daily cyber × ai intelligence

index

tagged

[bootrom-exploit]

2 editions · 1 item

July 15, 2026

Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days

Microsoft shipped a record 622 CVEs in July 2026, with two already under active exploitation in Active Directory and SharePoint, prompting immediate patching guidance. ESET identified 11 forgotten Microsoft-signed UEFI bootkit shims that bypass Secure Boot and survive OS reinstalls, enabling persistent firmware-level attacks. A jailbroken Gemini was exploited by a Russian fraudster to deploy a working C2 server and credential-stealing botnet in six minutes, demonstrating AI's collapsing timeline for attack infrastructure deployment. Cursor IDE has an unpatched arbitrary-code-execution flaw allowing malicious repositories to auto-execute code, and xAI's Grok Build CLI exfiltrated entire Git repositories to Google Cloud storage before uploads stopped.

June 22, 2026

  • usbliter8, a novel BootROM/SecureROM exploit for Apple A12/A13 chips (iPhone XS, iPhone 11, Apple Watch 4/5, HomePod mini), was disclosed with a public PoC — the first unpatchable hardware-level iPhone exploit in six years. It chains a USB-controller hardware bug with a firmware configuration flaw to achieve application-processor boot-chain compromise; physical access plus a Raspberry Pi are required, and there is no software fix. Paradigm Shift writeup, PoC, CyberInsider. · Offensive & Red Team

in Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR