Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-08-27
Daily Brief·2026-08-27·35 Sources·25 Items

Rosetta Daily · Aug 27, 2026

Scanned 35 sources, selected 25 items from the last 36 hours.

Actively Exploited (KEV)

Gitea — critical RCE actively exploited, dropping miner-like payloads (CVE-2026-60004, CVSS 9.8)

CISA warned on Tuesday of active exploitation of a recently patched Gitea flaw that lets an attacker with ordinary repository write access execute arbitrary shell commands. Reported attacks are dropping miner-like payloads. CISA added the CVE to its KEV catalog.

Sources: The Hacker News · Bleeping Computer

Oracle HTTP Server / WebLogic Server — max-severity flaw under active exploitation (CVE-2026-21962, CVSS 10.0)

CISA added this improper access control flaw to its KEV catalog on Monday, citing evidence of active exploitation. It lets an unauthenticated attacker with HTTP network access reach critical data on affected servers.

Sources: The Hacker News

Zimbra Collaboration Suite — 270+ servers already compromised via OS command injection (CVE-2026-73570)

Threat actors have compromised more than 270 Zimbra instances through remote code execution attacks against a high-severity ZCS vulnerability that CISA added to KEV on Aug 21.

Sources: Bleeping Computer

Critical Vulnerabilities

miniOrange SAML SSO plugin for WordPress — attackers probing unauthenticated admin bypass (CVE-2026-61979, CVSS 8.1)

Bad actors are attempting to exploit unauthenticated privilege-escalation bypasses in the Xecurify miniOrange SAML 2.0 SSO plugin, disclosed by Patchstack, that let an attacker sign in as any WordPress user including administrators. Not yet listed in KEV.

Sources: The Hacker News

Microsoft SharePoint — RCE exploit chain now under active targeting with public PoC

Threat intel firm Defused reports attackers are chaining two SharePoint vulnerabilities to achieve arbitrary code execution on unpatched servers. No CVE numbers or KEV status given in the source.

Sources: Bleeping Computer

QWED-MCP verification gateway — deterministic-check bypass (CVE-2026-55546, CVSS 9.8)

QWED-MCP, a deterministic verification gateway for the Model Context Protocol, had a flaw in verify_math_expression() prior to version 0.2.1 that undermines the verification it exists to provide.

Sources: NVD

AI Security

PraisonAI multi-agent framework — cluster of auth-bypass and SSRF-adjacent flaws (up to CVSS 9.1)

Five CVEs disclosed against PraisonAI prior to versions 4.6.51–4.6.58: unauthenticated Jobs API access (CVE-2026-55539, 8.6), auth-middleware bypass in create_auth_middleware() (CVE-2026-55533, 8.2), unrestricted Server API access via AgentServer (CVE-2026-55528, 8.2), an SSRF-block bypass in spider_tools._host_is_blocked (CVE-2026-55526, 8.5), and a Browser Server connection-handling issue (CVE-2026-55536, 9.1).

Sources: NVD · NVD

mcp-shell — command-execution MCP server flaws (CVE-2026-55580, CVSS 8.6; CVE-2026-55581/55582, CVSS 8.4)

mcp-shell, an MCP server built to run shell commands "securely, auditably, and on demand," carries multiple pre-0.x-fix vulnerabilities in that same execution path.

Sources: NVD

Marimo Notebook — MCP command could execute before notebook cells run in edit mode

Marimo patched a high-severity flaw that let an attacker-supplied Model Context Protocol command execute inside a specially crafted notebook, per a VulnCheck CNA record.

Sources: The Hacker News

NVIDIA NemoClaw — malicious webpage can seize a local Ollama instance and poison the model

Oasis Security disclosed a weakness letting an attacker-controlled webpage take unauthenticated control of a local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. Also covered in Chinese by 安全客.

Sources: The Hacker News · 安全客

Trail of Bits — "VMs won't contain cyber-capable agents"

Given preview access to GPT-5.6-Cyber, researchers tasked it with escaping a QEMU/KVM VM used for sandboxing on a Linux dev machine — a live test of whether current sandboxing assumptions hold against agentic offensive capability.

Sources: Trail of Bits Blog

Unit 42 — "The State of AI-Enabled Malware, August 2026"

Palo Alto's Unit 42 published research on AI-authored malware spanning brand abuse to agentic execution, and how existing behavioral detection holds up against it.

Sources: Unit 42

Vendor Advisories

CISA — seven ICS/OT advisories published today, covering FURUNO FA-50 AIS transponders, Bendix EC80 brake ECUs, Ebyte NE2-D11, PayRange API, Rently Smart Home, Zoneminder, and Siemens SIMATIC IoT2050 Advanced.

Sources: CISA — FURUNO FA-50 · CISA — Bendix EC80

CISA — "A Tale of Two SOCs": two simultaneous red team assessments, one detected nothing

Both target organizations were fully compromised to the domain level with similar tradecraft, but one detected and contained the intrusion while the other did not. CISA's lessons: untuned detection tools miss real threats, organizational silos block response, and cloud environments are underestimated risk.

Sources: The Hacker News · CISA Advisory AA26-237A

Web Security Research

PortSwigger — "What's in a tag name? JavaScript, apparently"

A dig into which characters HTML permits in tag names turns up a parsing quirk that lets an attacker-chosen tag name get interpreted as executable JavaScript.

Sources: PortSwigger Research

Trail of Bits — state divergence bug lets any user self-grant admin on Provenance Blockchain

A bug in Provenance Blockchain, a Cosmos SDK proof-of-stake chain used for tokenized loans and other financial products, allowed any user to grant themselves admin control over marker accounts without holding a token.

Sources: Trail of Bits Blog

Other

NovaCookies — AitM phishing kit abuses genuine Docusign notifications to steal Microsoft 365 sessions

The toolkit proxies real Microsoft 365 sign-ins while capturing authenticated session tokens as victims pass through.

Sources: The Hacker News

SLEEPWALKER — previously unreported Windows backdoor stays dormant until one crafted packet arrives

An independent researcher documented the backdoor, which then runs commands in a custom 23-instruction bytecode language of its own design.

Sources: The Hacker News

FBI disrupts proxy network that supported Chinese state espionage operations

The bureau took down infrastructure run by a technical "quartermaster" providing reconnaissance, proxy management, and operational routing for Chinese cyber espionage activity.

Sources: Bleeping Computer

US Treasury sanctions Iran-linked hackers behind critical-infrastructure breaches

Part of what Treasury called an "unprecedented, whole-of-government" economic campaign targeting Iran's cyber-enabling financial connections.

Sources: The Hacker News

Boston Scientific — cyberattack disrupts global operations

The medical technology company confirmed IT-system disruption affecting operations worldwide; no details yet on data impact.

Sources: Bleeping Computer

Nutex Health — hospital operator confirms data theft

The healthcare provider is investigating a breach in which an unauthorized third party exfiltrated data from company servers.

Sources: Bleeping Computer

Norway — DDoS attack disrupts shared government digital services

A large distributed denial-of-service attack has been disrupting Norway's shared public-sector digital infrastructure since Monday.

Sources: Bleeping Computer

Snowflake retires service-account passwords — the hard part is what comes next

Snowflake is forcing legacy service accounts off password auth onto passwordless methods; identifying who owns each account and how much access it actually needs is the harder problem, per Token Security.

Sources: Bleeping Computer

INTERPOL Operation Jackal IV — 58 arrests, 263 identified in West Africa fraud crackdown

An eight-month operation across 22 countries targeted West African organized crime groups behind global cyber fraud.

Sources: The Hacker News

← Prev
Rosetta Daily · Aug 26, 2026
Next →
Rosetta Daily · Aug 28, 2026