Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-07-24 11:02 UTC
Articles: 96 · Sources: 8
Auto-refresh: 15m

🌍 Global Ransomware Heatmap 2248 victims · last 90d · top: US

Critical CVEs & Vulnerabilities 18 items

The Hacker News2026-07-24 06:58 UTC
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying…
The Hacker News2026-07-23 18:36 UTC
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening…
SecurityWeek2026-07-23 09:06 UTC
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek .
CISA KEV2026-07-21 00:00 UTC
Added to KEV 2026-07-21. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-21 00:00 UTC
Added to KEV 2026-07-21. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-21 00:00 UTC
Added to KEV 2026-07-21. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-15 00:00 UTC
Added to KEV 2026-07-15. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
Krebs on Security2026-07-14 19:22 UTC
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to…
CISA KEV2026-07-14 00:00 UTC
Added to KEV 2026-07-14. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…

Active Threats & Malware 18 items

The Hacker News2026-07-24 10:09 UTC
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg,…
The Hacker News2026-07-24 06:50 UTC
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group…
Bleeping Computer2026-07-23 21:20 UTC
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]
Bleeping Computer2026-07-23 16:49 UTC
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]
Bleeping Computer2026-07-23 16:32 UTC
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. [...]
The Hacker News2026-07-23 13:11 UTC
The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and…
SecurityWeek2026-07-23 12:42 UTC
SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot. The post Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models appeared first on SecurityWeek .
The Hacker News2026-07-23 12:20 UTC
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April…
The Hacker News2026-07-23 11:28 UTC
Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with…

Data Breaches 6 items

Krebs on Security2026-07-13 15:03 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps…

Nation State Activity 1 items

Tools & Research 18 items

The Hacker News2026-07-24 10:15 UTC
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through the ministry's network on its own,…
The Hacker News2026-07-24 07:41 UTC
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and…
The Hacker News2026-07-23 15:02 UTC
Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and…
SecurityWeek2026-07-23 15:00 UTC
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. The post Is Patching Dead? Vulnerability Management in the Post-Mythos Era appeared first on SecurityWeek .
Bleeping Computer2026-07-23 14:00 UTC
FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how organizations can prepare for continuous, evidence-based assurance. [...]
The Hacker News2026-07-23 13:27 UTC
Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac. Accomplish AI, which shared details of the vulnerability with…
The Hacker News2026-07-23 11:45 UTC
Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones…
SecurityWeek2026-07-23 09:53 UTC
He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek .

📺 NetworkChuck Cliff Notes

2026-07-23 · watch on YouTube ↗
Live 90-min AMA exploring how AI is reshaping the network engineering role, part of the Summer of CCNA program.
  • Examines AI's practical impact on daily network engineering tasks and career trajectory
  • Live Q&A format lets community surface real concerns about AI replacing or augmenting NetEng roles
  • Tied to Summer of CCNA structured study program at academy.networkchuck.com/course/premium-summer-of-ccna
  • Covers how CCNA-level fundamentals remain relevant even as AI tooling evolves
  • Reinforces that human expertise in networking is still essential alongside AI automation
2026-07-23 · watch on YouTube ↗
NetworkChuck mounts the new $80 Raspberry Pi Touch Display 2 (10-inch, 1200x1920 IPS) on his studio wall as a Home Assistant kiosk dashboard.
  • RPi Touch Display 2 specs: 10-inch portrait IPS, 1200x1920, 10-finger touch, 400 nits, $80 — requires Pi 5 or Compute Module only
  • Pi 3/Pi 4 not supported — Pi 5 EEPROM firmware update required before display is recognized
  • Open-source kiosk app TouchKio (github.com/leukipp/touchkio) used to serve the Home Assistant dashboard full-screen
  • Physical install: wall-mounted with just a drill and screws, no custom bracket needed
  • Use case: smart home wall panel or homelab status board — solid option for self-hosted dashboard builds
2026-07-19 · watch on YouTube ↗
NetworkChuck tours the FIFA World Cup IBC in Dallas, captures live ST 2110 multicast traffic, and decodes a real match packet capture in Wireshark.
  • SMPTE ST 2110 uncompressed video over IP — 150,000+ multicast flows carrying every camera feed from 16 stadiums
  • Red/blue fiber redundancy with automatic failover keeps the broadcast network live if a link drops
  • Wireshark decode of a real World Cup match shows raw multicast video traffic at broadcast scale
  • HBS (Host Broadcast Services) manages the temporary IBC network — built up and torn down around each tournament
  • NetworkChuck built a Backrooms-style game on a Hostinger VPS at 1AM using a Hermes AI agent
2026-07-09 · watch on YouTube ↗
90-min live AMA for the Summer of CCNA program, fielding community questions on CCNA prep, networking fundamentals, and study strategies.
  • Live Q&A format targeting CCNA candidates with real-time answers to common exam and study sticking points
  • Covers core Cisco networking concepts aligned with current CCNA exam objectives
  • Part of the structured Summer of CCNA program — full course at academy.networkchuck.com/course/premium-summer-of-ccna
  • Interactive session allows community to surface and resolve gaps in networking knowledge before exam day
  • Reinforces study discipline and provides guidance on certification path and resources
2026-07-02 · watch on YouTube ↗
NetworkChuck & Daniel Miessler break down the top meta-prompts to run on Claude (Fable 5) during its limited free-access window before usage caps hit July 7.
  • Fable 5 (Claude) briefly returned with unrestricted access — free window closes July 7 before a 50% usage cap kicks in
  • Key prompt: optimize your AI harness — point max intelligence at the system governing all your other AI workflows
  • Security prompt: audit your deployed tools for attack surface exposure and prompt injection vulnerabilities
  • Self-model audit: ask the model to identify what you're actually building toward and which skills are about to become obsolete
  • Daniel Miessler's full prompt list at danielmiessler.com — treat the window like a super-intelligent consultant, not an errand runner