CHECKLEAKED.CC

Loading

Classic site

DAILY BRIEFING

Hackers leverage new Microsoft SharePoint exploit in attacks

Today's briefing covers active SharePoint attacks, critical Adobe patches, AI reasoning API flaws, Signal security updates, and enterprise internal security gaps.

Threat actors are actively leveraging proof-of-concept code to target Microsoft SharePoint installations following public research releases. Security teams with exposed SharePoint or enterprise Adobe deployments must prioritize patching immediately, as Adobe addressed multiple critical CVSS 10.0 flaws across ColdFusion and Campaign Classic.

Hackers leverage new Microsoft SharePoint exploit in attacks

Hackers have begun actively leveraging a proof-of-concept exploit for a critical Microsoft SharePoint vulnerability shortly after its public release by cybersecurity firm Rapid7.

Why it matters
Organizations running exposed SharePoint instances face immediate risk of unauthorized access and server compromise from active attack campaigns.
  • Microsoft
  • SharePoint
  • exploit
Read the original

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe issued security updates addressing multiple critical vulnerabilities across ColdFusion, Commerce, and Campaign Classic, including OS command injection flaw CVE-2026-48362 and eval injection flaw CVE-2026-48273.

What to do
Update affected Adobe ColdFusion installations to versions 2025.0.12 or 2023.0.23 and patch Commerce instances.
  • Adobe
  • ColdFusion
  • patch
Read the original

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

A vulnerability in reasoning APIs from OpenAI, Anthropic, and Google allowed researchers to extract hidden internal reasoning blocks, API keys, and passwords by replaying encrypted objects into sessions or weaker AI models.

  • OpenAI
  • Anthropic
  • Google
  • API
Read the original

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Picus Labs' Blue Report 2026 revealed that while enterprise perimeter defenses improved prevention to 69%, internal defenses remain vulnerable to undetected attacker activities like reconnaissance and credential theft.

Why it matters
Organizations relying solely on perimeter security risk rapid internal compromise once attackers breach external boundaries without triggering alarms.
  • defense
  • reconnaissance
Read the original

Signal adds new security feature to thwart man-in-the-middle attacks

Signal introduced Automatic Key Verification to provide users with an automated mechanism to confirm end-to-end encryption integrity and mitigate man-in-the-middle attacks.

Why it matters
Signal users seeking maximum privacy can now ensure communication channels have not been intercepted without manual safety number checks.
What to do
Update Signal applications to access the automatic key verification security feature.
  • Signal
Read the original

Key takeaways

  • AI API flaw enabled extraction of internal reasoning traces and secrets including 62 API keys and 33 passwords.
  • SharePoint
  • Rapid7
  • OpenAI
  • Anthropic
  • Adobe