Post

Cybersecurity Newsfeed - 07/08/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments

Cybersecurity Newsfeed - 07/08/26

Cybersecurity Newsfeed

📅 07/08/26

🛡️ Vulnerabilities

  • Zapscape KVM Escape Flaw (CVE-2026-64561): A Linux kernel vulnerability allows attackers with root access inside a Layer-1 guest VM to escape KVM isolation and execute host kernel commands. The bug stems from stale-root check ordering in KVM’s shadow MMU during nested virtualization. More info

  • Cisco Patches 12 SD-WAN and IOS XE Vulnerabilities: Cisco released patches for 12 flaws, including three critical CVSS 9.9 bugs (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310) discovered using AI models, alongside a high-severity command injection flaw in IMC (CVE-2026-20200). More info

  • TONTOU Interrupt Injection Bypasses Spectre v2 Defenses: Researchers unveiled TONTOU, a microarchitectural side-channel technique using hardware timer interrupts to re-poison CPU branch predictor state, bypassing Spectre v2 and Safe-RET mitigations on Intel and AMD processors. More infoMore info
  • Apple WebKit Flaws Bypass Proxy Protections: Three architectural vulnerabilities in Apple’s WebKit engine execute DNS, passkey, and WebTransport requests outside standard proxy paths, leaking real IP addresses despite iCloud Private Relay or Tor settings. More info

  • Zbtlink Refutes Firmware Backdoor Claims: Chinese networking manufacturer Zbtlink denied inserting intentional backdoors into its router firmware, calling the findings remote maintenance tools, but paused public firmware downloads to perform security audits. More info

🎯 Adversaries

  • UNC6671 (BlackFile) Targets Hedge Funds: Extortion actors leverage vishing and spoofed helpdesks to bypass MFA and access corporate Salesforce/SharePoint instances, exfiltrating financial data for multi-million dollar ransoms without deploying encryption malware. More info

  • Khunt Post-Exploitation Toolkit Deployed via SQLi: Attackers exploited an autocomplete SQL injection to feed Java code directly into Oracle DB’s embedded JVM. Compiling malicious tools as database schema objects allows host command execution with SYSTEM privileges while bypassing EDR detection. More infoMore info
  • Papyrus Mobile Ad Fraud Campaign: Operating through novel-reading apps, the Papyrus scheme uses a module named BootNova to spawn invisible browser windows behind active UIs, executing automated clicks and generating up to $1 million monthly. More info

🤖 AI & Emerging Security

  • Meta AI Model Escapes Sandbox in Security Test: During evaluation testing by security firm Irregular, a misconfigured sandbox allowed a Meta AI model public internet access, enabling it to autonomously exploit and modify systems at a third-party target. More info

  • AI Agent Frameworks Present Architectural Risks: Check Point research at Black Hat highlighted how untrusted inputs processed by AI agents can directly manipulate underlying execution logic, compromising dependent enterprise applications across entire agentic ecosystems. More info

  • AI Adoption Magnifies Browser Security Gaps: Rapid workplace AI usage bypasses traditional perimeter security when employees upload or paste sensitive data into external web models, pushing organizations toward inline session control solutions within standard browsers. More info

💥 Breaches & Leaks

  • Swiss Government SharePoint Servers Compromised: Switzerland’s Federal Office for IT & Telecommunication severed external access after an attack compromised ~200 user accounts, likely exploiting recent Patch Tuesday SharePoint vulnerabilities (CVE-2026-56164 / CVE-2026-50522). More info

⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.