daily cyber × ai intelligence

index

tagged

[microsoft-exchange]

2 editions

August 15, 2026

A Heavy Day for Exploit Research and In-the-Wild N-Days

Citrix NetScaler CVE-2026-8452, VMware vCenter critical auth-bypass and VMXNET3 flaws, and SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) are all under active exploitation in enterprise environments. GeoServer, Exchange Server, PostGIS, and Ruby 4.0 join a heavy wave of zero-day and n-day research, while autonomous AI agents weaponized against critical infrastructure and a guardrail bypass in production Claude deployments expose new attack surfaces. Clop ransomware targeted Shell and Philips likely via PTC Windchill, and ShinyHunters breached RingCentral for 1.6 million accounts; Anthropic's new watermark-detection API for Claude faced immediate circumvention attempts.

June 26, 2026

Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine

Gaslight, a Rust-based macOS stealer, is the first malware documented to embed prompt-injection payloads designed to sabotage AI-assisted malware analysis. ESET published a detailed breakdown of Gamaredon's 2025 arsenal, revealing six new PowerShell downloaders and extensive infrastructure laundering targeting Ukrainian government and military entities. Multiple critical vulnerabilities are being actively exploited, including CVE-2025-52465 in GeoServer for credential theft and CVE-2026-8461 in FFmpeg for remote code execution. curl patched a 24-year-old credential-leak vulnerability (CVE-2026-9079) alongside four additional flaws affecting SSH, STARTTLS, and proxy authentication.