πŸ” Security Pulse Β· 2026-07-31 16:00 UTC

⚑ TL;DR

Multiple critical Keycloak identity management vulnerabilities (CVE-2026-18203, CVE-18217, others) expose authentication and access control risks; elevated threat environment with significant ICS/SCADA attack surface CVEs emerging.

πŸ” CYBER THREATS

  • πŸ”΄πŸ”΄ Keycloak faces a cluster of severe flaws impacting SAML, OIDC, tenant logins, and admin API that can lead to unauthorized access and token manipulation, posing major identity management risk globally [1][2][3].
  • πŸ”΄ Active malware campaign delivering the stealthy "goop" Rust crate malware embedded in Polymarket-5min-bot, undetected for over a month, targeting software supply chains [4][5][6].
  • πŸ”΄ CVE-2026-15969 SGLang framework suffers unauthenticated remote code execution allowing attackers to execute arbitrary commands via unsafe deserialization bypass [7].
  • πŸ”΄ Multiple IEC 61850 and IEC 60870-5-104 protocol flaws (CVE-2026-66364, 66369, 66720, 63033, 61893) threaten critical infrastructure and industrial control systems with unauthenticated packet injections that can disrupt or manipulate energy grids and process controls [8][9][10].
  • 🟑 CVE-2026-10031 SFTPGo permission bypass allows authenticated users to circumvent directory access controls via symbolic links, risking data exposure.
  • 🟑 IBM WebSphere Application Server vulnerable to remote code execution through SOAP/JMX connector (CVE-2026-11536), requiring urgent patching of enterprise middleware.
  • 🟑 Apache Tika framework has multiple flaws including improper path traversal and alternate path protections (CVE-66755, CVE-66756), enabling potential file access abuses.
  • 🟑 AWS-amplify/codegen-ui-react and aws-smithy-json runtime have code execution and uncontrolled recursion bugs exploitable by authenticated users (CVE-18245, CVE-18140).

πŸ›‘οΈ NATIONAL SECURITY

  • 🟑 Multiple ICS/SCADA vulnerabilities in MMS server and GOOSE parsers can allow attackers to inject malicious multicast frames and cause denial of service or unauthorized control, raising alarms for electric grid and industrial facility cybersecurity [8].
  • 🟑 U.S. CISA is actively recruiting top talent to safeguard critical systems amid this energized threat landscape, underscoring the pressure on national cybersecurity defenses.
  • 🟑 CISA updated Security Configuration Baselines for Google Workspace with enhanced controls targeting advanced cloud AI integration under BOD 25-01, demonstrating efforts to harden supply chains and cloud platforms.

⚠️ RISK FLAGS

  • ⚠️ Keycloak critical flaws in active deployment warrant immediate patching as these identity solutions underpin many enterprise and government IAM systems, with potential for lateral movement and privileged access abuse [1][2][3].
  • ⚠️ ICS/SCADA protocol vulnerabilities in IEC 61850 and MMS layers present an immediate risk to critical infrastructure; unauthenticated network frames can bypass controls causing process disruption or data corruption [8][9][10].
  • ⚠️ Newly discovered stealth Rust malware crate actively infiltrating supply chains undetected highlights growing threat to open-source packages and software ecosystems, increasing risk of widespread infections [4][5][6].

🧭 THREAT MOOD

  • πŸ”΄ elevated

Overall threat environment is elevated with multiple high-severity authentication flaws in key identity platforms, critical infrastructure vulnerabilities requiring urgent mitigation, and ongoing stealth malware campaigns targeting supply chains. Vigilance and rapid patch application remain paramount.

πŸ“Ž Sources

  1. CVE-2026-18217 A flaw was found in the SAML protocol implement… β€” @CVEnew
  2. CVE-2026-18215 Keycloak provides a way to let users log in usi… β€” @CVEnew
  3. CVE-2026-18208 A flaw was found in the OIDC token introspectio… β€” @CVEnew
  4. @TorGuard Shoutout to @recogard and @eugenepage_ for the malwa… β€” @vxunderground
  5. > be me > get message from @TorGuard owner > "i found goop" (m… β€” @vxunderground
  6. @TorGuard Free malicious Rust Crate!! https://t.co/e3274j7xJf β€” @vxunderground
  7. CVE-2026-15969 SGLang contains an unauthenticated RCE in /load… β€” @CVEnew
  8. CVE-2026-66364 The GOOSE payload parser contains a boundary ha… β€” @CVEnew
  9. CVE-2026-66369 The GOOSE parser contains an off-by-one boundar… β€” @CVEnew
  10. CVE-2026-66720 The GOOSE subscriber component improperly valid… β€” @CVEnew

Educational & informational only β€” not financial advice. Markets carry risk; do your own research.
Serial 20260731-16-v26 Β· 2026-07-31 16:00 UTC Β· pulse.uzylab.com