Briefing archive

July 2026

Permanent daily editions, ordered newest first.

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Prioritize immediate patching of Check Point Management Servers and JFrog Artifactory instances due to active exploitation and public PoCs. We are seeing a dangerous convergence of AI agents autonomously exploiting zero-days and supply-chain compromises in npm, requiring tighter secrets management and dependency auditing. Additionally, critical RCEs in Gitea and vBulletin, alongside VMware VM escape flaws, necessitate an urgent update cycle across developer and virtualization stacks.

Read this edition

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Immediate priority is patching the CVSS 10.0 Arista VeloCloud Orchestrator flaw and auditing for FastJson RCE, both of which are seeing active exploitation. We are also seeing a surge in high-impact identity risks via AD CS PoCs and cloud 'Confused Deputy' flaws. Additionally, the emergence of autonomous AI agents in real-world espionage underscores an urgent need to evaluate agentic browser security.

Read this edition

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Immediate priority must be given to patching Fastjson, ServiceNow, and PTC Windchill/FlexPLM due to confirmed active exploitation of unauthenticated RCEs. We are also seeing a shift toward AI-automated post-exploitation and sophisticated browser-based malware assembly that bypasses traditional file scanning. Ensure Active Directory auditing is tightened against the Certighost impersonation technique.

Read this edition

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Self-managed GitLab systems missing the June security update and internet-exposed PTC Windchill or FlexPLM deployments require immediate attention: public GitLab exploit code is available, while Cl0p affiliates are using an unauthenticated RCE chain for data theft and extortion. Security teams should also account for the shift toward real-time phishing session hijacking and assess exposure to the reported Rockwell Arena code-execution flaws. Prompt patching, credential monitoring, and review of third-party incidents remain the practical priorities.

Read this edition

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

Today’s landscape is dominated by actively exploited AI agent vulnerabilities and prompt injection flaws that directly impact CI/CD pipelines and IAST workflows, alongside critical web application RCEs targeting enterprise SharePoint and WordPress deployments. High-impact supply chain compromises and ransomware campaigns underscore the need for rigorous dependency scanning and WAF rule tuning against emerging PhaaS kits like Kratos. For your stack, prioritizing agent guardrails in development environments, patching Langflow and Azure DevOps MCP integrations, and monitoring machine key theft trends will be critical to maintaining resilient appsec and API defenses.

Read this edition

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Enterprise appsec and AI security teams should prioritize patching critical SaaS and perimeter vulnerabilities, as active exploitation of ServiceNow’s AI platform, WordPress wp2shell, and Palo Alto GlobalProtect is rapidly expanding across large networks. Concurrently, AI agent supply-chain risks are materializing through sandbox escapes in major coding assistants and targeted ransomware encrypting Langflow model assets, while stealthy C2 channels like HollowGraph continue to bypass traditional monitoring. Defenders must accelerate IAST coverage for AI runtimes, validate WAF rules against emerging web exploits, and enforce strict identity boundaries across multi-platform AI deployments.

Read this edition

JadePuffer agentic attacks now target AI model data with ransomware

AI agent supply chains and sandbox escapes are rapidly evolving into active exploitation vectors, as evidenced by ransomware targeting ML datasets, autonomous breaches at Hugging Face, and CLI tool vulnerabilities. Concurrently, critical web application and SaaS flaws like the WP2Shell WordPress RCE and actively exploited ServiceNow pre-auth RCE demand immediate WAF rule tuning and API security validation. For enterprise defenders, prioritizing AI model/data protection, tightening client-side file parsing, and monitoring zero-day VPN exploitation will be essential to maintaining robust appsec and infrastructure postures.

Read this edition