CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-1352, CVE-2025-1376, CVE-2025-2492, CVE-2025-6052, CVE-2025-6141, CVE-2025-6170, CVE-2025-7039, CVE-2026-10702, CVE-2026-10763, CVE-2026-12352, CVE-2026-12948, CVE-2026-20744, CVE-2026-20896, CVE-2026-31431, CVE-2026-33017, CVE-2026-42945, CVE-2026-42952, CVE-2026-42953, CVE-2026-42958, CVE-2026-43499, CVE-2026-44383, CVE-2026-46242, CVE-2026-48192, CVE-2026-48282, CVE-2026-48908, CVE-2026-49033, CVE-2026-53166, CVE-2026-55255, CVE-2026-56290
IP Addresses:
103.207.14.220, 45.207.216.55
Get tomorrow's brief in your inbox
July 8, 2026
Today: CISA added four actively exploited flaws to the KEV catalog with Adobe ColdFusion attacks starting within two hours of disclosure. A 15-year-old Linux kernel flaw lets any logged-in user gain root across most distros, with working exploit code now public. Device code phishing campaigns bypass MFA by abusing legitimate OAuth flows, and AI coding tools create new supply chain attack surfaces that traditional scanning doesn't cover.
CISA Adds Four Actively Exploited Vulnerabilities to KEV (CVE-2026-48282, CVE-2026-56290, CVE-2026-55255, CVE-2026-48908)
CISA added four security flaws to its Known Exploited Vulnerabilities catalog on July 7. CVE-2026-48282 is a CVSS 10.0 path traversal vulnerability in Adobe ColdFusion that leads to arbitrary code execution. Exploitation began within two hours of public disclosure on June 30, with attempts recorded from an IP in India (103.207.14.220). CVE-2026-48908 (CVSS 10.0) affects JoomShaper SP Page Builder and allows unauthenticated arbitrary file upload leading to PHP code execution. Attackers exploited this as a zero-day via HTTP POST to the index.php?option=com_sppagebuilder&task=asset.uploadCustomIcon endpoint, followed by creation of a Super User account. CVE-2026-56290 (CVSS 10.0) is an improper access control flaw in Joomlack Page Builder CK enabling remote code execution through unauthenticated file upload. Exploitation attempts started June 27, delivering web shells to susceptible sites, with the first confirmed shell found at /media/com_pagebuilderck/gfonts/bhup.php. CVE-2026-55255 (CVSS 6.1) is an authorization bypass in Langflow allowing authenticated attackers to execute any flow by specifying the victim's flow ID. A single operator (45.207.216.55) weaponized this alongside CVE-2026-33017 between June 22 and June 25 in a campaign targeting LLM provider keys and AWS credentials.
Critical Gitea Flaw Under Active Exploitation (CVE-2026-20896)
A critical vulnerability in Gitea's reverse-proxy authentication mechanism allows attackers to access internet-accessible instances by supplying only a valid username. CVE-2026-20896 (CVSS 9.8) affects Gitea's official Docker images before version 1.26.3. The flaw exists because default settings allow connections from any source IP address instead of enforcing an allowlist. When reverse-proxy authentication is enabled, anyone who can reach the Gitea container's HTTP port directly can impersonate any user whose login name is known or guessable by providing a valid username in a header. Exploitation started 13 days after public disclosure. The attempt was associated with a VPN-exit scanner. Approximately 6,200 Gitea instances are accessible from the internet, though the number of vulnerable instances is unclear. Successful exploitation leads to complete compromise of all code and secrets Gitea holds, including private repositories, accidentally committed secrets (API keys, database credentials, deploy tokens), CI/CD configurations, and deploy keys.
5 claims tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| dataleak | Nissin Foods Do Brasil | Food & Beverages | Brazil |
| dataleak | RKW Group | Manufacturing | Germany |
| dataleak | ni*usa.com | Unknown | USA |
| dataleak | SCHERDEL Wiesauplast / Grant & Weber | Manufacturing / Healthcare | Germany / USA |
| dataleak | The Beacon Insurance Company | Insurance | Trinidad and Tobago |
GhostLock: 15-Year-Old Linux Kernel Flaw Enables Root and Container Escape (CVE-2026-43499)
Nebula Security disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user gain full root control. The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw scores 7.8 out of 10 (high, not critical) because an attacker needs to already be logged in to the machine. Nebula turned it into a working root exploit that is 97 percent reliable in testing and also escapes containers. Google awarded the team $92,337 through its kernelCTF bug-bounty program. The bug sits in the kernel's futex priority inheritance system. In one rare case where a lock operation hits a dead end and has to back out, the cleanup runs at the wrong moment and wipes the wrong task's record, leaving the kernel holding a pointer to memory it has already thrown away and reused. The flaw was fixed in April (patch 3bfdc63936dd), but the original fix introduced a separate crash bug (CVE-2026-53166), and the cleanup was still settling upstream in early July. Ubuntu, for example, had patched its newest release and some cloud kernels, but as of early July still listed 24.04, 22.04, and 20.04 LTS as vulnerable or in progress. GhostLock joins Bad Epoll (CVE-2026-46242) and Copy Fail (CVE-2026-31431, already on CISA's KEV list) in a run of 2026 Linux privilege-escalation bugs found by automated tools. GhostLock is also the second half of a chain Nebula calls IonStack. The first half, CVE-2026-10702, is a Firefox flaw that runs code inside the browser and escapes its sandbox; GhostLock carries it the rest of the way to root.
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
A Microsoft 365 device code phishing campaign leveraged collaboration-themed lures to take control of victim accounts between late June 2026 and early July. The campaign uses a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience, while a backend broker generates and polls Microsoft Authentication Broker device-code tokens. Device code phishing refers to an identity theft technique where attackers exploit a legitimate OAuth 2.0 authentication mechanism, specifically the Device Authorization Grant flow, to bypass multi-factor authentication (MFA) and gain persistent account access without having to steal user passwords. Unlike traditional phishing attacks that require operators to set up bogus adversary-in-the-middle (AitM) login pages, device code phishing relies on manipulating a user into completing a real, trusted authentication prompt. Threat actors initiate the authentication flow, then share a code with the target through a phishing lure. When the user enters the code, they authorize the threat actor's session without their knowledge, granting them access to the account. The activity is assessed to share strong overlaps with a campaign documented by Microsoft in February 2025 under the moniker Storm-2372, including the use of messaging or Teams-style lures. The threat actors are employing Storm-2372-style tradecraft through a reusable tooling layer called DEBULL. Successful device code phishing attacks can facilitate full account takeover, theft of valuable information, fraud, business email compromise (BEC), lateral movement within a compromised environment, and even disruptive attacks like ransomware. These campaigns are also known to leverage account takeover (ATO) jumping, a technique where an attacker compromises an initial email account and then abuses it to send phishing links to a broader set of contacts.
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. UAT-7810 is responsible for maintaining and proliferating LapDogs, an ORB network that first came to light in June 2025. UAT-7810 is most likely tasked with establishing ORB networks that can then be leveraged by associated secondary threat actors like UAT-5918 to conduct their own malicious attacks against high value targets. UAT-7810 has continued to develop their custom malware dubbed ShortLeash with a newer version codenamed LONGLEASH. Two other previously unreported tools are also in use: DOGLEASH, a passive backdoor that can execute arbitrary shellcode on a compromised Linux device, and LEASHTEST, an ELF binary used for testing certain functionality on MIPS-based embedded devices. UAT-7810 used at least four new servers to host variations of DOGLEASH. An additional Java-based backdoor tracked as JARLEASH was also deployed on at least one of the three servers for administration purposes, including file management, FTP, SFTP, and Netcat. Attack chains weaponize known vulnerabilities in unpatched Ruckus wireless routers such as CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. Campaigns observed earlier this year also targeted ASUS AiCloud Routers susceptible to CVE-2025-2492. LONGLEASH includes an executor component that enables proxying functions using HTTP, DNS, SOCKS, TCP, ICMP, and UDP protocols, manages network connections to other servers, authorizes clients, and removes the implant and all traces from the server if any tampering attempts are detected. It can also act as an intermediate C2 server to relay commands and data from the primary C2 and forward it to its peers.
Vidar Stealer Campaign Uses Code Signing Abuse, Go Loaders, and File Inflation
In April 2026, Unit 42 identified a financially motivated campaign delivering Vidar stealer and the XMRig cryptocurrency miner to consumer and small- and medium-sized business victims worldwide. Attackers lure victims via malvertising to pages for downloading files that impersonate cracked versions of copyright-protected software. Upon execution, the loader drops and runs both Vidar stealer and XMRig. Vidar stealer targets information like browser credentials, cookies and crypto wallets. XMRig mines Monero cryptocurrency. The campaign distributes loader binaries through malvertising, targeting victims who search for pirated or cracked versions of copyright-protected software. The campaign delivers the malware in password-protected archives with a .bin extension in the filenames to bypass email gateway scanning and prevent automated sandbox detonation without the password. Upon extraction and execution, the loader binary is signed with a certificate (subject CN=justwatch.com), creating a false sense of legitimacy. Analysis indicates the loaders use the Factory-v3 framework. All 43 samples discovered contain embedded Go build metadata identifying the Factory-v3 framework. The builder generates a unique binary per build, with 27 unique build UUIDs observed across 43 samples, defeating hash-based detection. The builder uses Go version 1.25.9, a custom pre-release. Anti-forensic measures include zeroed PE TimeDateStamp, no PE version info, DLL imports reduced to kernel32.dll only, and user-defined type names obfuscated to a V###### pattern. The same builder, toolchain and Authenticode certificate infrastructure underpin a concurrent Lumma stealer campaign, indicating Factory-v3 is used as a service for multiple stealer affiliates. All 43 loader samples carry an Authenticode signature fabricated to impersonate JustWatch GmbH, a legitimate German streaming guide service.
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. RedWing lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLabs says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool documented earlier this year. RedWing is sold as a complete product, in subscription tiers with referral discounts, guides, and how-to videos. A Telegram bot builds each buyer a custom app on demand. Researchers say a substantial number of the resulting droppers and payloads currently evade conventional security tools. Infection starts with a phishing link that opens a fake app-store page. The kit's dropper builder can mimic Google Play, the Galaxy Store, and AppGallery, or build fully custom pages, complete with fake ratings, reviews, and download counts. The page coaxes the user into installing the app from outside the official store and approving its permissions. RedWing's capabilities include fake login screens (overlays) that appear over real banking and cryptocurrency apps to steal passwords, reading incoming texts for one-time passcodes, using Accessibility to lift codes off the screen, silently switching the victim's incoming calls over to the attacker using a hidden carrier code (21) to turn on call forwarding, live screen streaming and a keylogger, switching on the camera and microphone, reading files, stealing contacts and call logs, tracking location, and pooling infected phones to flood a target website with traffic (DDoS). Buyers choose their own targets. Zimperium counted 82 targeted institutions across several sectors, with a strong focus on Russian financial firms. The evidence points to the Russian market, with one sample using a fake page for Russia's RuStore. RedWing fits a wider move in Android crime toward on-device fraud, where attackers operate inside the victim's own banking session.
Big Brand Jobs Scam Targets Marketing Pros' Google Accounts
A job-recruiting-focused phishing campaign is abusing legitimate platforms and masquerading as major corporate brands to get marketing professionals to give up their Google credentials. The campaign poses as job recruiters looking to hire marketing professionals for major brands such as Coca-Cola, Louis Vuitton, McKinsey & Company, Netflix, OpenAI, and FIFA. The email addresses the individual by their name and the individual works in the relevant field, so the attackers likely did relevant research and collection. The campaign is notable because it uses legitimate platforms and several techniques, including nested redirects, to disguise the phishing links as trusted domains and avoid detection. An example phishing email purportedly from McKinsey & Company contains a view calendar & schedule call link for a fake job interview. The email is sent via PeopleForce, a cloud-based human resources management platform. When a targeted individual clicks the link, they are sent to a seemingly legitimate domain (mckinsey-careers.com in this example) that is actually an attacker-controlled phishing link. Victims are initially sent to a domain for ExactTarget, a Salesforce subsidiary, then immediately redirected to Wise Agent, a real estate-focused CRM platform, and then finally to the phishing site hosted on Netlify. The nested redirects through legitimate services are intended to install trust in the victim and can bypass basic web filters that only look at the domain in the first link (email filters). When an individual eventually lands on the phishing link, they are presented with a fake Google sign-in window, likely generated via the browser-in-the-browser (BitB) tactic, in which attackers craft a legitimate-looking pop-in window, complete with a valid looking URL, that in reality is just HTML built into the existing page. According to a URLScan.io analysis of the McKinsey & Company link, the domain was created June 29 and has been flagged as potentially malicious. The IP address for the domain has been flagged dozens of times over the last year for a variety of malicious activity. More than 30 malicious domains pose as corporate URLs, four of which are FIFA-related.
Fake IT Support on Microsoft Teams Coaxes Workers Into Installing Malware
Threat actors are posing as IT support on Microsoft Teams to trick workers into installing malware. The campaign leverages compromised or fake Teams accounts to send messages to employees, often claiming there is a security issue that requires immediate action. The messages direct users to click a link or download a file, which then installs malware on their system. This social engineering tactic exploits the trust employees place in internal IT communications and the urgency often associated with security alerts.
The Ghost in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI. In environments where AutoCertificateRollover is disabled and certificates are manually rotated, the database often becomes a ghost, a record that still exists, still decrypts successfully, but references a certificate no longer used for token signing by the ADFS service. During a recent red team engagement, Mandiant discovered that analysts followed the standard DKM extraction path, retrieving the encrypted blob from the WID database and decrypting it using the DKM material stored in Active Directory. The extraction succeeded, but the recovered certificate was no longer valid for token signing, and Entra ID rejected the resulting tokens with AADSTS500172 due to invalid signing material. Analysis revealed that AutoCertificateRollover had been disabled and a manual rotation had been performed. Confirmation was obtained directly via Get-AdfsProperties, which returned AutoCertificateRollover: False. While the ADFS service used a new valid key for signing, the WID configuration database was never updated to reflect the new certificate, leaving an expired ghost entry as the only record. This drift condition surfaces via Microsoft Event ID 385, which indicates certificate validity warnings in the ADFS service. Notably, this event self-resolves when AutoCertificateRollover is re-enabled and a subsequent certificate rollover is performed; in environments where it is disabled and manual rotation is performed without a corresponding database update, it is the observable symptom of this drift condition. ADFS maintains private keys in two protection contexts. In Location 1 (User DPAPI), encrypted key blobs may exist on disk, but the DPAPI protection is tied to the service account's SID and associated DPAPI masterkey material. The active signing key resides in the system's machine-scoped cryptographic store, protected by Windows Machine DPAPI and managed through the operating system's cryptographic subsystem. Successfully obtaining this active key allows an attacker to forge valid SAML assertions for any user, bypassing the need for user credentials and multi-factor authentication, and granting unauthorized access to any SAML-federated application including Microsoft 365 and Entra ID.
Microsoft Flips Windows Backup to On by Default Unless You're in the EU
Microsoft is enabling Windows Backup by default for new Windows installations outside the European Union. The feature automatically backs up user files, settings, and app preferences to OneDrive. The change does not apply to EU users due to regulatory concerns. The default-on behavior has raised privacy concerns, as users may not be aware that their data is being synced to Microsoft's cloud without explicit opt-in. The feature can be disabled in Settings, but the default-on behavior represents a shift in Microsoft's approach to cloud backups.
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password. Varonis found it and named it Rogue Agent. The flaw affected only organizations that built agents with Dialogflow's Playbooks and custom Code Blocks, which let developers add their own Python. Pulling it off needed the dialogflow.playbooks.update permission on one such agent, which limits the realistic attacker to a malicious insider or a compromised developer account. From that one foothold, the reach extended to every agent in the project. Dialogflow's Code Blocks let developers add custom Python to a chatbot's conversation flow. That code runs in a Google-managed Cloud Run environment, and every agent that uses Code Blocks in the same Google Cloud project shares one instance of it. Varonis found the file that wraps developer code, code_execution_env.py, sitting in the shared environment with write access. A single Code Block could replace it, downloading a modified code_execution_env.py from an attacker-controlled server and overwriting the original inside the running container. From then on, the attacker's version runs for every Code Block execution across every agent sharing that environment. The Code Block environment had unrestricted outbound internet access, bypassing VPC Service Controls. The environment exposed the Instance Metadata Service (IMDS), a normally internal endpoint that hands out cloud credentials. The overwrite happened inside Google's environment, where customers have no visibility, so detection was nearly impossible. Google has fixed it, and both Varonis and Google say there is no sign the flaw was ever used in a real attack.
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data (GitLost)
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones included, the issue can steer it into pulling private contents into a public comment. Noma Security calls the technique GitLost. The target is GitHub Agentic Workflows, a feature now in public preview that GitHub launched in February. Instead of writing automation scripts, you write instructions to an AI agent in plain English in a Markdown file. The agent reads issues and pull requests, runs tools, and replies on its own. Workflows are read-only by default, but an organization can hand one a token with read access across its repositories to give it cross-repo context, private ones included. The weakness is indirect prompt injection. An AI agent cannot reliably tell the difference between instructions from its owner and instructions hidden inside the content it happens to read. In Noma's proof of concept, the malicious issue was dressed up as a routine request from a VP of Sales after a customer meeting. The workflow was set to wake up when an issue is assigned, read the issue, and reply with a comment. It also had read access to the organization's other repos. Once a routine automation assigned the issue, the agent pulled a private repository's README and pasted it into a public comment on the issue. GitHub built guardrails to stop exactly this, but Noma reported that in its test, a one-word change (prefixing the malicious instruction with "Additionally") was enough to slip past. What sets GitLost apart is what the attacker gets to control. The agent is not a chat window but a credentialed actor sitting inside an organization's CI/CD-adjacent infrastructure, with read access spanning repos the attacker cannot see. It touches no server, needs no stolen credentials, and does not require write access to anything private. The attacker only has to open a public issue.
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, software supply chain security meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? In the roughly 20 months since the Model Context Protocol launched, AI tools, models, and the infrastructure around them have become load-bearing parts of how software gets built, deployed, and run. Code is written by agents. Packages are pulled in by autonomous tools that decide they are needed. Prompts have become a real input to the build, which means they are a real way to compromise it. The provenance question that has always defined supply chain security (where did this come from and can I trust it) now applies to the model, the agent, and the tooling, not only the artifact. An AI coding assistant suggests a dependency and a developer accepts it without the package ever crossing a human's threat model. An autonomous agent reaches for a tool over MCP to complete a task, and that tool reaches for another. A prompt, crafted by an attacker and planted somewhere the model will read it, steers what gets written or what gets pulled in. Validating AI-generated code before it's committed is table stakes. The harder problem is governing the agents doing the writing and the tools they call. The teams we work with aren't short on findings. They're drowning in them. Adding scan the AI output too to an already overloaded queue makes the alert pile taller, not the program stronger. Two things change when AI is genuinely in scope. First, lineage has to extend to everything entering the pipeline, including the models and agents. One approach is extending lineage to the pipeline itself, tracing activity, provenance, and configuration changes from first commit to runtime, and applying the same rigor to models and agents as to any other dependency. Second, prioritization has to be based on real exploitability, not volume. Correlating findings with runtime context with what's actually reachable is the difference between a vulnerability list and a workable chain of exploit. Gartner formalized this in June when it published the inaugural Magic Quadrant for Software Supply Chain Security.
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants (WriteOut)
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative AI platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Security Research team. An outsider could go from having no access to taking over any Writer AI agent. The flaw has been addressed, and no customer action is required.
CrowdStrike Uncovers New Prompt Injection Techniques
CrowdStrike has uncovered new prompt injection techniques that pose risks to AI systems. Details are limited in the available article content, but the finding suggests continued evolution in attack methods targeting AI models and agents.
Hydro-Québec Le Circuit Electrique Charging Station Backend (CVE-2026-20744, CVE-2026-42952, CVE-2026-44383)
The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. Previously, there was no throttling on repeated authentication attempts, which could allow a denial-of-service attack. Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend. Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems for certain charging stations still reliant on OCPP.
Hitachi Energy e-mesh EMS (CVE-2026-42945)
NGINX Plus and NGINX Open Source used in e-mesh EMS have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture with a replacement string that includes a question mark. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests, which may cause a heap buffer overflow in the NGINX worker process leading to a restart. Attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. e-mesh EMS versions using NGINX v1.30.0 and below are affected. EPSS score is 99th percentile.
Siemens SINEC OS (CVE-2025-6052, CVE-2025-7039, CVE-2025-1376, CVE-2025-1352, CVE-2025-6170, CVE-2025-6141)
SINEC OS before V4.0 contains multiple vulnerabilities in RUGGEDCOM RST2428P. Vulnerabilities include critical memory corruption in GNU elfutils, denial of service in elf_strptr, a flaw in GLib's GString memory management causing hidden overflow, a stack-based buffer overflow in GNU ncurses, and a flaw in xmllint that can cause crashes.
Hitachi Energy PROMOD V (CVE-2026-10763)
PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server. This could allow attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access.
Siemens Mendix Studio Pro (CVE-2026-48192)
Mendix Studio Pro versions before V11.12 are affected by a file parsing vulnerability that could be triggered when the application reads a specially crafted malicious project during the build pipeline. This could allow an attacker to execute arbitrary code in the context of that user. Affected versions include Mendix Studio Pro 10.11 through 10.24 (below 10.24.21) and 11.0 through 11.11 (11.6 below 11.6.7).
Labcenter Proteus 9 (CVE-2026-49033, CVE-2026-42953, CVE-2026-42958)
The application contains an out-of-bounds write vulnerability, a stack-based buffer overflow vulnerability, and a use-after-free vulnerability that can be exploited to cause memory corruption and execute arbitrary code while parsing specially crafted files.
Digi International PortServer TS, Digi One SP IA (CVE-2026-12948, CVE-2026-12352)
CVE-2026-12352 allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device. CVE-2026-12948 is a stored cross-site scripting (XSS) vulnerability in the web management interface that allows a remote, authenticated administrator to inject script into certain system configuration fields.
Today's stories show a consistent pattern: critical vulnerabilities are being exploited within hours or days of public disclosure, and AI integration into development workflows is creating new attack surfaces that traditional security controls don't address. The GhostLock Linux kernel flaw demonstrates that even decade-old code can harbor exploitable vulnerabilities that automated tools are only now finding. Meanwhile, device code phishing, malware-as-a-service platforms like RedWing, and prompt injection attacks against AI agents all point to threat actors exploiting trust relationships and legitimate authentication mechanisms rather than relying solely on traditional exploitation. Organizations need to compress patch cycles, extend supply chain security to include AI components, and train users to recognize social engineering that abuses trusted platforms and processes.