Rosetta Daily · Jul 31, 2026
Generated automatically · 30 sources scanned · 22 items selected
Critical Vulnerabilities
-
Ruflo MCP Bridge — Unauthenticated RCE (RufRoot) — Ruflo (agent meta-harness for Claude Code / OpenAI Codex), CVE-2026-59726, CVSS 10.0 🔴⚠️
Default docker-compose exposed the MCP bridge (POST /mcp) with 233 tools and no authentication; an unauthenticated network attacker can callterminal_executeto get a shell, read provider API keys, spawn agent swarms on the victim's keys, and poison AgentDB learning patterns. Affects all versions < 3.16.3; fixed within 24h of disclosure.
The Hacker News · SecurityWeek -
VMware vCenter Directory Service — Authentication Bypass — Broadcom VMSA-2026-0006, CVE-2026-59309, CVSS 9.8 🔴
Auth bypass in the VMware Directory Service lets remote attackers bypass authentication; part of a 5-CVE advisory that also patches an ESX VM-escape (CVE-2026-47876, VMXNET3 OOB write) and a vCenter directory traversal (CVE-2026-59310).
GBHackers · SecurityAffairs -
Microsoft Defender Malware Protection Engine — Critical RCE — Microsoft, CVE-2026-55011 & CVE-2026-55012 🔴
Integer underflow/overflow flaws in the malware-scanning engine allow unauthenticated attackers to execute arbitrary code locally. Engine updates ship automatically but should be verified.
NeuraCybIntel
In-the-Wild Exploitation (CISA KEV)
- Cisco Secure Firewall Management Center — Hard-coded Password (Zero-Day)— Cisco FMC, CVE-2026-20316, CVSS 5.3 (High SIR)
Added to CISA KEV on July 29, 2026. A static, hardcoded low-privilege credential in the FMC web interface lets a remote, unauthenticated attacker log in and read sensitive data; Cisco confirmed active exploitation before a patch existed and warns it can be chained with other FMC flaws to escalate. Patch is the only complete fix.
CISA Alert· runZero· Cybersecurity News
Vendor Advisories
-
Broadcom / VMware VMSA-2026-0006 — Five CVEs across ESX, vCenter, Workstation, Fusion (CVSS 2.7–9.8); rated Critical overall. Released July 29. vSphere 8.0 Update 3k carries the fix but temporarily blocks the VCF 9.1 upgrade path.
Broadcom advisory · angrysysops -
Microsoft — Defender engine RCE (CVE-2026-55011/55012) follows a heavy July Patch Tuesday (570 flaws, 3 zero-days incl. AD FS CVE-2026-56155 and SharePoint bugs already in KEV).
BleepingComputer
Web Security Research
-
PTC Windchill exploited in ransomware campaigns — PLM platform being actively leveraged for initial access in extortion operations; patch and restrict management-interface exposure.
IT Security News -
MCP bridges as a new web attack surface — the RufRoot pattern (network-exposed, unauthenticated agent tool endpoints) generalizes: audit any MCP/agent bridge for default-open ports and missing auth before it reaches production.
Mallory writeup
AI Security
-
RufRoot (CVE-2026-59726) — unauth RCE + API-key theft + learning-store poisoning via an open MCP bridge. See Critical Vulnerabilities above; a landmark case of AI-agent infrastructure being the attack surface, not the model. ⚠️
The Hacker News -
Prompt injection remains OWASP's #1 LLM risk in 2026 — reporting cites a ~340% YoY surge; agent tool-input injection is the highest-impact unsolved category (84% success in lab testing). Same-channel instruction/data confusion means defense-in-depth, not a single fix. ⚠️
Securance · Axis Intelligence
Threat Intelligence
-
Analog Devices — data theft confirmed — intruders detected on ADI systems in June; investigation found files were stolen.
SecurityWeek -
Scattered Spider operator arrested — part of continued law-enforcement pressure on the social-engineering crew, reported alongside July ransomware developments.
Bitdefender Threat Debrief -
Ransomware cartelization — Qilin, Akira, "The Gentlemen" and LockBit together account for ~41% of all victims; Qilin claims ~1,500 victims since launch (500+ in 2026), the most active operation.
SecureBlink
Ransomware Today
~29 new victim posts in the last 24 hours; most active groups: SafePay, followed by Akira ⭐ and AiLock. Notable disclosure this week: DentaQuest data breach affecting 23M+ individuals (Jul 27). Qilin remains 2026's most active operation overall.
Full victim table
Bug Bounty
Bug Bounty coverage is now a standalone weekly deep-dive (themed recent disclosures + 2-3 deep analyses).
View the Bug Bounty weekly section
AI Frontier
OpenAI
- GPT-5.6 (Sol / Terra / Luna)launched — first frontier model cleared through a customer-by-customer US government review before public release; Sol hit ~750 tokens/sec on Cerebras. (govt pre-clearance)
ThursdAI
Anthropic
- Claude Opus 5released July 24 — within 0.5% of Fable 5's peak on CursorBench 3.2 at half the cost per task; pricing unchanged at $5/$25.
ThursdAI
Google DeepMind / AI
- Gemini 3.5 Prolaunch pushed to July 17 for a full architectural rebuild.
BigGo Finance
Failed Sources (if any)
- RansomLook Recent Posts API — not reachable from this run (network/provenance gated); ransomware figures sourced via secondary trackers/news instead.
Sources used: see intel/sources.yaml