CyberNews: 07/08/2026 Edition
Today’s roundup
Summary
Check Point Research exposed five memory-corruption bugs in Cloudflare's `workerd` runtime, which powers Code Mode and Workers. These flaws enable cross-tenant out-of-bounds reads and remote code execution (RCE), directly impacting isolation in the in-process sandbox architecture.
PortSwigger research detailed novel CSS-based attack techniques affecting multiple major webmail clients, including Yahoo, AOL, Fastmail, ProtonMail, Gmail, and Outlook. These vulnerabilities allow for CSS sanitizer bypasses, token exfiltration, UI spoofing, and real-time keyloggers, leading to account compromise and data theft.
Security researcher Malcolm Stagg unveiled "NatJack," a new attack class manipulating Network Address Translation (NAT) tables. This enables TCP session hijacking, DNS spoofing, port exposure, and NAT table exhaustion across various implementations, including Windows.
A new Linux kernel vulnerability, "Zapscape" (CVE-2026-64561), allows privileged L1 guest virtual machines to escape KVM isolation and execute code on the host. The flaw affects KVM/x86's shadow memory management unit (MMU) when nested virtualization is exposed to untrusted guests.
Cisco issued updates for 12 critical security vulnerabilities in its Catalyst SD-WAN and IOS XE Software, including three flaws with a CVSS score of 9.9. These patches address significant risks to widely deployed network infrastructure, following an internal security review.
Connor Riley Moucka pleaded guilty to computer fraud and conspiracy for hacking over 165 organizations using Snowflake, and stealing over 100 million AT&T customer records. Co-conspirators Cameron Wagenius and John Erin Binns were also implicated in the extortion scheme, which yielded over $2.5 million.
Malware can abuse Windows Hello for Business keys to gain persistent access to Microsoft Entra ID, as demonstrated by Dirk-jan Mollema. This technique allows adversaries to establish long-term cloud access, register devices, and obtain Primary Refresh Tokens (PRT), bypassing existing tenant policies.
Novee Security researchers identified flaws in Anthropic's Claude Code and Google's Gemini CLI that allowed GitHub issues, even from unprivileged accounts, to execute code on CI runners. This compromise exposed CI workflow secrets and could hijack AI agent runs at OpenAI.
An active, widespread email-driven phishing campaign uses adversary-in-the-middle (AiTM) techniques to hijack Microsoft 365 accounts. The attackers leverage residential proxies to collect payroll and finance-related emails and identify key financial personnel within targeted organizations.
Researchers discovered "TONTOU," a new CPU attack that bypasses Spectre v2 speculative execution side-channel mitigations. An exploit for TONTOU was successfully developed to leak sensitive information, specifically Linux password hashes, from vulnerable systems.
Want to dig deeper?
Vulnerabilities
| CVE-2026-64561 | Medium |