pivots into build/supply chains.
    thehackernews

  • WordPress "wp2shell" — unauthenticated RCE 🔴 — WordPress core/plugin, CVE-2026-63030 & CVE-2026-60137
    Emergency updates issued for two chained critical flaws allowing unauthenticated remote code execution and full site takeover.
    Check Point Research

  • Microsoft AD FS & SharePoint zero-days 🔥⚠️ — CVE-2026-56155 (AD FS), CVE-2026-56164 (SharePoint)
    Two zero-days exploited in the wild; federal agencies were mandated to patch CVE-2026-56155 by July 28. Attacks target identity and collaboration infrastructure.
    securityonline.info

  • Linux kernel LPE on CentOS Stream 9 ⚠️ — Linux kernel tc (traffic-control) subsystem, CVE-2026-53264, CVSS 7.8
    STAR Labs published an exploit turning an ordinary local user into root via a use-after-free race; researchers noted AI assisted in finding the bug and accelerating exploit development.
    thehackernews

In-the-Wild Exploitation (CISA KEV)

  • CVE-2026-16812 — Arista VeloCloud Orchestrator(CVSS 10.0) — added to KEV amid active exploitation.
  • CVE-2026-16232 — Check Point SmartConsole improper authentication— added July 22.
  • CVE-2026-50522 — Microsoft SharePoint deserialization of untrusted data— added July 22.
  • Fortinet FortiOS flaw— added to KEV alongside the VeloCloud entry.
    CISA KEV· OpenText

Vendor Advisories

  • Microsoft July 2026 Patch Tuesday— 570 vulnerabilities fixed (57 critical, 510 important), two zero-days exploited in the wild (AD FS, SharePoint). One of the largest monthly releases on record.
    CrowdStrike· Rapid7
  • JetBrains— out-of-band advisory for TeamCity On-Premises (CVE-2026-63077).
  • WordPress— emergency core/plugin updates ("wp2shell").
  • Arista— VCO OS command-injection fix (CVE-2026-16812).

Web Security Research

  • vBulletin unauthenticated eval()RCE— Public exploit shows an unauthenticated request reaching PHP's eval()inside vBulletin to execute code on unpatched forum servers.
    thehackernews
  • HTTP/2 flaw & Notepad++ plugin abuse— Featured in this week's roundup alongside a Check Point 0-day and a "Certighost" exploit; worth watching for protocol- and supply-chain-level abuse.
    cybersecuritynews

AI Security

  • AI as an active operator in intrusions— Check Point Research: AI has moved from attack aid to active operator across live intrusions and malware development; high-risk GenAI prompts doubled to ~4%.
    Check Point Research
  • MINJA memory-injection attack— Poisoning an LLM agent's memory through ordinary queries alone (no direct memory access): 98.2% injection success, 76.8% attack success.
    MDPI review
  • International AI Safety Report 2026— Even best-defended models bypassed ~50% of the time within 10 attempts; Claude, GPT, Gemini, Grok and open models all shown vulnerable. Jailbreak-as-a-service sells for $50–200/mo.
    Group-IB
  • EU AI Act GPAI enforcement— General-purpose-AI obligations apply now, with enforcement powers going live August 2026; continuous automated red-teaming becoming a compliance baseline.
    unrot.co

Threat Intelligence

  • East Asia-linked APT hits Middle East governments— Zscaler ThreatLabz reports previously unreported malware TELESHIM, MIXEDKEY and BINDCLOAK; TELESHIM abuses the Telegram API for C2 to blend with legitimate traffic.
    thehackernews
  • Dysphoria IoT botnet— Adopted blockchain-based name services and infected-device relays after March law-enforcement action against JackSkid infrastructure.
    thehackernews
  • VPN/firewall edge under siege— Palo Alto, Fortinet, Citrix and Check Point appliances are the dominant ransomware initial-access vector in mid-2026; Qilin affiliates chain auth-bypass, credential harvesting and legacy-protocol weaknesses.
    cybersecuritynews

Chinese-Language Community Picks

  • This run could not fetch FreeBuf / Xianzhi / Anquanke separately (web_fetch source-gate restriction). The cross-source topics most relevant to the Chinese-language web-security community are the vBulletin unauthenticated eval()RCEand the WordPress wp2shell unauthenticated RCE— both common attack surfaces in the forum/CMS ecosystem, so check your asset versions.

Ransomware Today

The RansomLook API was unreachable from the run environment; today's picture is compiled from open reporting. Highlights: Qilin ⭐ listed medtech firm Stryker (Jul 24); Anubis hit care provider Eagle Crest Communities (WI) (Jul 27) and earlier Coca-Cola subsidiary Fairlife (Jul 20). Edge VPN/firewall exploitation remains the leading initial-access route.
Full victim notes

Bug Bounty

Bug Bounty coverage is now a standalone weekly (deep dives + themed recent disclosures).
View the weekly Bug Bounty feature


AI Frontier

OpenAI

  • Previewed GPT-5.6(Sol / Terra / Luna) to a small group of government-vetted organizations ahead of a broader July release; reportedly floated giving Washington a 5% equity stake.

Anthropic

  • Launched Claude Sonnet 5; announced Claude Science(building on the Coefficient Bio acquisition and hire of AlphaFold's John Jumper). Interpretability team identified an internal subspace behaving like a "global workspace" via a Jacobian-based technique. Andrej Karpathy joined to work on frontier LLMs; Commerce lifted export controls that had pulled Fable 5 / Mythos 5 offline.

Google DeepMind / AI

  • Released Gemini 3.6 Flash, Nano Banana 2 Lite, and Gemini Omni Flash.

🛡 = security/safety-relevant


Failed / Limited Sources

  • RansomLook API (/api/posts?days=1) — unreachable from run environment; used open reporting instead.
  • Direct RSS/Atom feeds (CISA KEV, Bleeping, THN, PortSwigger, etc.) — blocked by web_fetch provenance gate; content gathered via WebSearch.
  • Chinese community feeds (FreeBuf / 先知 / 安全客) — not individually retrievable this run; cross-cutting web items (vBulletin, WordPress) cover overlapping ground.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 28, 2026
Next →
Rosetta Daily · Jul 30, 2026