Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-07-22 11:02 UTC
Articles: 96 · Sources: 8
Auto-refresh: 15m

🌍 Global Ransomware Heatmap 2202 victims · last 90d · top: US

Critical CVEs & Vulnerabilities 18 items

Bleeping Computer2026-07-21 16:41 UTC
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. [...]
The Hacker News2026-07-21 14:57 UTC
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an…
The Hacker News2026-07-21 14:04 UTC
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments. Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257…
CISA KEV2026-07-21 00:00 UTC
Added to KEV 2026-07-21. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-21 00:00 UTC
Added to KEV 2026-07-21. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-21 00:00 UTC
Added to KEV 2026-07-21. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-15 00:00 UTC
Added to KEV 2026-07-15. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
Krebs on Security2026-07-14 19:22 UTC
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to…
CISA KEV2026-07-14 00:00 UTC
Added to KEV 2026-07-14. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-07-14 00:00 UTC
Added to KEV 2026-07-14. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…

Active Threats & Malware 14 items

The Hacker News2026-07-22 06:00 UTC
Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a…
Bleeping Computer2026-07-21 23:07 UTC
Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. [...]
Dark Reading2026-07-20 18:30 UTC
"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.
Krebs on Security2026-07-02 19:27 UTC
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity…
Krebs on Security2026-06-18 17:37 UTC
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to…
Krebs on Security2026-06-10 14:03 UTC
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life…

Data Breaches 4 items

The Hacker News2026-07-21 18:46 UTC
Apple has moved to address a security flaw in its Hide My Email service that enabled users' real email addresses to be unmasked, effectively undermining the feature's privacy guarantees. 404 Media reported Tuesday that a fix for the issue was deployed by Apple on July 3, 2026, after more than a year, when it was…
Krebs on Security2026-07-13 15:03 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps…

Tools & Research 18 items

SecurityWeek2026-07-22 07:48 UTC
OpenAI says its AI models went rogue, as CISOS call the incident a watershed moment, warning that autonomous AI threat models have officially crossed into production reality. The post OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face appeared first on SecurityWeek .
Bleeping Computer2026-07-22 05:19 UTC
OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]
The Hacker News2026-07-22 04:57 UTC
A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it works because one of its tools returns…
The Hacker News2026-07-22 04:18 UTC
OpenAI on Tuesday said a combination of its artificial intelligence (AI) models, including GPT-5.6 Sol and an "even more capable pre-release model," was behind the security incident that targeted Hugging Face's production infrastructure last week. The AI company said the models were operating with "reduced cyber…
Krebs on Security2026-07-22 01:10 UTC
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's…
SecurityWeek2026-07-21 17:44 UTC
The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. The post Cisco Launches Low-Cost AI Models for Source Code Security appeared first on SecurityWeek .
The Hacker News2026-07-21 16:06 UTC
Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page…
The Hacker News2026-07-21 15:09 UTC
Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to…
Bleeping Computer2026-07-21 14:00 UTC
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. [...]
The Hacker News2026-07-21 13:18 UTC
Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the…

📺 NetworkChuck Cliff Notes

2026-07-19 · watch on YouTube ↗
NetworkChuck tours FIFA's IBC in Dallas, analyzes a real ST 2110 packet capture in Wireshark, and breaks down the multicast backbone powering World Cup broadcasts.
  • SMPTE ST 2110 uncompressed video over IP — raw multicast traffic at broadcast scale, decoded live in Wireshark
  • 150,000 multicast flows managed via SDN; red/blue fiber redundancy for sub-second failover between stadium and IBC
  • HBS provided an actual match PCAP — rare look at production broadcast network traffic patterns
  • IBC in Dallas aggregates feeds from 16 stadiums; all production (replay, audio, graphics) happens 1,500 miles from the pitch
  • NetworkChuck built a Backrooms-style game on a Hostinger VPS using a Hermes agent as a side project during the visit
2026-07-16 · watch on YouTube ↗
NetworkChuck hosts a live 90-min Summer of CCNA AMA examining how AI is reshaping network engineering roles and skill requirements.
  • Explores whether AI will replace or augment network engineers and what skills remain essential
  • Live Q&A format with community questions on AI tools intersecting with Cisco networking workflows
  • Reinforces CCNA-relevant fundamentals as a foundation even in an AI-driven infrastructure landscape
  • Addresses student concerns about career trajectory and certification value in the age of AI
  • Part of the Summer of CCNA program — enroll at academy.networkchuck.com/course/premium-summer-of-ccna
2026-07-09 · watch on YouTube ↗
NetworkChuck hosts a 90-min live AMA for Summer of CCNA, fielding community questions on Cisco networking and certification prep at 5PM ET.
  • Live Q&A format covering CCNA exam topics and student certification questions
  • Part of the ongoing Summer of CCNA program at NetworkChuck Academy
  • Reinforces core Cisco networking concepts aligned with current CCNA exam objectives
  • Interactive session encouraging community engagement and direct instructor access
  • Enroll at academy.networkchuck.com/course/premium-summer-of-ccna
2026-07-02 · watch on YouTube ↗
NetworkChuck and Daniel Miessler break down the exact meta-prompts to run on Fable 5 before the free window closes July 7.
  • Fable 5 (Anthropic) was briefly pulled offline by the U.S. government and relaunched with a limited free-tier window through ~July 7
  • Core prompt strategy: point maximum intelligence at deep systems — AI harness optimization, prompt injection hardening, and full attack surface audit
  • Daniel Miessler's 4 key prompts: optimize your AI harness, audit security/prompt injection handling, enumerate your full deployed attack surface, run a self-model audit on goals
  • Framework: treat Fable 5 like a super-intelligent alien — don't run errands, use it to rebuild foundational systems that outlast the access window
  • Reference: full prompt list at danielmiessler.com/blog/prompts-to-run-when-fable-comes-back
2026-06-19 · watch on YouTube ↗
NetworkChuck breaks down Shadow AI — unsanctioned AI tools employees use without IT knowledge — and the serious security and compliance risks they create.
  • Shadow AI refers to AI tools adopted by employees outside IT visibility or approval
  • Key risks: data leakage to third-party LLMs, compliance violations, and loss of data governance
  • Discovery and inventory of AI tool usage is the critical first mitigation step
  • Vanta positioned as a solution to find, track, and govern AI tools across the enterprise
  • Organizations need formal AI acceptable-use policies and continuous monitoring to reduce exposure