threat-intel CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws The CISA has issued an urgent warning to federal agencies and all organizations regarding several actively exploited vulnerabilities in Adobe ColdFusion, Langflow, Joomla extensions, and CitrixBleed. These flaws, includi… SecurityWeek · Jul 8, 2026 Critical CVE-2026-48282CVE-2026-55255CVE-2026-33017vulnerabilityexploitationpatch
threat-intel Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection A critical vulnerability, dubbed GitLost, has been identified in GitHub Agentic Workflows, allowing unauthenticated attackers to potentially leak private repository data by injecting prompts into public GitHub Issues. Th… SecurityWeek · Jul 8, 2026 Critical prompt injectionai securityagentic ai
threat-intel China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware A Chinese APT group, UAT-7810, is expanding its Operational Relay Box (ORB) network by utilizing custom malware, including LONGLEASH and LEASHTEST, to establish persistent access for secondary threat actors. The group le… The Hacker News · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717TWaptmalwarec2
threat-intel ESET Threat Report H1 2026 The first half of 2026 demonstrates attackers’ increasing reliance on adapting existing techniques, leveraging AI to enhance their efficiency and expand the attack surface. This includes AI-powered malware, sophisticate… WeLiveSecurity · Jul 8, 2026 Medium aisocial engineeringransomware
threat-intel State IDs for AI Agents: Will Estonia Set a Precedent? Estonia is planning to assign official government ID numbers to AI agents to regulate their use within government systems. This initiative, part of Eesti.AI, aims to enable organizations and individuals to utilize AI for… Dark Reading · Jul 8, 2026 Medium EEairegulationdigitalization
threat-intel 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros Researchers at Nebula Security discovered GhostLock (CVE-2026-43499), a 15-year-old Linux kernel vulnerability that allows an unprivileged user to gain root access on a machine. The flaw, discovered by their AI-driven bu… The Hacker News · Jul 8, 2026 High CVE-2026-43499CVE-2026-53166CVE-2026-46242linuxkernelprivilege-escalation
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror
threat-intel ISC Stormcast For Wednesday, July 8th, 2026 https://isc.sans.edu/podcastdetail/9998, (Wed, Jul 8th) The SANS Internet Storm Center’s latest Stormcast highlighted a significant increase in malicious activity targeting industrial control systems (ICS) and operational technology (OT) environments. Specifically, the report… SANS Internet Storm Center · Jul 8, 2026 High icsotvulnerability
threat-intel Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A financially motivated campaign utilizing Vidar stealer and XMRig cryptocurrency miner has been active since April 2026, targeting consumers and small- and medium-sized businesses globally, primarily in the U.S. and EU.… Palo Alto Unit 42 · Jul 7, 2026 High USDEmalvertisingdll hijackinganti-forensic
threat-intel Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft Google has patched a critical vulnerability in its Dialogflow CX AI chatbot platform, dubbed 'Rogue Agent,' which could have allowed attackers to steal data from AI agents. The flaw stemmed from a permission boundary iss… Dark Reading · Jul 7, 2026 High aichatbotcodeblocks
threat-intel More Odd DNS Records: NIMLOC, (Tue, Jul 7th) This article discusses the continued use of NIMLOC DNS records, an obsolete record type originally designed for the Nimrod routing architecture. Despite the demise of NetBIOS and the shift to modern DNS and SMB protocols… SANS Internet Storm Center · Jul 7, 2026 Info dnsnetbiosmac
threat-intel Critical Gitea Flaw Under Active Exploitation, Researchers Warn A critical vulnerability in Gitea’s reverse-proxy authentication mechanism is being actively exploited, allowing attackers to bypass authentication and gain unauthorized access to Gitea instances. The flaw, tracked as CV… SecurityWeek · Jul 7, 2026 Critical CVE-2026-20896vulnerabilityauthenticationgit
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
threat-intel Britain plans to build autonomous AI 'Cyber Shield' to defend nation The UK’s National Cyber Security Centre (NCSC) is developing an AI-powered ‘Cyber Shield’ to bolster national cybersecurity defenses against increasingly sophisticated and rapid attacks. This initiative aims to automate… The Record · Jul 7, 2026 High UKaicybersecuritynational defense
threat-intel 'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows A critical prompt injection vulnerability, dubbed ‘GitLost,’ has been discovered in GitHub’s Agentic Workflows, allowing unauthenticated attackers to steal private data from an organization’s repositories by crafting a G… Dark Reading · Jul 7, 2026 High prompt injectionagentic aisecurity vulnerability
threat-intel DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts A Microsoft 365 device code phishing campaign, leveraging collaboration-themed lures, has been observed targeting M365 accounts. The campaign, utilizing a reusable tooling layer called DEBULL, bypasses multi-factor authe… The Hacker News · Jul 7, 2026 High HRTRdevice-codephishingmicrosoft
threat-intel Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Researchers at Noma Security discovered a vulnerability, dubbed ‘GitLost,’ in GitHub Agentic Workflows that allows attackers to trick AI agents into leaking private repository content simply by posting a malicious issue… The Hacker News · Jul 7, 2026 High prompt injectionai agentgithub
threat-intel Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker U.S. prosecutors have linked an alleged Scattered Spider hacker, Peter Stokes, to a luxury jewelry retailer breach through a persistent Windows device ID. Stokes, a dual U.S.-Estonian citizen, was extradited from Finland… The Hacker News · Jul 7, 2026 High ESFIUNdevice-idhackerintrusion
threat-intel Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants A critical session isolation vulnerability, dubbed WriteOut, has been discovered in Writer, an AI platform, allowing attackers to steal session tokens and gain control of user accounts across multiple organizations. The… The Hacker News · Jul 7, 2026 Critical session-hijackingtenant-isolationai
threat-intel CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws The US Cybersecurity and Infrastructure Security Agency (CISA) is leveraging Anthropic’s AI model, Mythos, to proactively scan federal government software for security vulnerabilities. This initiative is part of a broade… SecurityWeek · Jul 7, 2026 Medium USaiintelligencevulnerability