Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-07-20 11:02 UTC
Articles: 96 · Sources: 8
Auto-refresh: 15m

🌍 Global Ransomware Heatmap 2205 victims · last 90d · top: US

Critical CVEs & Vulnerabilities 18 items

The Hacker News2026-07-20 09:10 UTC
Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets…
SecurityWeek2026-07-20 05:21 UTC
Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure. The post WP2Shell WordPress Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .
The Hacker News2026-07-19 20:42 UTC
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build…
CISA KEV2026-07-15 00:00 UTC
Added to KEV 2026-07-15. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
Krebs on Security2026-07-14 19:22 UTC
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to…
CISA KEV2026-07-14 00:00 UTC
Added to KEV 2026-07-14. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-14 00:00 UTC
Added to KEV 2026-07-14. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-13 00:00 UTC
Added to KEV 2026-07-13. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…

Active Threats & Malware 12 items

The Hacker News2026-07-19 13:30 UTC
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a…
The Hacker News2026-07-17 18:54 UTC
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented"…
The Hacker News2026-07-17 17:12 UTC
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders…
Krebs on Security2026-07-02 19:27 UTC
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity…
Krebs on Security2026-06-18 17:37 UTC
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to…
Krebs on Security2026-06-10 14:03 UTC
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life…

Data Breaches 5 items

The Hacker News2026-07-19 13:18 UTC
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The…
Bleeping Computer2026-07-17 20:45 UTC
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. [...]
The Hacker News2026-07-17 16:39 UTC
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime…
Krebs on Security2026-07-13 15:03 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps…

Tools & Research 18 items

SecurityWeek2026-07-20 10:31 UTC
Attendees will be able to interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. The post Watch on Demand: Cloud & Data Security Summit appeared first on SecurityWeek .
SecurityWeek2026-07-20 10:25 UTC
The agentic security tool identifies potentially exploitable code flaws, traces attack paths, and recommends targeted remediations. The post Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool appeared first on SecurityWeek .
SecurityWeek2026-07-20 09:36 UTC
Targeting production infrastructure, the attack compromised internal datasets and service credentials. The post Hugging Face Hacked in Autonomous AI Attack appeared first on SecurityWeek .
SecurityWeek2026-07-20 08:12 UTC
The fresh security update resolves six critical and high-severity use-after-free vulnerabilities. The post Chrome 150 Update Patches Severe Memory Safety Bugs appeared first on SecurityWeek .
The Hacker News2026-07-20 05:27 UTC
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized…
The Hacker News2026-07-20 05:15 UTC
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2,…
Bleeping Computer2026-07-18 13:15 UTC
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risks while supporting compliance. [...]
The Hacker News2026-07-17 21:20 UTC
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare…
The Hacker News2026-07-17 20:20 UTC
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red…
Dark Reading2026-07-17 16:43 UTC
AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.
Bleeping Computer2026-07-17 14:00 UTC
Residential proxies are no longer the silver bullet they once were for carding. Flare explains why cybercriminals increasingly seek "clean" residential proxies and combine them with browser fingerprints, device profiles, and other identity signals to evade modern fraud detection. [...]

📺 NetworkChuck Cliff Notes

2026-07-19 · watch on YouTube ↗
NetworkChuck tours FIFA's World Cup IBC in Dallas, analyzes real ST 2110 packet captures in Wireshark, and breaks down the multicast broadcast network feeding 16 stadiums.
  • SMPTE ST 2110 uncompressed video over IP — 150,000 multicast flows managed across the IBC core network
  • Red/blue fiber redundancy with sub-second failover — same concept as active/passive uplinks but at broadcast scale
  • Wireshark deep-dive on a live match capture: multicast group enumeration, payload decode, timing analysis
  • HBS (Host Broadcast Services) SDN architecture handles signal routing from 16 stadiums to a single IBC in Dallas
  • Built a Hostinger VPS game at 1AM simulating the IBC — AI-assisted, shows real-world rapid deployment mindset
2026-07-16 · watch on YouTube ↗
NetworkChuck hosts a 90-min live AMA exploring how AI is reshaping the network engineering role within the Summer of CCNA program.
  • Examines AI's practical impact on network engineer job functions, workflows, and skill requirements
  • Live Q&A format addressing student concerns about AI displacing or augmenting networking careers
  • Covers CCNA-relevant topics in the context of an AI-driven infrastructure landscape
  • Encourages enrollment in Summer of CCNA at academy.networkchuck.com/course/premium-summer-of-ccna
  • Interactive community session bridging traditional Cisco networking fundamentals with emerging AI trends
2026-07-09 · watch on YouTube ↗
NetworkChuck hosts a 90-min live AMA for Summer of CCNA, fielding student questions on Cisco networking and certification prep.
  • Live Q&A format targeting students enrolled in the Summer of CCNA program
  • Covers CCNA exam topics, certification path guidance, and study strategies
  • Reinforces core Cisco networking concepts aligned with current CCNA exam objectives
  • Interactive session encouraging community engagement and direct instructor access
  • Sign-up available at academy.networkchuck.com/course/premium-summer-of-ccna
2026-07-02 · watch on YouTube ↗
NetworkChuck and Daniel Miessler break down the top meta-prompts to run on Fable 5 (Claude's most powerful model) before the free-use window closes.
  • Fable 5 (Anthropic's most capable model) relaunched after a brief government-ordered pause — free full-access window ends ~July 7
  • Daniel Miessler's framework: don't use max intelligence for errands — point it at your deepest systems and hardest questions
  • Prompt 1: Optimize your AI harness/orchestration layer for better reliability and output quality
  • Prompt 2–3: Security audit — prompt injection hardening and full attack surface review of everything you've deployed
  • Prompt 4: Self-model audit — force the model to tell you what you're actually building toward and which skills will 10x or die
2026-06-19 · watch on YouTube ↗
Shadow AI — unsanctioned AI tools employees use without IT approval — creates serious data leakage, compliance, and governance risks most orgs can't see.
  • Shadow AI refers to unauthorized AI tools (ChatGPT, Copilot plugins, AI SaaS) used inside orgs without IT/security visibility
  • Key risks: data exfiltration, IP leakage, compliance violations, and total loss of governance over sensitive data
  • Most organizations are blind to the true scope of Shadow AI sprawl across their environments
  • Discovery and inventory of AI tool usage is the critical first mitigation step
  • Vanta positioned as a solution to find, track, and govern AI tool usage across the enterprise