Marisol "Fuse" Delgado
she/her · Practical defense — Patch Tuesday, the KEV tracker, what to actually do
Fuse isn’t shy about the fact that her past wasn’t a victimless curiosity story — she did real damage for real money in her 20s, got caught, and did federal time for it. What came after was a hard pivot into defensive consulting, because that was the only door still open, and because she’d rather be useful than nostalgic about it.
She has no patience for anyone who romanticizes what she did. She writes the practical stuff: what’s actually exploitable right now, what to patch first, what can wait. She does not discuss the specifics of her own past intrusions, in interviews or in print, ever.
Articles

Mythos at three months: measure exposure, not volume
Three months after Anthropic's Mythos disclosure, the industry is still arguing about CVE queue depth. The number that matters is time-to-patch on your exposed critical assets.

CERT-UA: UAC-0145 (Sandworm) runs ClickFix on Ukraine
CERT-UA alert 6318437 attributes a June–July ClickFix campaign hitting at least 10 compromised Ukrainian sites to UAC-0145, a Sandworm sub-cluster tied to GRU.

SonicWall SMA1000: Volexity names UTA0533, IoC list out
Volexity attributes the SMA1000 pre-disclosure exploitation to a new actor, UTA0533, active since June 22 — and publishes the toolkit for defenders to hunt.

LegacyHive: PoC drops for unpatched Windows LPE zero-day
A researcher publishing as "Nightmare Eclipse" dropped a PoC for LegacyHive — an unpatched local privilege escalation in Windows' User Profile Service.

Metasploit adds HTTP-to-SMB NTLM relay, RISC-V payloads
Rapid7's July 17 Metasploit wrap-up ships a Windows HTTP-to-SMB NTLM relay module, RISC-V shell payloads, and 421 new fetch-style variants. Check SMB signing tonight.

7-Zip 26.02 patches XZ heap overflow, no auto-update
7-Zip 26.02 fixes a heap-based buffer overflow in XZ decompression (ZDI-26-444) — RCE if a user opens a crafted archive, and there is no automatic update.

NadMesh botnet raids exposed AI tools for 3,811 AWS keys
A Go botnet called NadMesh, active since early July, feeds a Shodan queue into ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Operator dashboard claims 3,811 AWS keys.

Expel: GoldenEyeDog stole 27 EV certs from DigiCert
Expel says the April DigiCert breach was CylindricalCanine, a GoldenEyeDog subgroup. Twenty-seven of 60 revoked EV certs signed Zhong Stealer artifacts.

HollowByte: 11-byte OpenSSL DoS, no CVE, silent June fix
Okta's Red Team named 'HollowByte' — an OpenSSL DoS where 11 bytes of TLS pull 131 KB of process memory per shot. OpenSSL patched it in June with no CVE.

Agent Data Injection: The Bug Under Every AI Agent
Seoul National / UIUC / Largosoft research shows web and coding agents get steered by planted content in the pages, comments, and reviews they consume. Fix the trust boundary, not the model.

CISA adds a fourth SharePoint bug to KEV in 48 hours
CVE-2026-58644 — an unauthenticated deserialization RCE, CVSS 9.8 — landed on CISA KEV this morning, two days after Microsoft shipped the SharePoint fix.

FortiSandbox: two 9.8 unauth RCEs hit KEV, Sunday deadline
CISA added CVE-2026-39808 and CVE-2026-25089 to KEV today — unauthenticated OS command injection in Fortinet FortiSandbox, CVSS 9.8 each, federal BOD 26-04 deadline this Sunday.

Unpatched Shark vacuums: regional root, no CVE, no patch
tokay0 published a Shark robot vacuum flaw July 13: over-permissive AWS IoT device cert grants root on any other Shark in the same region. No patch.

CISA KEV: Oracle EBS Payments 9.8 unauth RCE lands
CISA added CVE-2026-46817 to KEV on Wednesday: unauthenticated CVSS 9.8 takeover of Oracle E-Business Suite Payments. Oracle's May 2026 CPU already has the fix.

Zoom PSIRT: patch Workplace 7.0.0, unauth takeover 9.8
Zoom pushed a critical unauth account-takeover advisory (ZSB-26014, CVSS 9.8) for the Windows Workplace client and VDI Client — patch to 7.0.0 or the branch build.

SonicWall SMA1000: what Rapid7 saw before disclosure
Rapid7 caught the SMA1000 zero-day exploitation before SonicWall's advisory. Attackers took credentials, MFA seeds, and pivoted to internal domain controllers.

AWS persistence: four patterns to hunt after an incident
Rapid7's Jan Blažek maps four AWS persistence classes — new IAM users, assume-role edits, Lambda backdoors, federated tokens — with the CloudTrail signals to hunt for each.

Firefox exploit code public; Chrome, Adobe patch same day
Mozilla says exploit code is public for two Firefox flaws fixed in 152.0.6. Chrome shipped Ozone use-after-free fixes; Adobe pushed 8 ColdFusion criticals.

CISA: three SharePoint bugs exploited, patch by July 17
CISA named three actively exploited on-prem SharePoint CVEs and put a July 17 remediation clock on federal agencies. Shadowserver counts 800+ unpatched servers. Patch on one maintenance touch.

Microsoft blocks Dell PCs from July KB5101650 rollout
Microsoft applied a safeguard hold on July's KB5101650 for a limited set of Dell devices running Windows 11 25H2 and 24H2 after a June preview update triggered Intel IPF driver crashes, heat, and battery drain.

Entra ID passkeys go default in Sept; SMS/voice out Feb 1
Microsoft is auto-enrolling Entra ID SMS/voice MFA users into passkeys starting September 2026 and retiring native SMS/voice delivery on Feb 1, 2027. What to do.

LastPass, Bitwarden users hit by lookalike-domain phishing
LastPass and Bitwarden users are getting phishing from lookalike "compliance" domains pushing a DocuSign-styled downloader. Delete the email; don't click.

SonicWall SMA1000 zero-days on CISA KEV: patch by July 17
Two SMA1000 flaws — a CVSS-10.0 unauthenticated SSRF and a post-auth code injection — hit CISA KEV today. Patch to 12.4.3-03453 or 12.5.0-02835 before July 17.

SharePoint JWT bypass fixed; RCE half of chain still open
Rapid7 disclosed CVE-2026-55040 today — a SharePoint JWT auth bypass patched in July Patch Tuesday. Second half of a pre-auth RCE chain lands next month. Patch now.

Microsoft July Patch Tuesday: 570 CVEs, 3 zero-days out
Microsoft's July 2026 Patch Tuesday ships 570 CVEs, including two exploited zero-days in AD FS and SharePoint plus a publicly disclosed BitLocker bypass. Patch AD FS first.

Progress patches ShareFile zero-day: 5.12.5 and 6.0.2 out
Progress shipped ShareFile Storage Zone Controller 5.12.5 and 6.0.2 to fix a high-severity authenticated path traversal. CVE pending. Patch first, then bring the boxes back up.

OAuth client ID spoofing sneaks past Entra sign-in logs
Proofpoint tracked two credential-stuffing crews that submit fake OAuth application IDs to Entra ID's token endpoint. The sign-in logs don't record what defenders are looking for.

OFAC sanctions 1VPNS admin plus Belarusian cryptor seller
OFAC designated 1VPNS, its Ukrainian admin Rashevskyi, and Belarusian cryptor seller Silayev on July 14 — the follow-on to May's Operation Saffron seizure.

Grok Build v0.2.93 uploaded whole repos to xAI's bucket
xAI's Grok Build CLI v0.2.93 uploaded whole git repos, history and all, to a GCS bucket. The "Improve the model" toggle didn't stop it. Fix is server-side.

Notarized Werkbit.app carries CrashStealer past Gatekeeper
Jamf flagged CrashStealer, a native-C++ macOS infostealer arriving inside Werkbit.app — Apple-notarized and gated behind a meeting PIN.

Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV
CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.

Huntress Flags Suspected AI-Written PowerShell in AD Case
Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

RedHook Android RAT pairs Wireless ADB on-device
Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.

jscrambler 8.14.0 npm hijack: Rust stealer on install
Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms
Sysdig confirms the first in-the-wild hit on Gitea Docker CVE-2026-20896; Singapore CSA now warns customers; 1.26.3 shipped with a regression, so run 1.26.4.
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

Zimbra ships 10.1.19; Google TAG reported the XSS
Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.

OpenMandriva ex-contributor wipes GNOME, Cosmic packages
Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

Injective SDK 1.20.21 on npm shipped a wallet stealer
Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

Microsoft patches Defender 'RoguePlanet' LPE; PoC public
Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now
SimpleHelp Server 5.5.15 and earlier accept forged OIDC tokens as valid technician sessions. CVSS 10.0, KEV, patch is 5.5.16 — CISA deadline was July 2.

WriteOut: One Preview Link Took Over Writer AI Accounts
SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

GitLost: Public Issue Leaks Private GitHub Repo Data
Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

GhostLock: 15-Year Linux Kernel Root/Container Escape
Nebula Security's GhostLock (CVE-2026-43499) — a 15-year-old futex use-after-free — hits every mainstream Linux distro. Escapes containers. Patch again.

CISA Adds Langflow and Two Joomla Builders to KEV
CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

Tenda Router Backdoor Has No Patch. Here's What to Do.
CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

BeyondTrust Patches Four RS/PRA Flaws — Patch Now
BeyondTrust shipped fixes on July 6 for four vulnerabilities in Remote Support and Privileged Remote Access, including a CVSS 9.8 pre-auth bypass. No in-wild exploitation reported. Here's the priority order.

Gitea Docker's Auth Bypass: Probing Already Underway
The Gitea Docker image up through 1.26.2 shipped a wildcard reverse-proxy trusted list, collapsing auth to a header. Fixed in 1.26.3. The Hacker News reports opportunistic scanning 13 days after disclosure; ~6,200 exposed instances.

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.

QuimaRAT: A $150 Cross-Platform Java RAT MaaS
LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

Opera GX Patches Auto-Install Mods Flaw
Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.

SkillCloak: Scanners Miss 90%+ of Skill Malware
HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

Flipper Zero Firmware Goes Maintenance-Only
Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

PolinRider: DPRK Seeds 108 Malicious Packages
The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

ARToken PhaaS Targets M365 Device-Code Phishing
Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

ChocoPoC: Fake CVE PoC Repos Ship a Stealer
YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

Bad Epoll: Linux Kernel LPE Also Hits Android
A newly disclosed use-after-free in Linux 6.4+ kernels lets an unprivileged local user gain root. Android on affected kernels is in scope; the upstream fix is in.

PamStealer: A Fake Maccy Site Steals macOS Creds
Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

Cisco Confirms Active Exploitation of Unified CM Flaw
Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now
A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress's fix has been available since June 4.

SharePoint RCE now on CISA KEV: patch it this week, not next
CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.