CVE-2025-3248, CVE-2026-10592, CVE-2026-11703, CVE-2026-12340, CVE-2026-13208, CVE-2026-13218, CVE-2026-13322, CVE-2026-13325, CVE-2026-3055, CVE-2026-33017, CVE-2026-42055, CVE-2026-48779, CVE-2026-55958, CVE-2026-55960, CVE-2026-55961, CVE-2026-55962, CVE-2026-55964, CVE-2026-57062, CVE-2026-57231, CVE-2026-57918, CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016, CVE-2026-6291, CVE-2026-6329, CVE-2026-6412, CVE-2026-6450, CVE-2026-6731, CVE-2026-7532, CVE-2026-8451
Domains:
209[.]214
Get tomorrow's brief in your inbox
Today: Citrix patches a high-severity NetScaler memory disclosure flaw reminiscent of CitrixBleed. Anonymous researcher dumps exploits for 15 zero-day vulnerabilities without vendor notification, targeting Linux kernel, FFmpeg, VLC, and more. Microsoft 365 credential spray campaign using Azure CLI ROPC flow bypasses MFA to compromise 78 accounts across 64 organizations.
Langflow RCE Actively Exploited for Cryptocurrency Mining (CVE-2026-33017, CVE-2025-3248)
Threat actors are exploiting CVE-2026-33017 (CVSS 9.3), an unauthenticated remote code execution vulnerability in Langflow AI application endpoints, to deploy Monero miners. Both CVEs are on CISA's Known Exploited Vulnerabilities catalog with EPSS scores of 98.4% and 100%, indicating widespread exploitation. The attack observed over 19 days (March 27 to April 15, 2026) uses a single-line Python payload through unauthenticated Langflow API endpoints to pull a shell script, download a Go-based miner binary called "lambsys," and establish persistence. The malware terminates competing miners (Kinsing, WatchDog, Rocke, Outlaw), disables AppArmor, UFW, iptables, SELinux, and Alibaba Cloud's agent, then deploys a custom XMRig miner. It propagates laterally through reused SSH keys.
Citrix NetScaler SAML Memory Disclosure Flaw (CVE-2026-8451)
Citrix disclosed six vulnerabilities in NetScaler ADC and Gateway appliances, including CVE-2026-8451, a high-severity memory disclosure flaw discovered by watchTowr while reproducing CVE-2026-3055. The new vulnerability stems from out-of-bounds memory reads triggered by malformed SAML requests when NetScaler is configured as a SAML identity provider for single sign-on. This flaw belongs to the same vulnerability class as the 2023 CitrixBleed incident. CVE-2026-3055, disclosed in March, was added to CISA's Known Exploited Vulnerabilities catalog after confirmed active exploitation, with EPSS score of 84% (100th percentile). The bulletin also includes five additional vulnerabilities: memory overflow denial-of-service conditions, unauthenticated arbitrary file reads on exposed management interfaces, memory overread through TCP timestamp handling, and an HTTP/2 denial-of-service flaw requiring manual timeout configuration changes. NetScaler products have accumulated over 20 CISA KEV entries in the past three years, including multiple flaws weaponized in ransomware campaigns.
Anonymous Researcher Drops 15+ Zero-Day Exploits Without Vendor Notification
A researcher using the pseudonym "Bikini" published proof-of-concept exploit code and detailed write-ups for more than a dozen zero-day vulnerabilities in popular open-source projects without notifying vendors. The exploits impact 15 software projects including Linux kernel, Libssh2, Anydesk, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN, and VLC player. Since disclosure, several projects learned of the exploits and started patching. Nine vulnerabilities have been confirmed and received CVE identifiers. The researcher claims to have used OpenAI's GPT-5.5-3-Codex-Spark AI model to fuzz project code and identify irregularities, later confirmed with manual review. The researcher promised to drop additional zero-days in coming days. This incident, called "Exploratorium," reflects a growing trend in 2026 where AI-assisted vulnerability research produces more findings than researchers can responsibly disclose through traditional channels.
Massive Azure CLI Password Spray Bypasses MFA via ROPC Flow
Threat actors compromised 78 Microsoft 365 accounts across 64 organizations between June 12 and 26, 2026, making over 81 million login attempts targeting the Azure CLI. The campaign leverages the deprecated OAuth Resource Owner Password Credentials (ROPC) flow, which sends username and password directly to the token endpoint without interactive MFA prompts. This allows attackers to bypass Conditional Access Policy protections even in environments with MFA enabled. The attacks originated from IPv6 address range 2a0a:d683::/32 controlled by LSHIY LLC (AS32167), an internet infrastructure provider registered in Hong Kong, Wuhan, and New York. Huntress observed the volume of credential spray attacks increase by over 155 times across its customer base in the past six months. The campaign targeted organizations with MFA misconfigurations: MFA enforced only for specific apps rather than "All Cloud Apps," enforced only for admin user groups, enforced only for non-trusted locations, or implemented but never enforced. Eight impacted businesses had no MFA policy at all.
EvilTokens Affiliate Panel Targeting Microsoft 365 (ARToken)
Cisco Talos identified a fully-featured phishing-as-a-service operator panel branded "ARToken" that shares infrastructure and operational patterns with the EvilTokens platform. The panel exposes over 80 API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise operations, and SharePoint exfiltration through a React-based dashboard. The phishing kit deploys a seven-layer anti-analysis system combining client-side behavioral verification with XOR-encrypted payloads. Talos recovered two near-identical lure messages sent April 20, 2026, spoofing an accounts-payable contact at a Wisconsin contractor, addressed to an accounts-payable recipient at a U.S. life-sciences company. The lure abused a real vendor relationship with an outstanding-invoice query theme. All three email authentication checks failed (SPF, DKIM, DMARC). The visible anchor text mimicked the vendor's genuine SharePoint tenant, but the actual href pointed to an attacker-controlled look-alike domain. EvilTokens sells access at $1,500 one-time plus $500/month, with a standalone "Portal Browser" for $500 lifetime. The platform's second-stage capabilities include an AI-augmented BEC pipeline chaining Groq-hosted Llama models for financial exposure scoring and GPT-4o-mini for email translation.
AI-Hallucinated Domains as Software Supply Chain Attack Vector (Phantom Squatting)
Unit 42 researchers found that large language models consistently hallucinate web domains for legitimate brands, which adversaries are actively weaponizing by registering these nonexistent domains to intercept traffic generated by AI systems. The research analyzed 913 global brands, executed 685,339 URL queries across multiple LLM model configurations, generated 2.1 million URLs, and revealed over 13,229 confirmed malicious URLs. Approximately 250,000 hallucinated domains remain unregistered, presenting a significant opportunity for adversaries to exploit the software supply chain through preemptive registration. Unit 42's proactive monitoring of high-priority hallucinated domains yielded real-world detections 18-51 days ahead of adversary registration across multiple sectors. A standout case reveals an attacker who leveraged an AI coding assistant to build a phishing kit named "Montana Empire" targeting a domain the detection pipeline identified as a high-risk hallucination target 23 days earlier. This demonstrates the full cycle from AI-assisted attack development to LLM-hallucinated domain prediction. The attack vector is particularly dangerous because LLMs function as trusted supply chain dependencies: AI agents perform autonomous web research, AI coding assistants recommend third-party service endpoints, and enterprise CI/CD pipelines integrate AI assistants that suggest URLs.
DHS HSIN Network Breach
Hackers breached a DHS internal network for sharing sensitive data with federal, state, local, and industry partners between late May and early June 2026. The intrusion impacted the Homeland Security Information Network (HSIN), targeting HSIN servers and a connected SharePoint system. Details about the intruders and what they took are still unknown. NAIC (National Association of Insurance Commissioners) was hacked at the start of June by the ShinyHunters group, forcing the organization to suspend risk designations for insurers. Some credit rating agencies paused data sharing with NAIC to avoid exposing sensitive information if hackers were still in the network. NAIC was using the data to compile risk designations telling members how much capital they needed to cover policies. NAIC says it has evicted the hackers and is meeting with credit agencies to restore full operations.
Microsoft Defender Extends Endpoint Protection to Local AI Agents
Microsoft Defender now discovers more than 25 types of local AI agents and Model Context Protocol (MCP) servers across managed Windows and macOS devices. Defender protects at runtime: if a developer using a coding agent like GitHub Copilot CLI or Claude Code is targeted by prompt injection attempts, Defender detects and blocks it before the malicious action executes. Security teams can investigate agent exposure across their environment with Advanced Hunting. These capabilities are now in preview. Microsoft also announced Codename MDASH, a multi-model agentic scanning system designed to discover, validate, and help remediate software vulnerabilities across complex environments. MDASH orchestrates a panel of specialized AI agents that reason through proprietary code and systems. Microsoft Entra Backup and Recovery is now generally available, delivering Microsoft-managed, always-on backups native to your environment that are protected from deletion or modification. Security teams can back up core directory objects, compare and restore to previous timestamps, and configure Conditional Access policies to protect against permanent deletion.
Podman Host Environment Variable Leakage (CVE-2026-57231)
Malformed container images can trick podman run into leaking host environment variables into the container. EPSS score is 3% (17th percentile), indicating low observed exploitation.
Multiple Cryptographic Library Vulnerabilities
Microsoft Security Response Center published information on multiple cryptographic and TLS implementation vulnerabilities:
Sources: MSRC
KubeVirt Virtualization Vulnerabilities
Multiple vulnerabilities disclosed in KubeVirt virtualization platform:
Sources: MSRC
GLib Library Vulnerabilities
Six buffer-handling vulnerabilities disclosed in GLib library:
Sources: MSRC
NGINX and Node.js Package Vulnerabilities
Sources: MSRC
Browser Security Beyond Zero-Days
CrowdStrike published analysis on browser security risks beyond zero-day vulnerabilities. The Verizon 2026 Data Breach Investigations Report found vulnerability exploitation surpassed stolen credentials as the top breach entry point in 2025. The CrowdStrike 2026 Global Threat Report found 42% of vulnerabilities were exploited before public disclosure. The time between vulnerability discovery and patching creates a dangerous gap, which is growing with the rise of frontier AI models. The browser ecosystem multiplies exposure because many browsers are built on Chromium as a shared core. If vulnerable code lives in a shared core, the vulnerability can affect multiple browsers at once. Enterprise environments are highly interconnected, where a single browser-based exposure can intersect with identity, SaaS access, unmanaged devices, cloud applications, privileged accounts, and sensitive data. The full scope of zero-day exploitation remains difficult to measure, as publicly known zero-days are only the cases that have been detected, investigated, and disclosed.
Huntress CEO Addresses Threat Hunter Judgment Call
Huntress CEO addressed an incident where a threat hunter used "poor judgment" in alerting a ransomware criminal about a law enforcement probe. The incident reflects ethical and operational challenges in threat intelligence work, particularly when researchers interact with adversary infrastructure or leak sites during investigations.
Today's brief reflects three converging threats to enterprise infrastructure. First, AI-assisted vulnerability research is accelerating the discovery of zero-day exploits faster than traditional disclosure processes can handle, creating a window where defenders have no patches available. Second, misconfigurations in modern authentication systems (particularly MFA that doesn't cover legacy OAuth flows like ROPC) are enabling massive-scale credential spray campaigns that bypass controls organizations assume are protecting them. Third, the integration of AI into development workflows is creating new supply chain attack vectors through hallucinated domains and poisoned training data, fundamentally altering the trust model for code generation and web research.