Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-08-25
Daily Brief·2026-08-25·33 Sources·20 Items

Rosetta Daily · Aug 25, 2026

Scanned 33 sources, selected 20 items from 291 raw items collected in this window.

Known Exploited (KEV)

Zimbra Collaboration Suite command injection actively exploited (CVE-2026-73570)

CISA added this flaw to its KEV catalog on August 21 and issued an emergency directive giving federal agencies three days to patch. The command-injection bug lets attackers execute arbitrary code on the mail server and is confirmed under active exploitation.

Sources: Bleeping Computer

Critical Vulnerabilities

Joomla miniOrange OAuth Client account takeover (CVE-2026-77995, CVSS 10.0)

Versions before 3.2.0 mishandle a cookie value, letting attackers log in as any account, including administrators — a maximum-severity flaw.

Sources: NVD

LXD path traversal lets attackers overwrite host files as root (CVE-2026-66897, CVSS 9.9)

An attacker with container-edit permissions, or anyone launching a crafted image, can abuse template path handling to overwrite arbitrary files on the host as root — a container escape.

Sources: NVD

StackGres Kubernetes-Postgres operator privilege escalation (CVE-2026-78155, CVSS 9.9)

A low-privilege tenant who owns a database can escalate to administrator privileges on the StackGres operator, affecting cloud-native Postgres deployments.

Sources: NVD

Red Hat Keycloak password-reset flaw enables full account takeover (CVE-2026-18963, CVSS 9.1)

An unauthenticated remote attacker can force a password reset and take over any user account. Red Hat has released patches; upgrading is recommended.

Sources: The Hacker News

Zscaler Client Connector: multiple high-severity flaws including remote code execution (CVE-2026-59568 and others, up to CVSS 9.1)

The zero-trust client Zscaler Client Connector has a cluster of bugs: unauthenticated remote code execution in the ZCC context (CVE-2026-59568), an authentication bypass between the client and its portal (CVE-2026-59564), local privilege escalation (CVE-2026-59567), and a Windows buffer overflow causing kernel-level denial of service (CVE-2026-59565).

Sources: NVD CVE-2026-59568 · CVE-2026-59564 · CVE-2026-59567 · CVE-2026-59565

Delta Electronics DIAEnergie OT energy-management software: SQL injection to RCE (4 CVEs, CVSS 8.8)

The same DIAEnergie build (v1.11.00.002) was assigned four separate CVEs (CVE-2026-78314 through 78317), all SQL injection flaws leading to remote code execution in industrial energy-management deployments.

Sources: NVD CVE-2026-78314 · 78315 · 78316 · 78317

phpIPAM REST API authentication bypass (CVE-2026-67602, CVSS 9.3)

Versions before 1.8.2 have a flawed object-cache keying scheme that lets unauthenticated attackers gain full REST API access to this widely used IP address management tool.

Sources: NVD

exceljs-hardened prototype pollution (CVE-2026-78207, CVSS 9.3)

This npm package, marketed as a "hardened" fork, fails to reject __proto__, constructor, or prototype keys in its deepMerge helper, letting attackers trigger prototype pollution via malicious cell-note JSON.

Sources: NVD

justhtml HTML sanitizer: multiple bypasses leading to XSS (3 CVEs, CVSS 9.3)

The justhtml sanitization library has several bypass issues: incomplete angle-bracket escaping when converting text nodes to Markdown (CVE-2026-8445), multiple sanitization bypasses that let script content survive (CVE-2026-7808), and flaws across URL sanitization and Markdown passthrough logic (CVE-2026-5388).

Sources: NVD CVE-2026-8445 · CVE-2026-7808 · CVE-2026-5388

A batch of WordPress plugins disclose critical flaws, up to CVSS 9.8

Several WordPress/WooCommerce plugins disclosed high-severity bugs together: FreightCo (unauthenticated PHP object injection), Jawn (unauthenticated privilege escalation), WP Cafe Pro (unauthenticated local file inclusion), Affiliate Pro (unauthenticated privilege escalation), and Digits (unauthenticated privilege escalation) all score CVSS 9.8; Woo Essential (unauthenticated SQL injection) scores 9.3.

Sources: NVD CVE-2026-66650 · CVE-2026-66648 · CVE-2026-66587 · CVE-2026-32558 · CVE-2026-28165 · CVE-2026-32551

Ransomware-tracking platform RansomLook itself has multiple authorization flaws (5 CVEs, up to CVSS 9.4)

RansomLook, a widely used community platform for tracking ransomware group activity, disclosed a cluster of authorization bugs: a missing authorization check on its admin config endpoint (CVE-2026-78387, CVSS 9.4), unauthorized access to private groups/markets/ransom notes (CVE-2026-78372, 78370), stored XSS in the cryptocurrency wallet detail view (CVE-2026-78391), and a missing-authentication admin endpoint for creating crypto groups (CVE-2026-78369).

Sources: NVD CVE-2026-78387 · CVE-2026-78372 · CVE-2026-78370 · CVE-2026-78391 · CVE-2026-78369

Threat Intelligence & Research

ShinyHunters' attack on security firm ReliaQuest fails

ReliaQuest confirmed an employee was targeted in a social-engineering attack where hackers impersonated a member of its security team; the data-theft attempt failed.

Sources: Bleeping Computer

WordlistLoader and SynkLoader: two new loaders feeding ransomware access brokers

Researchers disclosed two malware families: WordlistLoader delivers Amatera Stealer via ClickFix/ClearFake lures, and SynkLoader specializes in phishing Windows passwords; both are reportedly used to sell initial access to ransomware groups.

Sources: The Hacker News

Operation QUICSILVER: QUICAgent backdoor targets Myanmar government and IT sector

Attackers use graduation-ceremony invitation lures to deliver a Go-language backdoor called QUICAgent against Myanmar government and IT organizations, in a campaign dubbed Operation QUICSILVER.

Sources: The Hacker News

Rust crate with 245M downloads poisoned, suspected North Korean actors

Chinese outlet Anquanke reports a Rust crate with 245 million downloads was poisoned with malicious code that executes automatically at compile time, attributing the campaign to a suspected North Korea-linked group.

Sources: 安全客

ToxicPanda Android trojan expands to 349 targeted apps

The ToxicPanda Android malware gained new functionality that abuses VPN permissions to block Google Play access, expanding its targeting to 349 apps and 167 remote commands.

Sources: Bleeping Computer

South Korean startup platform breach exposes key-management failure

A government-backed South Korean startup platform embedded an encryption key directly in an API, exposing encrypted personal data — a reminder that encryption keys must be managed separately from the data they protect.

Sources: Bleeping Computer

AI Security

UAT-10147 uses AI to scale server attacks, deploys SPECTRE with EDR bypass and Linux rootkit

A suspected Chinese-speaking cybercrime group, UAT-10147, is reportedly using AI to scale attacks against Windows and Linux web servers worldwide, deploying the SPECTRE malware with EDR-evasion and a Linux rootkit; targets cluster in Brazil, Bolivia, China, Canada, and Vietnam.

Sources: The Hacker News

Akamai research: the top 5% of enterprise AI users pose the biggest risk

New Akamai research finds that while security teams focus on everyday ChatGPT/Claude use, a small group of "power users" quietly hardcoding unvetted AI tools into critical business operations poses the more urgent threat.

Sources: The Hacker News

← Prev
Rosetta Daily · Aug 24, 2026
Next →
Rosetta Daily · Aug 26, 2026