Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-07-21 11:02 UTC
Articles: 96 · Sources: 8
Auto-refresh: 15m

🌍 Global Ransomware Heatmap 2209 victims · last 90d · top: US

Critical CVEs & Vulnerabilities 18 items

The Hacker News2026-07-21 08:59 UTC
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early…
The Hacker News2026-07-21 07:34 UTC
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training…
The Hacker News2026-07-21 06:29 UTC
Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could…
The Hacker News2026-07-20 09:10 UTC
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets…
CISA KEV2026-07-15 00:00 UTC
Added to KEV 2026-07-15. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
Krebs on Security2026-07-14 19:22 UTC
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to…
CISA KEV2026-07-14 00:00 UTC
Added to KEV 2026-07-14. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-14 00:00 UTC
Added to KEV 2026-07-14. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…

Active Threats & Malware 13 items

Dark Reading2026-07-20 18:30 UTC
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
The Hacker News2026-07-20 18:23 UTC
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. "FakeGit uses copied…
The Hacker News2026-07-20 17:29 UTC
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer…
The Hacker News2026-07-20 14:33 UTC
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and…
Krebs on Security2026-07-02 19:27 UTC
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity…
Krebs on Security2026-06-18 17:37 UTC
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to…
Krebs on Security2026-06-10 14:03 UTC
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life…

Data Breaches 6 items

SecurityWeek2026-07-21 09:36 UTC
Using social engineering, hackers compromised employee accounts with access to personal and health information. The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek .
Bleeping Computer2026-07-20 11:56 UTC
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system. [...]
SecurityWeek2026-07-20 11:27 UTC
Hackers stole names, addresses, Social Security numbers, credit/debit card numbers, and other information from a third-party management platform. The post Ernst & Young Data Breach Affects Personal, Financial Information appeared first on SecurityWeek .
Krebs on Security2026-07-13 15:03 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps…

Tools & Research 18 items

SecurityWeek2026-07-21 08:20 UTC
The latest Zimbra refresh resolves command injection, XSS, restriction bypass, and SSRF security defects. The post Zimbra Update Patches Critical Vulnerabilities appeared first on SecurityWeek .
Bleeping Computer2026-07-20 21:14 UTC
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings. [...]
Dark Reading2026-07-20 19:07 UTC
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.
Bleeping Computer2026-07-20 14:01 UTC
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. [...]
Dark Reading2026-07-20 14:00 UTC
From the World Cup to the United States' 250th celebration, this year's event calendar has been packed with high-profile gatherings that drew global audiences, intense scrutiny, and enormous security demands.
SecurityWeek2026-07-20 12:32 UTC
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek .
SecurityWeek2026-07-20 11:46 UTC
Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens. The post New Index Tracks Material Breaches — And Refuses to Add Up the Losses appeared first on SecurityWeek .

📺 NetworkChuck Cliff Notes

2026-07-19 · watch on YouTube ↗
NetworkChuck gets inside FIFA's World Cup IBC in Dallas, captures live ST 2110 multicast traffic, and decodes a real match in Wireshark.
  • FIFA IBC routes every camera feed from 16 stadiums over a massive temporary broadcast network in Dallas using SMPTE ST 2110 uncompressed video over IP
  • 150,000 multicast flows managed via broadcast SDN — red/blue redundant fiber paths with sub-second failover for zero-downtime switching
  • Live Wireshark pcap analysis of a real World Cup match reveals ST 2110 packet structure, multicast group addressing, and PTP timing
  • NetworkChuck built a Backrooms-style game at 1AM on a Hostinger VPS using a Hermes AI agent to explore the IBC virtually
  • Sponsored by Hostinger; full behind-the-scenes crew interviews available on NetworkChuck Academy
2026-07-16 · watch on YouTube ↗
NetworkChuck hosts a live 90-min Summer of CCNA AMA exploring how AI is reshaping network engineering roles and career paths.
  • Examines AI's practical impact on network engineer job functions, workflows, and daily responsibilities
  • Addresses community concerns about AI displacing vs. augmenting networking careers
  • Covers CCNA-relevant topics in the context of an AI-driven infrastructure landscape
  • Live Q&A format with direct instructor-student engagement on certification and career questions
  • Enroll at academy.networkchuck.com/course/premium-summer-of-ccna
2026-07-09 · watch on YouTube ↗
NetworkChuck hosts a live 90-min Summer of CCNA AMA at 5PM ET, fielding community questions on Cisco networking and CCNA certification prep.
  • Live 90-minute AMA format — students submit questions directly to NetworkChuck
  • Covers CCNA exam topics, study strategies, and certification path guidance
  • Part of the ongoing Summer of CCNA structured learning program
  • Interactive community session reinforcing core Cisco networking concepts
  • Enroll at academy.networkchuck.com/course/premium-summer-of-ccna
2026-07-02 · watch on YouTube ↗
NetworkChuck & Daniel Miessler break down which meta-prompts to run on Fable 5 (Claude Opus 4) during its limited free window before July 7 usage caps hit.
  • Fable 5 (Anthropic's most capable model) was briefly pulled by the U.S. gov, now back with a free window closing ~July 7
  • Key prompt 1: feed it your AI harness/system prompt and have it rebuild the architecture from scratch
  • Key prompt 2: full attack surface audit of everything you've deployed — prompt injection, security gaps, exposed endpoints
  • Key prompt 3: self-model audit — have it tell you what you're actually optimizing toward and which skills will 10x vs. die
  • Framework: don't use max intelligence for errands — point it at your deepest systems for work that outlasts the window
2026-06-19 · watch on YouTube ↗
NetworkChuck explores Shadow AI — unsanctioned AI tools employees use without IT approval — and the serious data leakage, compliance, and governance risks they create.
  • Shadow AI refers to AI tools employees adopt without IT/security team knowledge or approval
  • Key risks: sensitive data exfiltration to third-party LLMs, compliance violations, and blind spots in your attack surface
  • Most orgs lack visibility into which AI tools are in use — discovery and inventory are the critical first step
  • Vanta positioned as a solution to find, track, and govern AI tool usage across the enterprise
  • Mitigation requires policy enforcement, employee awareness, and continuous monitoring — not just blocking