CVE-2024-28224, CVE-2026-15981, CVE-2026-18965, CVE-2026-58115, CVE-2026-59769, CVE-2026-60004, CVE-2026-61979, CVE-2026-67560, CVE-2026-67578, CVE-2026-68967, CVE-2026-71187, CVE-2026-71396, CVE-2026-73125, CVE-2026-73809, CVE-2026-73839, CVE-2026-75960, CVE-2026-76060, CVE-2026-76179
IP Addresses:
169.254.169.254, 0.0.0.0, 1.1.1.1, 8.8.8.8
Get tomorrow's brief in your inbox
Today: CISA adds actively exploited Gitea RCE to KEV catalog with a Thursday patch deadline. Multiple ICS vendors ship critical authentication bypasses affecting industrial gateways and vehicle brake systems. U.S. sanctions five Iranian MOIS-linked hackers behind years of critical infrastructure breaches and cryptocurrency theft.
Critical Gitea RCE Actively Exploited as CISA Issues Patch Deadline (CVE-2026-60004)
CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting a critical remote code execution flaw in Gitea with a CVSS score of 9.8. The vulnerability allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the Gitea OS user by abusing the diffpatch endpoint to install and execute a Git hook. With default open registration enabled, unauthenticated visitors can create accounts and trigger the exploit. At least one documented attack deployed a cryptocurrency miner-like payload after the dropper killed competing processes and fetched architecture-specific binaries. The flaw affects all Gitea versions from 1.17 onward.
NVIDIA NemoClaw Local AI Model Poisoning via DNS Rebinding (No CVE)
Oasis Security disclosed that NVIDIA NemoClaw's Ollama configuration on Windows and WSL binds the model server to 0.0.0.0:11434 without authentication, allowing attackers to use DNS rebinding to take control of local AI instances and inject hidden instructions into chat templates. The poisoned instructions persist across conversations and survive agent restarts. NemoClaw v0.0.35 fixed the issue on macOS and Linux; Windows installations in v0.0.34 carry a warning but no fix. The attack leverages the same DNS rebinding technique patched in Ollama v0.1.29 (CVE-2024-28224) in March 2024, but NemoClaw skips Host header validation when bound to non-loopback addresses.
SLEEPWALKER Backdoor Uses Custom 23-Instruction Language and Network Trigger Packets
An independent researcher documented SLEEPWALKER, an unsigned 64-bit Windows DLL backdoor that side-loads into ESET Management Agent (ERAAgent.exe) and waits for a specifically crafted network packet before executing commands in a custom 23-instruction bytecode language. The backdoor monitors every network interface in promiscuous mode, capturing all traffic including packets destined for other machines, making gateways and VPN servers potential monitoring points. It supports six transports including VMware VMCI for hypervisor-level persistence similar to UNC3886 tactics. The sample contains no domains, IPs, or URLs and makes no outbound connections, evading infrastructure-based detection. Attribution, deployment method, and victim details remain unknown.
Fake Apple Support AI Voice Calls Target Stolen Device Owners (AnonyMousKIT PhaaS)
SOCRadar disclosed AnonyMousKIT, a phishing-as-a-service platform targeting owners of stolen Apple devices using AI voice agents that impersonate Apple Support and request device passcodes, Apple ID credentials, and live 2FA codes to remove Activation Lock. The platform operates on a credit-metered system with five attack channels: email (1.50 credits), SMS (varies by sender ID), WhatsApp, recorded voice (1 credit), and AI voice agents (2 credits). Between August 2025 and May 2026, operators made 200 AI voice calls at $0.096 each, with 179 targeting Brazil. Lures cite the device's internal Apple model identifier and live Find My status pulled from the stolen hardware. The platform uses commercial voice service Vapi with five configured personas named "Alice from Apple Support."
Coordinated MyChart Phishing Targets Epic Patient Portal Passwords
Multiple health systems across the U.S. issued alerts warning patients about coordinated phishing messages attempting to steal credentials for Epic Systems' MyChart patient portal. The effort appears coordinated by a single threat actor or group targeting Epic's widely deployed patient portal system used by hundreds of hospitals and health systems nationwide.
Microsoft Publishes Patch Window Collapse Analysis and Control Plane Recommendations
Microsoft published analysis on the collapsing patch window between vulnerability disclosure and exploitation, arguing that AI tools are accelerating offensive timelines while defensive patching processes remain unchanged. The post advocates for a "new control plane" approach beyond traditional patch-test-deploy cycles, though specific product recommendations are unclear. The analysis notes that vulnerabilities announced in the morning can face active scanning and exploitation by afternoon while enterprise validation and deployment still require days or weeks.
Russia Begins Blocking DNS-over-HTTPS and DNS-over-TLS Servers
Russian internet users reported widespread blocks of DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) servers including Cloudflare's 1.1.1.1 and Google's 8.8.8.8, suggesting the government implemented previously announced plans to block protocols that hide users' intended destinations. The blocks appear across multiple regions though Roskomnadzor has not confirmed official action. Russia tested similar blocks on Beeline's network in March 2026 and announced plans to block DoH in 2021, before tightening internet controls following the Ukraine invasion.
INTERPOL Operation Jackal IV Arrests 58 in West African Cybercrime Crackdown
INTERPOL's eight-month Operation Jackal IV resulted in 58 arrests and identified 263 suspects linked to West African organized crime groups including Black Axe. The operation spanned 22 countries and targeted crime-as-a-service networks providing domains and money laundering support. Highlights include dismantling a Romanian call center investment scam that stole €143 million, seizing $2.67 million in South Africa from syndicates running romance scams against retirees, and identifying 196 individuals in Argentina linked to a major CaaS network. Previous Jackal operations arrested hundreds and seized millions in assets targeting African financial crime networks.
U.S. Sanctions Five Iranian MOIS-Linked Hackers Behind Infrastructure Breaches
The Treasury Department sanctioned five Iranian cyber actors affiliated with Iran's Ministry of Intelligence and Security (MOIS) as part of Operation Economic Outcast. The individuals, linked to the Tehran-based Mabna Institute, conducted widespread compromises of U.S. critical infrastructure since late 2023 targeting energy, defense, healthcare, IT, and financial sectors. Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i conducted the bulk of network compromises and data exfiltration. Arman Kahzadian focused on cryptocurrency heists including a $30,000 Bitcoin wallet theft. TRM Labs identified $16.8 million in total funds across 30 wallets linked to the five actors.
CISA Red Team Assessment Shows Detection Gap Between Two Organizations
CISA released a cybersecurity advisory comparing two simultaneous red team assessments using identical tactics. Organization A failed to detect initial compromise, privilege escalation, lateral movement to sensitive business systems, and cloud resource access. Organization B detected the initial compromise and quarantined affected systems, forcing the red team to adopt an assume-breach model where defenders again detected activity in the OT DMZ bastion host and isolated it. The assessment demonstrates the critical importance of early detection and response capabilities.
Q2 2026 Vulnerability Registrations Reach Unprecedented Levels
Kaspersky reports that CVE registrations in Q2 2026 reached unprecedented levels driven by widespread AI adoption for application development and vulnerability research. AI tools helped discover entire new vulnerability classes, particularly in the Linux networking subsystem including the Dirty Frag series. Security researchers increasingly published exploits for unpatched vulnerabilities. A researcher named Nightmare Eclipse published fully functional exploits for Windows Defender vulnerabilities BlueHammer and RedSun before CVE registration, setting a new precedent for disclosure without waiting for patches.
Cybersecurity Affordability Crisis Threatens Small Businesses and Supply Chains
The global average data breach cost reached a record $4.99 million in 2025, up 12% year-over-year to $1,100 per hour, while global cybersecurity spending is projected to hit $239.8 billion in 2026. Small-to-medium businesses face disproportionate risk as venture-backed security vendors prioritize enterprise customers with expensive products that don't account for SMBs lacking dedicated security teams or 24/7 SOCs. The affordability gap creates systemic supply chain risks as millions of under-protected small businesses become weak links.
Siemens SIMATIC IoT2050 Advanced Missing Authentication (CVE-2026-58115)
SIEMENS SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain missing authentication in the Node-RED HTTP interface allowing unauthenticated remote code execution with maximum privileges. Affects all versions before v4.3.4.1. Siemens released updates and recommends hardening or uninstalling Node-RED.
Ebyte NE2-D11 Gateway Multiple Authentication Bypasses (6 CVEs)
Ebyte NE2-D11 industrial gateway firmware FW-9167-0-11 contains six vulnerabilities including missing authentication (CVE-2026-73125), cleartext credential transmission (CVE-2026-73809), plaintext credential exposure (CVE-2026-73839), client-side authentication bypass (CVE-2026-71187), and improper session token protection (CVE-2026-76179). Combined, the flaws allow unauthenticated attackers to access sensitive configuration data, modify device settings, hijack sessions, and disrupt operations. Ebyte acknowledged the vulnerabilities and indicated a patch was under development but has not responded to coordination requests.
Bendix EC80 Brake ECU Stack Overflow and Out-of-Bounds Write (3 CVEs)
Bendix EC80ESP brake ECUs contain a stack-based buffer overflow (CVE-2026-67560) and out-of-bounds write (CVE-2026-68967) allowing attackers to crash the ECU, remotely execute code, or inject arbitrary CAN bus traffic. Successful exploitation could disable ABS functions, steering assist, speedometer, shifting capabilities, and automatic traction control. Affects 11 product variants across firmware versions Z228999, Z266494, and Z286098.
WordPress MiniOrange SAML SSO Plugin Authentication Bypass (CVE-2026-61979, CVE-2026-15981)
MiniOrange SAML 2.0 Single Sign-On plugin for WordPress contains two critical authentication bypass vulnerabilities allowing unauthenticated attackers to log in as any user including administrators. Affects 10,000+ WordPress sites using the free edition plus unknown numbers using paid/enterprise versions. The developer patched all affected versions but did not warn users, listed fixes as bugfixes rather than security patches, and used different versioning for paid editions making it difficult to determine patch status. Free edition patched in v5.4.5. Attackers are exploiting the flaws in opportunistic campaigns.
ZoneMinder Authenticated OS Command Injection (CVE-2026-76060)
ZoneMinder versions 1.37.48 and 1.38.3 contain an authenticated OS command injection vulnerability in event export functionality. The exportFile HTTP request parameter passes unsanitized input into PHP exec() allowing any authenticated user with View Events permission to execute arbitrary OS commands as the web server user.
FURUNO FA-50 AIS Transponder Hardcoded Credentials (CVE-2026-59769, CVE-2026-67578)
FURUNO FA-50 Class B AIS Transponder (discontinued October 2020) contains hardcoded credentials (CVE-2026-59769) and missing authentication (CVE-2026-67578) allowing attackers with network access to alter device settings. FURUNO notes production ended and software updates will no longer be provided. Mitigation relies on physical security and network isolation.
PayRange API Missing Authorization (CVE-2026-18965)
PayRange API contains missing authorization on management endpoints exposing verbose details of every device on the PayRange network with or without authentication. PayRange has not responded to coordination requests. The vulnerability affects payment kiosks in laundromats, vending machines, and other commercial facilities.
Rently Smart Home Credential Protection Weakness (CVE-2026-75960)
Rently Smart Home versions 20.1.0 and earlier contain insufficiently protected credentials allowing attackers to retrieve PINs including the Master PIN and override standard user permissions. Rently patched the vulnerability in late June with no user action required.
Today's threat landscape shows a clear acceleration in the time between disclosure and exploitation, with AI tools lowering the barrier for attackers while defensive patch cycles remain unchanged. The Gitea KEV addition highlights this compression with active exploitation before widespread awareness. Industrial and IoT devices continue showing fundamental authentication failures that should have been caught in security reviews years ago. The Iranian MOIS sanctions reveal years of undetected critical infrastructure breaches, underscoring persistent detection gaps even in defended environments.