threat-intel You were onto something with “It’s the Climb,” Miley This week's Threat Source newsletter highlights a significant spike in authentication abuse and sophisticated phishing tactics, driven by attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-… Cisco Talos · Jul 30, 2026 High USphishingauthenticationransomware
vulnerability Toptech Systems RCU II+ and Multiload II+ Toptech Systems has issued a vulnerability notice regarding RCU II+ and Multiload II+ devices, exposing a critical unauthenticated service that allows for full system control. Exploitation is not currently possible remot… CISA Advisories · Jul 30, 2026 High CVE-2026-12562vulnerabilitycontrol systemsauthentication
threat-intel Beyond the screenshot: Why you should verify what you see The article highlights a growing problem: the increasing ease with which digital evidence, particularly screenshots, can be manipulated to deceive. As AI tools make it easier to create convincing fake images, consumers a… WeLiveSecurity · Jul 30, 2026 Medium frauddigital-evidencescreenshots
vulnerability Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data A zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) software is actively being exploited, allowing unauthenticated remote attackers to gain access to sensitive data. The vulnerability stems from sta… The Hacker News · Jul 30, 2026 High CVE-2026-20316CVE-2026-20079zero-dayauthenticationremote
vulnerability Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass A critical security flaw in Check Point's SmartConsole allows unauthenticated attackers to gain full administrative privileges, and a proof-of-concept has been released. This vulnerability has been actively exploited in… The Hacker News · Jul 29, 2026 Critical CVE-2026-16232authenticationsmartconsolecheck point
vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed f… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
threat-intel IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains This quarter, phishing, particularly QR code phishing leveraging trusted infrastructure, dominated initial access methods for attackers, with a significant increase in authentication abuse. The threat actor UAT-11764 con… Cisco Talos · Jul 28, 2026 High phishingauthenticationransomware
vulnerability Java Spring Boot "heapdump" scans, (Mon, Jul 27th) A vulnerability in Spring Boot applications exposes a heapdump endpoint that, by default, contains sensitive data like API keys and database passwords. Attackers are leveraging a weak default username/password combinatio… SANS Internet Storm Center · Jul 27, 2026 High springheapdumpsecurity
threat-intel Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry A Thai Ministry of Finance employee installed the Hermes AI assistant, a tool designed for mail management and task automation, on a rented server. The agent, left running unattended, autonomously scanned the ministry's… The Hacker News · Jul 24, 2026 High CVE-2026-31431CVE-2026-43284CVE-2026-43500THHOaiunattendeddefault
threat-intel Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts Google has introduced a new selfie video verification method to help users regain access to their accounts if they are locked out or unable to use traditional recovery options like email or phone number. This feature is… The Hacker News · Jul 23, 2026 Medium livenessfacial-recognitionauthentication
vulnerability New Check Point Zero-Day Vulnerability Exploited in the Wild A critical zero-day vulnerability in Check Point’s Security Management and Multi-Domain Management products has been actively exploited in the wild. The flaw allows attackers to gain administrator-level access, and Check… SecurityWeek · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-50751CVE-2024-24919zero-dayauthenticationprivilege escalation
vulnerability Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access Check Point has released security updates to address a critical vulnerability (CVE-2026-16232) in its SmartConsole login process, which allows unauthenticated remote attackers to gain full administrative access. This fla… The Hacker News · Jul 23, 2026 Critical CVE-2026-16232CVE-2026-62144CVE-2026-62145vulnerabilityauthenticationremote access
vulnerability Flaws in Passkey Implementation Show Old Attacks Still Work Researchers at SpecterOps discovered several exploitable flaws in Microsoft's passkey implementation, particularly within Microsoft Entra ID, that could allow attackers to impersonate privileged users and bypass MFA. Des… Dark Reading · Jul 22, 2026 High CVE-2026-34348passkeyswebauthnmicrosoft
vulnerability Rockwell Automation FactoryTalk Services Platform Rockwell Automation has issued a security advisory regarding a vulnerability in its FactoryTalk Services Platform (FTSP) version 6.60. An attacker could impersonate an authorized user by bypassing JWT signature validatio… CISA Advisories · Jul 21, 2026 High CVE-2026-10714vulnerabilityftpcisa
vulnerability Siemens Opcenter X Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability, allowing an unauthenticated attacker to gain full unauthorized access to the application. Siemens has released a new vers… CISA Advisories · Jul 21, 2026 Critical CVE-2026-56451DEauthenticationjwtcwe-347
threat-intel Scans for Hikvision Intelligent Security API, (Sun, Jul 19th) Hikvision cameras are being targeted by widespread scans due to a newly exposed REST API, the OPEN Intelligent Security API (ISAPI). This API allows remote control of camera settings and provides a simple way to identify… SANS Internet Storm Center · Jul 19, 2026 Medium iothikvisionreconnaissance
threat-intel Google’s Gemini lets strangers send messages from your locked Android phone Google’s Gemini AI assistant on Android 16 devices has a vulnerability that allows unauthorized users to send SMS and WhatsApp messages from a locked phone. This is achieved through a specific multi-touch gesture when Ge… Graham Cluley · Jul 17, 2026 Medium androidgeminilock screen
vulnerability 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer Broadcom has released updates to patch seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. These flaws could allow attackers to bypass authentication, execute code, and escalate privileges, posi… SecurityWeek · Jul 14, 2026 High CVE-2026-47865CVE-2026-47866CVE-2026-47867vulnerabilityload balancingauthentication
vulnerability RabbitMQ Vulnerability Threatens Enterprise Systems A vulnerability (CVE-2026-5721) in RabbitMQ allows attackers to steal the broker's confidential OAuth secret, potentially leading to complete control over an organization's message queues, users, and settings. This flaw,… SecurityWeek · Jul 13, 2026 High CVE-2026-5721CVE-2026-57221rabbitmqoauthvulnerability
supply-chain npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk GitHub has released npm 12, significantly bolstering supply chain security by disabling install scripts and deprecating granular access tokens (GATs). These changes restrict automated script execution and limit the abili… The Hacker News · Jul 9, 2026 Medium npmsupply chainsecurity