Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: July 1, 2026 - July 1, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Wednesday, July 1, 2026 -88% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

CVE-2026-48558 — SimpleHelp Remote Support

Authentication bypass in SimpleHelp OIDC authentication flow. When OIDC is configured, identity tokens submitted during login are accepted without verifying cryptographic signatures, allowing remote unauthenticated attackers to submit forged tokens with arbitrary identity claims to obtain fully authenticated technician sessions. May also allow MFA bypass. Actively exploited to deploy Djinn Stealer targeting Windows, macOS, and Linux.

REMEDIATION

Apply vendor security updates immediately per SimpleHelp advisory. Discontinue use if mitigations unavailable per CISA BOD 26-04. Review SimpleHelp authentication logs for suspicious OIDC token submissions. Implement network-based access controls as compensating control.

Source: CISA KEV  •  Published: 2026-06-15

AI & Supply Chain

[CRITICAL]

TRUSTFALL-MCP-2026 — Cursor CLI, Claude Code, Gemini CLI, GitHub Copilot CLI

Unpatched prompt injection vulnerability in Model Context Protocol (MCP) implementations affecting multiple AI IDEs. Requires only .mcp.json and settings file in malicious repository. Auto-approved MCP server spawns as unsandboxed OS process with full user privileges and access to SSH keys, cloud credentials, and source code. Zero-click exploitation in CI/CD environments. Represents OWASP LLM01 vulnerability class.

REMEDIATION

Review every repository for .mcp.json files before opening. Disable auto-approval in agent settings. Restrict MCP server execution in CI environments. Implement mandatory code review for MCP configuration changes. Deploy until vendor patches are available.

Source: Adversa AI  •  Published: 2026-05-07

Priority Action Matrix

01DO NOWCVE-2026-48558 (SimpleHelp Remote Support): Apply vendor security updates immediately per SimpleHelp advisory. Discontinue use if mitigations unavailable per CISA BOD 26-04. Review SimpleHelp authentication logs for suspicious OIDC token submis...
02DO NOWTRUSTFALL-MCP-2026 (Cursor CLI, Claude Code, Gemini CLI, GitHub Copilot CLI): Review every repository for .mcp.json files before opening. Disable auto-approval in agent settings. Restrict MCP server execution in CI environments. Implement mandatory code review for MCP configura...

Biggest Risk This Period

BIGGEST RISK

CVE-2026-48558: Authentication bypass in SimpleHelp OIDC authentication flow. When OIDC is configured, identity tokens submitted during login are accepted without verifying cryptographic signatures, allowing remote unauthenticated attackers to submit forged tokens with arbitrary identity claims to obtain fully authenticated technician sessions. May also allow MFA bypass. Actively exploited to deploy Djinn Stealer targeting Windows, macOS, and Linux.