Rosetta Daily · Jul 30, 2026
Generated automatically · 24 sources scanned · 16 items selected · window: past 24h
Critical Vulnerabilities
-
New Gitea RCE Lets Repository Writers Plant a Git Hook — Gitea, CVE-2026-60004, CVSS 9.8 🔴
A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Because registration is enabled by default, an outside visitor can self-register, create a repo and exploit it — no pre-existing credentials needed. July 28 advisory ships public PoC; fixed in 1.27.1 (affects 1.17+). No in-the-wild exploitation reported yet.
The Hacker News · advisory writeup -
Windows VMSwitch Elevation of Privilege — Microsoft, CVE-2026-57092, CVSS 9.9 🔴
Highest-scored flaw in July Patch Tuesday: a use-after-free in Hyper-V's virtual switch lets a low-privileged attacker escalate to full host compromise — a serious multi-tenant / VDI risk. Patched July 14.
BleepingComputer
In-the-Wild Exploitation (CISA KEV)
-
SharePoint Server RCE added to CISA KEV — Microsoft SharePoint, CVE-2026-45659, CVSS 8.8 🔥⚠️
Remote code execution via deserialization of untrusted data; CISA cited evidence of active exploitation when adding it to the KEV catalog. Patch immediately — SharePoint remains a top target for initial access.
The Hacker News · CISA KEV -
CISA KEV cadence stays high — 9 new KEV entries in the last 7 days (28 across the past 30 days). Zero-days from Microsoft's July batch — CVE-2026-56164 (SharePoint) and CVE-2026-56155 (AD FS) — carried federal remediation deadlines of July 17 and July 28 respectively. ⚠️
CISA alerts (Jul 22)
Vendor Advisories
- Microsoft July 2026 Patch Tuesday — record ~570–620 flaws, 3 zero-days— Two exploited in the wild (CVE-2026-56164 SharePoint, CVE-2026-56155 AD FS) and one publicly disclosed (CVE-2026-50661, BitLocker — deploy within 24–48h as it undermines full-disk encryption guarantees). EoP dominates the batch (41%), then RCE (27%). Microsoft attributes the swelling count partly to a new AI-powered internal bug-discovery system.
BleepingComputer· ZDI review
Web Security Research
- PortSwigger Research — Top 10 Web Hacking Techniques of 2025— The 19th edition of the community-powered ranking has published its final list; a useful pulse-check on the year's most impactful web attack primitives (and nominations context for 2026).
PortSwigger Research
AI Security
- Prompt injection remains the #1 AI security risk (OWASP LLM01)— Reviews through July 2026 report attack success rates of 50–84% depending on configuration; production systems from Microsoft, Google, GitHub and OpenAI have all been exploited via prompt injection. The attack surface now spans agentic AI, RAG pipelines, multimodal models and coding assistants — text-based filters alone don't cover it. With the EU AI Act's August 2026 deadline looming, compliance mapping is getting urgent.
Vectra AI overview· comprehensive review (MDPI)
Threat Intelligence
-
Unit 42 2026 Global Incident Response Report — attacks 4× faster — Data exfiltration in under an hour in some cases; 65% of initial access is identity-based; 87% of attacks span multiple surfaces. AI is compressing the initial-access-to-exfiltration timeline to minutes.
Unit 42 -
Iran-nexus "Screening Serpens" espionage — Unit 42 details AppDomainManager hijacking and new RAT variants targeting technology and defense sectors.
Unit 42
Ransomware Today
18 fresh victim posts tracked; the most active operations remain Qilin, The Gentlemen and Akira — Qilin and The Gentlemen each claimed ~300 victims in Q2 2026 and are trading the #1 spot week to week. Recent Qilin claims span manufacturing (Stryker, Jul 24) and healthcare (Next Clinics). ⭐ Watchlist hits on qilin, akira, healthcare, manufacturing.
Full victim table
Bug Bounty
Bug Bounty coverage is now a standalone weekly deep-dive (themed recent disclosures + 2–3 in-depth analyses).
Open the Bug Bounty weekly feature
AI Frontier
OpenAI
- GPT-5.6 family generally available— Sol / Terra / Luna variants opened to GA on July 9 (previewed June 26 behind a US-government access list). OpenAI is also reported to be preparing a new open-weight language model.
LLM updates
Anthropic
- Claude Opus 5 released (July 24)— Immediately took the top of Artificial Analysis's Intelligence Index; Claude Sonnet 5 became the default model June 30. Independent testing (Axis Intelligence, through July 2026) rates Claude Opus 4.7 lowest in aggregate vulnerability count and highest in single-turn jailbreak resistance.
ThursdAI July 2026
Google DeepMind / AI
- Gemini 3.6 Flash shipped (July 21)— Cheaper, faster Flash now powering the free Gemini app; Google also launched Nano Banana 2 Lite (fastest/cheapest image gen) and Gemini Omni Flash (video + conversational editing). Gemini 3.5 Pro remains delayed / unreleased.
ThursdAI July 2026
Failed Sources (if any)
- RansomLook API / RSS — not reachable from the execution sandbox (network egress blocked); ransomware section compiled from public reporting instead.
- Direct RSS/Atom fetch for several feeds (PortSwigger, Project Zero, MSRC, FreeBuf) unavailable in this run — items sourced via web search of the same publishers.
Sources used: see intel/sources.yaml