logo

Weekly Digest #27 — Zero-Days Everywhere, Sanctions Escalate, and Your Browser Extension Just Betrayed You

ID: a41003f6-562a-5bcc-a064-8268508e46c1

STIX ID: report--a41003f6-562a-5bcc-a064-8268508e46c1

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

...
...

**Executive summary:** CosmicBytez Labs Weekly Digest #27 reports multiple high-impact events: emergency zero-days in Progress ShareFile (path traversal) and SonicWall SMA1000 (unauthenticated SSRF chained to RCE, CVSS 10.0) with confirmed active exploitation and emergency patches; ShinyHunters’ large-scale Salesforce data theft via credential theft, OAuth abuse, and misconfigurations; OFAC sanctions against a VPN provider and a malware cryptor seller; and discovery of a dormant browsing-history collector in the ModHeader extension (1.6M installs). The digest emphasizes immediate actions — patching affected systems, auditing IIS and AD FS logs, reviewing browser extensions and third-party integrations, and validating vendor/ VPN risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.