⚠ exploit status: CVE-2026-33017 · KEV CVE-2026-33825 · KEV·R CVE-2026-48558 · KEV CVE-2026-46817 · KEV
Crit  2026-07-01 06:08Z · last 24h · 46 findings · glm-5.2:cloud

Threat Brief — 2026-07-01 — Azure Spray, SimpleHelp RCE, AI Agents Under Fire

Executive summary. Three actively exploited criticals dominate today: SimpleHelp's OIDC auth bypass (CVSS 10.0) is delivering the novel TaskWeaver and Djinn Stealer payloads; Oracle E-Business Suite Payments has a CVSS 9.8 takeover flaw being touched in the wild; and CISA confirms the Windows Defender "BlueHammer" EoP is now in ransomware operators' toolkits. Separately, a large-scale Azure CLI password spray has fired 81M+ attempts and hit at least 78 accounts. A strong secondary theme is AI-agent attack surface: poisoned MCP tool descriptions, agentjacking via fake bug reports, BioShocking browser prompt injection, and exposed LLM endpoints all surfaced in the last 24 hours.


Top items

Themes

AI-agent and LLM attack surface is expanding fast. Multiple distinct vectors surfaced: poisoned MCP tool descriptions silently exfiltrating company data (Microsoft research); "agentjacking" via fake bug reports hijacking AI coding agents; "BioShocking" prompt-injection tricking AI browsers into leaking credentials; exposed AI endpoints being hijacked for offensive ops (Langflow CVE-2026-33017KEV miner deployment); and 282 iOS chatbot apps found leaking LLM API keys in plaintext. Together these form a coherent "AI stack as new perimeter" story — prioritise access controls on AI endpoints, scrutinise agent tool definitions, and review coding-agent command boundaries (GuardFall bypass shows existing safety checks are bypassable via classic shell injection).

Identity attacks remain the top monetisation path. The Azure CLI spray and SimpleHelp's MFA bypass both sit on identity boundary failure — one at scale, one at depth. Pair these with the ongoing BEC research and the Nidec-Blackfield $2M ransom ask, and identity hardening (MFA, Conditional Access, service-account hygiene, privileged access review) is the single highest-leverage control right now.

Supply-chain vectors are diversifying. New this cycle: "phantom squatting" on AI-hallucinated domains to poison software dependencies, and trojanised Pyrogram forks on PyPI targeting Telegram bot developers for arbitrary file read. Both are low-sophistication, high-reward entry points — review dependency provenance and pin hashes where possible for Python projects touching Telegram.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb