Rosetta Daily · Aug 18, 2026
Scanned 12 sources, 373 raw items, selected 15.
Critical Vulnerabilities
Joomla Sourcerer extension unauthenticated RCE (CVE-2026-74253, CVSS 10.0)
Regular Labs' Sourcerer extension before 14.0.0 processes {source} blocks found in Joomla's final rendered HTML through unverified reflected user input, allowing unauthenticated remote code execution. A same-day Chinese-language report (安全客) noted the flaw was already being exploited just three days after the patch shipped. Sources: NVD, 安全客
multicloud-operators-subscription privilege escalation (CVE-2026-66792, CVSS 9.9)
A user on a managed cluster can escalate privileges by creating a Subscription resource with specially crafted annotations. Source: NVD
T-Systems ImageMaster file upload RCE (CVE-2026-50768, CVSS 9.8)
Version 9.14.2.8.1's "add attachments" feature in the create-new-document function allows a remote attacker to execute arbitrary code via a malicious upload. Source: NVD
GitLab CE/EE unauthenticated GraphQL flaw can delete public projects (CVE-2026-19478, CVSS 9.4)
Affects multiple version lines from 18.2 through 19.2; under certain conditions an unauthenticated attacker could delete public projects via the GraphQL API. GitLab has shipped fixes. Sources: The Hacker News, NVD
Python crypto package openssl_encrypt: mass disclosure of 20+ vulnerabilities (up to CVSS 9.3)
Versions before 1.4.0 were hit with a simultaneous disclosure of hardcoded database credentials, hardcoded JWT/telemetry secrets, authentication bypasses (verify_api_token, AES-GCM decryption), AST sandbox escapes, and a weak PRNG, among others. Representative entry: CVE-2026-74880 (refresh tokens passed as plaintext URL query parameters)
Microsoft Copilot information disclosure (CVE-2026-24301)
A command-injection flaw lets an unauthorized attacker disclose information over the network. Source: MSRC
Actively Exploited / KEV
Ray-Project Ray code injection (CVE-2025-62593) added to CISA KEV
CISA confirmed active in-the-wild exploitation on Aug 17, with browser-triggered RCE. Sources: CISA, The Hacker News
Windows Task Host flaw now exploited by ransomware gangs
Flagged as actively exploited back in April; CISA now confirms ransomware operators have also adopted it. Source: Bleeping Computer
Microsoft Defender "ShieldBreak" zero-day (CVE-2026-69414)
Disclosed last week by researcher "Nightmare Eclipse"; Microsoft is still working on a patch. Source: Bleeping Computer
Suspected China-nexus APT exploits VMware vCenter flaw to deploy Babuk-derived ransomware
CVE-2026-59310 (CVSS 9.8), a vCenter directory-traversal flaw, can be weaponized for arbitrary code execution; researchers attribute active exploitation to a suspected China-nexus APT. Source: The Hacker News
WordPress login-page XSS2Shell flaw — 11,000+ sites under active attack
Reachable from the login page with no account required, per monitoring by 安全客. Source: 安全客
Data Breaches & Campaigns
Hacker claims 3.6 million Azure account records stolen from Fortune 500 companies
The actor claims to have used stolen credentials to breach multiple companies' Azure infrastructure and is now selling employee databases. Source: Bleeping Computer
16 typosquatted RubyGems packages steal browser credentials and crypto wallets
Researchers identified a new campaign, tracked as StubMaker, distributing a Windows-based info-stealer through look-alike gem names. Source: The Hacker News
TWINLOOT: previously undocumented Python implant abuses SharePoint and Teams for credential theft and lateral movement
A modular, PyArmor-hardened implant framework. Source: The Hacker News
AI Security
Anthropic and EPFL research: self-propagating "AI mind viruses" can spread between agents through persistent prompt files
Researchers demonstrated the technique in a simulated six-agent coding environment; payloads propagate through the editable system-prompt files agent harnesses use to carry state across sessions. Preprint released Aug 10. Source: The Hacker News