Press "Enter" to skip to content

OSINT / CyberSec report 03.07.2026 00:08

1. CISA added the critical SharePoint remote code execution vulnerability CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News).

2. Security researchers identified the first end-to-end ransomware attack executed by an AI agent, which exploited a Langflow remote code execution flaw to encrypt a production database (The Hacker News).

3. The FortiBleed campaign, which compromised 75000 Fortinet firewalls, has been linked to the INC and Lynx ransomware groups for follow-on network intrusions (The Hacker News).

4. A new information-stealing trojan named ChocoPoC is being distributed via fake proof-of-concept exploit repositories on GitHub to target vulnerability researchers (The Hacker News).

5. A 19-year-old suspect associated with the Scattered Spider hacking collective has been extradited from Finland to the United States to face computer intrusion and fraud charges (The Hacker News).

6. Medtronic is notifying customers of a data breach involving the unauthorized exposure of personal information by the ShinyHunters group (BleepingComputer).

7. Progress Kemp LoadMaster is facing active exploitation attempts targeting a critical pre-authentication remote code execution flaw tracked as CVE-2026-8037 (The Hacker News).

8. Adobe released patches for seven maximum-severity vulnerabilities in ColdFusion and Campaign Classic that could lead to arbitrary code execution (The Hacker News).

9. Two critical vulnerabilities in the Cursor AI code editor, collectively named DuneSlide, allow attackers to escape the sandbox and execute arbitrary commands on developer machines (The Hacker News).

10. An unpatched remote code execution flaw in the Argo CD repo-server component poses a risk of full Kubernetes cluster takeover (The Hacker News).

11. A massive password-spraying campaign targeting Microsoft 365 environments generated over 81 million login attempts within a two-week period (BleepingComputer).

12. Over 900 instances of Oracle E-Business Suite remain exposed online while being actively targeted by attackers exploiting a critical security flaw (BleepingComputer).

13. The Department of Homeland Security is investigating a breach of the Homeland Security Information Network, a platform used for sensitive information sharing (BleepingComputer).

14. A new malware delivery chain dubbed VEIL#DROP uses social engineering on Blogger pages to distribute the PureLogs information stealer (The Hacker News).

15. A campaign distributing AsyncRAT is leveraging SEO-poisoned websites to trick users into downloading malicious installers masquerading as legitimate software (The Hacker News).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *