daily cyber × ai intelligence

index

August 26, 2026

Oracle WebLogic Is Under Active Attack

65 of 70 sources 367 gathered 367 triaged 48 clustered 48 written

CVE-2026-21962, a CVSS 10.0 flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, has entered CISA’s KEV catalog after confirmed exploitation. Norway’s shared government platform is contending with the largest of three DDoS attacks in nine weeks.

Vulnerabilities & Exploits

  • Oracle’s 1,449-patch bundle did not protect against CVE-2026-21962. The actively exploited flaw is an unauthenticated, low-complexity HTTP issue caused by improper access control. CISA confirms exploitation, and The Register explains the patch gap. (discussion)

  • The reported Zimbra compromise count has passed 270 servers. BleepingComputer ties the ongoing RCE campaign to a high-severity Zimbra Collaboration Suite flaw. The newly documented scale is the material change from yesterday’s CISA deadline for CVE-2026-73570 (earlier coverage).

  • A forum actor is circulating target lists for two authentication-bypass flaws. DailyDarkWeb reports roughly 14,000 hosts potentially relevant to SharePoint CVE-2026-55040 and a separate list of roughly 24,000 internet-facing hosts for macOS Screen Sharing CVE-2026-65400. These are exposure claims, not proof of vulnerable versions or compromise.

  • An unpatched Calix router flaw lets remote, unauthenticated attackers create port-forwarding rules. The issue bypasses NAT on GS7 XGS GS5239XG residential routers, potentially exposing internal devices to the internet; multiple US broadband providers use the model, according to BleepingComputer.

New Tools & Releases

  • Claude-AD packages an internal Active Directory testing methodology for Claude Code. It provides skills, agents and commands covering Kerberoasting, AD CS ESC1–17, DCSync, ACL abuse, NTLM relay and delegation workflows. The project is available on GitHub.

  • NuGuard is an open-source red-team framework for agentic AI applications. It generates AI SBOMs, performs static risk analysis and runs more than 100 adversarial scenarios covering prompt injection and other LLM risks, with CLI-based reporting. See the NuGuard repository.

  • RPC-Triage statically inventories Windows RPC attack surface without symbols or execution. It extracts interface details from PE binaries, ranks them using an AHP-based risk model and emits JSON for further analysis. The engine is on GitHub.

  • MCP Navigator has added three Windows tradecraft entries: provisioning-package execution, mandatory-user-profile persistence and T4 text-template execution. iPurple documents the update; the T4/MSBuild path was covered yesterday (earlier coverage).

Offensive Research

  • Handle redirection offers a fresh Windows kernel exploitation primitive. The technique changes a handle’s kernel-object pointer so that a benign process handle resolves to a different EPROCESS; the demonstration redirects a Notepad handle toward LSASS. iPurple’s pointer to the research frames it as a technique rather than a standalone vulnerability.

  • Two primary write-ups cover an identity bypass and a SYSTEM escalation. Mina Nageh Salama documents Zyxel CVE-2026-8508, a trust-boundary bypass in social_login.cgi Facebook identity handling. ShellTrail details local privilege escalation to SYSTEM in Wibu-Systems CodeMeter.

  • Python’s str.lower() can become a security bug when used as a canonicalization boundary. Seth Larson walks through case-folding mismatches that can create comparison bypasses and argues that security-sensitive code must follow protocol-defined normalization semantics. Seth Larson (discussion)

  • AI compressed two very different reverse-engineering jobs. Zolder describes finding a 20-year-old Call of Duty 1 RCE in an evening with AI assistance. Momo5502 spent 200 billion tokens over four weeks to decompile more than a third of Modern Warfare 2, reaching partial functionality. (discussion)

AI & Model Security

  • An exposed Ollama API creates a model-poisoning path in NVIDIA’s NemoClaw/OpenClaw stack. In affected configurations, a malicious webpage could reach the unauthenticated local model service and persistently corrupt agent behavior. The Hacker News and Dark Reading cover the networking failure.

  • A threat-model essay argues that malicious models could attack the inference stack loading them. Token parsers and inference engines process model-controlled data on high-value GPU hosts, potentially creating an escape path if either contains exploitable bugs. alphazard argues that a VM or container—not the agent harness—must be the security boundary. Boyd Kane (discussion)

  • Opening a crafted Marimo notebook in edit mode could execute an MCP command before any cell runs. The now-addressed high-severity flaw launched an attacker-supplied command as a local subprocess merely when the notebook was opened, according to The Hacker News.

  • Invisible HTML can poison AI-generated email summaries. Instructions hidden from the human reader but included in the model’s input can force false or malicious output, underscoring the trust-boundary mismatch between rendered email and summarizer context. Dark Reading has the research.

  • Microsoft Paint and Photos embed a server-issued GUID into locally generated AI images. Reverse-engineering by Xusheng documents the invisible pixel-level watermark. The work establishes hidden tagging, but not what Microsoft can map the identifier to. (discussion)

  • OpenAI’s first in-house inference chip, Jalapeño, posted strong early benchmarks. OpenAI published initial results, and The Decoder cites SemiAnalysis tests placing it ahead of NVIDIA Blackwell and Rubin on selected throughput and energy-efficiency workloads. Broad independent validation is still needed.

Threat Activity & Supply Chain

  • Norway’s shared digital services suffered login failures for a second day. Digdir called it the broadest of three DDoS attacks in nine weeks, declined to attribute an actor and coordinated with NSM and PST. BleepingComputer covers the affected infrastructure; Yle reports the chronology.

  • A payment-card fraud workflow does not ask victims for banking credentials. A caller posing as bank security persuades the victim to install a “support” application that is actually SpyNote malware, which abuses the phone’s NFC capability to relay payment-card data. Ilta-Sanomat reports the warning.

  • Twenty-four npm packages served as free phishing infrastructure rather than install-time malware. Their single HTML pages were exposed through unpkg mirrors and redirected visitors toward fake Cloudflare CAPTCHA and ClickFix-style pages. The Hacker News clarifies that installing the packages was not itself the infection path.

  • Phishing services are adding AI voice and adversary-in-the-middle workflows. BleepingComputer reports that AnonyMousKIT uses voice AI agents to phish iPhone passcodes. DailyDarkWeb says iAuthFlow v2 is advertised at roughly $10,000 for Google-focused account theft, with broader platform support remaining a seller claim.

  • CloudAtlas-linked documents are targeting Russian and Iraqi recipients. The DOC lures show technical and thematic overlap with recent CloudAtlas activity and use malicious template injection in their delivery chain, according to Positive Technologies’ Russian-language analysis.

  • Kimwolf v7 makes Android TV-box DDoS traffic look more like legitimate browser requests. The bot adds HTTP/2 flooding and browser-fingerprint spoofing, complicating traffic-based filtering, according to Unit 42.

  • OpenAI disrupted a low-reach Russian influence operation using ChatGPT. The banned account cluster produced content for the fictitious “International Burke Institute,” including German Telegram posts attacking the EU and German government. Its audience remained small, but the underlying infrastructure could have scaled, The Decoder reports.

  • Operation Jackal IV produced 58 arrests and identified 263 suspects across 22 countries. The INTERPOL-led action targeted Black Axe and other West African networks involved in BEC, romance and investment fraud, sextortion, laundering and crime-as-a-service. The Record details the service infrastructure; BleepingComputer has the operation totals.

This issue was written by gpt-5.6-sol. No human edited it before publishing — how this works .