Cisco Talos reports that the China-linked UAT-7810 threat actor continues to enhance its Operational Relay Box (ORB) infrastructure by developing additional custom malware, including LONGLEASH. The ORB network approach—compromising internet-facing networking devices—helps actors create resilient, distributed access paths that can be difficult to eliminate. The key takeaway for defenders: prioritize exposure reduction and rapid triage of suspicious activity on perimeter and networking equipment, not just endpoints.
Source: Cisco Talos
Attackers exploit critical Adobe ColdFusion flaw (CVE-2026-48282) in the wild
Multiple reports indicate that attackers are actively exploiting CVE-2026-48282, a maximum-severity Adobe ColdFusion vulnerability patched June 30, 2026. Detection efforts (including honeypot telemetry) show exploitation attempts occurring within days of analysis publication, underscoring how quickly attackers move once proof and targeting guidance circulate. Organizations running ColdFusion should treat this as a fast-moving incident response and patch immediately, then validate for exploitation indicators.
Source: Help Net Security
16-year-old Linux KVM flaw (Januscape) enables VM escape on Intel/AMD
A long-dormant Linux kernel vulnerability, tracked as “Januscape,” can allow guest code to corrupt host kernel memory and potentially escape virtual machines—impacting both Intel and AMD systems. Because hypervisors concentrate trust, a successful VM escape can turn a single compromised tenant into full host compromise. The practical risk driver is coverage: cloud and virtualization operators should assess exposure and accelerate patching and mitigations across affected kernel versions.
Source: Security Week
CISA adds exploited ColdFusion/Langflow/Joomla/related flaws to KEV—and urges rapid patching
U.S. CISA expanded its Known Exploited Vulnerabilities (KEV) catalog with multiple vulnerabilities, including Adobe ColdFusion (CVE-2026-48282) and additional widely deployed software components (e.g., Langflow and Joomla-related issues), citing evidence of active exploitation. For federal entities and those following KEV-driven patch SLAs, this is a clear signal that mitigation timelines should compress further. The operational message: align asset inventories, patch windows, and verification/testing to the KEV cadence rather than traditional quarterly rhythms.
Source: Security Week
Critical Gitea Docker authentication bypass (CVE-2026-20896) actively exploited
Researchers warn of active exploitation of a critical Gitea flaw (CVE-2026-20896) affecting official Docker images prior to 1.26.3. The issue is an authentication bypass reachable via a single HTTP header, enabling attackers to access repositories and sensitive data. If you run Gitea in containers, treat this as a high-priority credential and secret exposure risk: update images, rotate exposed credentials/tokens, and review logs for unauthorized repository access.
Source: Security Affairs
“Ghost certificate” ADFS drift could enable SAML forgery via Machine DPAPI
Google Cloud Threat Intelligence describes an attack path where configuration drift during manual ADFS certificate rotation can leave a “ghost” state that still enables recovery of signing key material from Machine DPAPI. In the demonstrated scenario, attackers can obtain keys and forge valid SAML assertions, potentially bypassing MFA and identity-based controls for federated applications. Defenders should harden ADFS as Tier 0 identity infrastructure, monitor for certificate validity inconsistencies (e.g., ADFS Event ID 385), and consider hardware-backed key protection (HSM) to eliminate host key extraction.
Source: Google Cloud TI
You May Also Be Interested In... More Odd DNS Records: NIMLOC
uBlock Origin adds protections against ClickFix attacks
Britain plans autonomous AI “Cyber Shield” to defend nation