CVE-2026-11856, CVE-2026-12064, CVE-2026-14191, CVE-2026-14355, CVE-2026-33017, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-38968, CVE-2026-38969, CVE-2026-48282, CVE-2026-48908, CVE-2026-50746, CVE-2026-50747, CVE-2026-50748, CVE-2026-53269, CVE-2026-53327, CVE-2026-53332, CVE-2026-53336, CVE-2026-53339, CVE-2026-53345, CVE-2026-53354, CVE-2026-53359, CVE-2026-54400, CVE-2026-54402, CVE-2026-54908, CVE-2026-55115, CVE-2026-55116, CVE-2026-55255, CVE-2026-55999, CVE-2026-56000, CVE-2026-56001, CVE-2026-56002, CVE-2026-56290, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002, CVE-2026-8925, CVE-2026-9079, CVE-2026-9547
Get tomorrow's brief in your inbox
Today: CISA adds five exploited vulnerabilities to KEV catalog with a July 10 deadline, including critical 10/10 flaws in Adobe ColdFusion and two Joomla extensions already under active attack. GodDamn ransomware is abusing a Microsoft-signed malicious driver to disable endpoint security before deployment. Ubiquiti patches 10 critical flaws across UniFi product line.
CISA KEV: Five Exploited Vulnerabilities with July 10 Deadline
CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on July 8, requiring federal agencies to patch within three days. The most critical are CVE-2026-48282 (Adobe ColdFusion path traversal, CVSS 10.0, EPSS 3.2%), CVE-2026-48908 (SP Page Builder for Joomla RCE, CVSS 10.0, EPSS 1.4%), and CVE-2026-56290 (Page Builder CK for Joomla arbitrary file upload, CVSS 10.0, EPSS 0.7%). Both Joomla bugs allow unauthenticated remote code execution. CVE-2026-48908 enables attackers to upload PHP to the web root via an unauthenticated icon upload feature, and threat actors have used it to plant hidden admin accounts and PHP file manager backdoors. CVE-2026-56290 was patched June 27 and exploited within hours to deploy web shells. CVE-2026-55255 (Langflow cross-tenant IDOR, CVSS 9.9, EPSS 0.4%) allows attackers to execute flows belonging to other users. Sysdig observed it chained with CVE-2026-33017 (Langflow RCE, patched March, EPSS 98.4%, CISA KEV due April 8) for reconnaissance and flow ID harvesting.
GodDamn Ransomware Uses Microsoft-Signed Malicious Driver to Kill Security Tools
Hyadina ransomware group (formerly Beast and Monster lockers) deployed a Microsoft-signed kernel driver called PoisonX to disable endpoint security before deploying its new GodDamn locker. Symantec observed the campaign against a US organization starting May 29 with AnyDesk RMM dropped in a Music folder. On May 30, attackers deployed PoisonX (published to GitHub April 7 by user "oxfemale" as a "research tool"), which killed security processes and removed user-mode API hooks. The attacker then used 14 open-source credential stealers (13 from NirSoft, plus Mimikatz) targeting browsers, email, instant messengers, Wi-Fi, and network traffic. Hyadina moved laterally via PsExec before ransomware deployment. Targets include healthcare, manufacturing, and education sectors. Hyadina avoids former Soviet countries. PoisonX gained a legitimate Hardware Compatibility signature from Microsoft despite having no legitimate use case.
6 claims tracked from crpx0 group on July 8. These are unverified claims from ransomware leak sites.
| Group | Victim | Sector | Country |
|---|---|---|---|
| crpx0 | Creative Smiles Pediatric Dentistry | Healthcare | US |
| crpx0 | AMHWA Biopharm Co., Ltd. | Pharmaceuticals | Unknown |
| crpx0 | SF Smile Doctor | Healthcare | US |
| crpx0 | Bishop Arts Dental PLLC | Healthcare | US |
| crpx0 | Top Notch Dentistry of Dallas | Healthcare | US |
| crpx0 | Benjamin H. Wang DDS Inc. | Healthcare | US |
Healthcare Corporations Face Class Action Lawsuits Over Data Breaches and PII Sharing
Three Jane Doe plaintiffs filed suit against CareNow (owned by HCA Healthcare) in Davidson County Circuit Court on June 11. The complaint alleges CareNow divulged patient PII to Google and third-party marketing companies via tracking technologies embedded in online appointment scheduling. HCA Healthcare is Nashville's second-largest employer and operates more than 20 urgent care centers across Middle Tennessee. The lawsuit is part of a broader wave of class actions targeting healthcare corporations for exposing or leaking PII and PHI.
Ubiquiti Patches 10 Critical Flaws Across UniFi Product Line
Ubiquiti released patches for 10 vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS. Seven are rated critical (9.0-10.0 CVSS). CVE-2026-50746 (UniFi Connect, CVSS 10.0, EPSS 0.8%) allows unauthenticated command injection on the host. CVE-2026-50747 (UniFi Talk, CVSS 9.9) is an authenticated SQL injection leading to privilege escalation. CVE-2026-50748 (UniFi Access, CVSS 9.9, EPSS 0.8%) is an input validation flaw enabling command injection. CVE-2026-54400 (UniFi Access, CVSS 9.1) is an access control issue allowing privilege escalation. CVE-2026-55115 (UniFi Protect, CVSS 9.9) is an SSRF flaw enabling privilege escalation. CVE-2026-54402 and CVE-2026-55116 (UniFi OS, CVSS 9.9 and 9.0) allow command injection and unauthorized device changes. No evidence of exploitation yet, but three older UniFi OS CVEs (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) were added to CISA KEV last month after being exploited by Russian state actors. Compromised Ubiquiti routers have been enlisted into the MooBot botnet.
HalluSquatting: AI Coding Assistants Can Be Tricked Into Installing Botnet Malware
Researchers at Tel Aviv University and Technion discovered a new supply chain attack called HalluSquatting that exploits AI coding assistant hallucinations. When asked to fetch a trending repository or plugin not in the training data, AI assistants consistently hallucinate fake package names. Attackers can register those names, embed adversarial instructions in the repository, and wait for assistants to fetch the malicious version. Indirect prompt injection in the fetched content hijacks the assistant, which then uses its built-in terminal tool to run attacker commands. In testing, the fake name consistency rate was up to 85% for repositories and 100% for skill installs across Cursor, Windsurf, GitHub Copilot, Cline, Google Gemini CLI, and OpenClaw. The attack does not rely on exploits, passwords, or worming, and is cross-platform. The payload is text the AI interprets, not network traffic a firewall can inspect. Ben Nassi's group previously built a self-spreading AI email worm and a calendar invite that hijacked Gemini.
Felons and Fraudsters Operate Offensive Cybersecurity Startup IRIS C2
IRIS C2, a McLean, Virginia-based startup claiming to acquire zero-day exploits for $10,000 to $7 million, is operated by Jack Burkman and Jacob Wohl. Both are convicted felons with a history of fake intelligence companies and disinformation campaigns. Wohl and Burkman were prosecuted for robocalls suppressing Black votes in Detroit (15 felony counts, sentenced to probation), pleaded guilty to telecommunications fraud in Ohio (2022), and were fined $5.1 million by the FCC (largest TCPA fine at the time). They fabricated sexual assault claims against Robert Mueller and Pete Buttigieg, and spread false claims about Elizabeth Warren and Kamala Harris. IRIS C2 operates under Calvexa Group LLC. G2Exchange shows Calvexa registered as a federal contractor but has no active government contracts. The company claims to hire junior engineers with raw talent and no degree requirement.
Microsoft Deploys AI System to Proactively Harden Cloud Infrastructure
Microsoft built a multi-agent AI system to evaluate its cloud services against Secure Future Initiative (SFI) security requirements. The system uses orchestration agents, analysis agents grounded in threat intelligence, and evidence-gathering agents that investigate code, infrastructure definitions, identity configurations, and runtime states. It profiles service architectures, enumerates applicable security controls, verifies implementations, evaluates defense-in-depth coverage, identifies gaps, and produces compensating control analysis. The system compresses weeks of manual security reviews into hours. Microsoft emphasizes that vulnerabilities emerge from the interplay of code, configuration, deployment, and connectivity, not just code alone. The system is internal and not available as a product, but insights will inform future Microsoft offerings. It complements codename MDASH (code-level vulnerability scanning) by adding configuration, identity, network, and runtime context.
Account Takeover Attacks Shift to Verification and Recovery Layers as Passkeys Block Primary Login
Passkeys are now deployed by 75% of global consumers (FIDO Alliance 2026 research) and 68% of companies, making credential stuffing less effective. Attackers are relocating to identity verification and recovery flows: account recovery, device re-enrollment, step-up verification, and magic link interception. Veriff's 2026 Fraud Industry Pulse Survey (1,200 respondents) reports a broad rise in impersonation fraud, malware, authorized fraud, and document fraud. Veriff's Identity Fraud Report 2026 found 4.18% of verification attempts fraudulent, with digitally presented media 300% more likely to be AI-generated or altered. Impersonation accounts for 85%+ of fraud attacks. Magic link interception via unverified mobile deep links, compromised inboxes, and SIM swaps is now a primary ATO vector. Defensive trends include intent binding (cryptographically linking verified human actions to authorized transactions), network-effect fraud pattern detection across millions of sessions, and rising regulatory baselines.
OpenSSH 10.4 Patches Seven Flaws Affecting sshd, sftp, scp, and ssh Client
OpenSSH released version 10.4 addressing seven vulnerabilities. CVE-2026-60000 (EPSS 0.3%) allows remote DoS via excessive authentication attempts due to mishandled MaxAuthTries for GSSAPIAuthentication. CVE-2026-59997 (EPSS 0.2%) causes internal-sftp to recognize only the first 9 command-line arguments, potentially breaking security configurations. CVE-2026-59996 (EPSS 0.2%) allows scp to place files in parent directories during remote-to-remote copies. CVE-2026-59995 (EPSS 0.2%) allows sftp to download files outside intended directories when using attacker-controlled servers. CVE-2026-60001 (EPSS 0.3%) causes sshd to not honor minimum authentication delay. CVE-2026-59999 (EPSS 0.1%) allows PermitTunnel=yes to override DisableForwarding=yes. CVE-2026-60002 (EPSS 0.3%) causes a use-after-free in the ssh client when a server changes its host key during re-exchange.
WinRAR RAR5 Recovery Volume Heap Overflow (CVE-2026-14191)
CVE-2026-14191 is an out-of-bounds heap write in WinRAR and UnRAR RAR5 recovery volume (.rev) handling in RecVolumes5::ReadHeader. No CVSS score or exploitation status published.
X.Org Server and libXfont2 Memory Corruption Flaws
CVE-2026-56000 (EPSS 0.2%) is a use-after-free in xorg-x11-server and xwayland GLX contextTags in CommonMakeCurrent(). CVE-2026-55999 is a heap buffer overflow in glamor font atlas. CVE-2026-56002 (EPSS 0.5%) is a heap buffer overflow in libXfont2 PCF font parsing. CVE-2026-56001 is an integer overflow leading to heap buffer overflow in BitmapScaleBitmaps.
PHP AES-WRAP-PAD Memory Corruption (CVE-2026-14355)
CVE-2026-14355 (EPSS 0.3%) is a memory corruption in ext/openssl openssl_encrypt with AES-WRAP-PAD.
Linux Kernel Vulnerabilities
CVE-2026-53359 (KVM x86 shadow paging use-after-free, EPSS 0.2%), CVE-2026-53354 (ARM64 TLBI errata mitigation, EPSS 0.2%), CVE-2026-53345 (KVM vCPU dirty memory WARN, EPSS 0.2%), CVE-2026-53332 (slimbus qcom-ngd-ctrl race condition, EPSS 0.2%), CVE-2026-53336 (nvmem onie-tlv hang, EPSS 0.2%), CVE-2026-53327 (debugobjects pi_blocked_on, EPSS 0.2%), CVE-2026-53339 (i2c qcom-cci NULL pointer dereference), CVE-2026-53269 (netfilter synproxy mutex).
Miscellaneous CVEs
CVE-2026-54908 (Pion DTLS DoS via panic, EPSS 0.3%), CVE-2026-9079 (stale proxy password leak, EPSS 0.8%), CVE-2026-9547 (SSH improper host validation, EPSS 0.4%), CVE-2026-11856 (cross-origin Digest auth state leak, EPSS 0.8%), CVE-2026-8925 (SASL double-free, EPSS 0.8%), CVE-2026-12064 (proto-default skips SSH verification), CVE-2026-38968 (ntopng predictable session identifier, CVSS not scored, EPSS 0.4%), CVE-2026-38969 (Ruby webrick request smuggling via trailer Content-Length, EPSS 0.3%).
Today's brief highlights the continued erosion of trust boundaries in software supply chains and authentication systems. CISA's aggressive KEV additions reflect the weaponization speed of newly disclosed vulnerabilities, with Joomla extensions exploited within hours of patch release. The GodDamn ransomware campaign demonstrates that signed code is no longer a reliable security indicator when malicious developers can obtain legitimate signatures. HalluSquatting reveals that AI-assisted development introduces a new class of supply chain risk where model hallucinations become exploitable attack surfaces. Finally, the shift from credential stuffing to verification layer attacks shows that hardening one control simply moves adversaries to the next weakest link rather than stopping them entirely.