Squidbleed: Claude Mythos Found a 29-Year-Old Heartbleed in Squid Proxy — And the Patch Isn’t in 7.6
CVE-2026-47729 is a heap buffer overread in Squid Proxy’s FTP directory listing parser that has leaked other users’ HTTP Authorization headers, cookies, and API keys since 1997 — in every version, in default configuration. Found by Calif.io using Claude Mythos Preview in under an hour. Critical: the patch is in Squid 7.7, not 7.6. Disable FTP in Squid now.
Read Full Brief →Threats & Attacks
A quirk of C’s strchr, a 1997 FTP parser, and a heap overread that leaks other users’ passwords. Found by Calif.io using Claude Mythos in under an hour. The patch is coming in 7.7. Disable FTP in Squid now.
+181% in 48 hours. Five CISA-mandated actions. 35% generic admin, 28.3% built-in Fortinet accounts compromised. Hudson Rock free lookup tool live. FortiSandbox also exploited.
Scan, stuff, sniff, feed. A Turkish NATO defense contractor confirmed fully compromised. Initial access vector still unconfirmed.
REDCap legacy exploitation, INFINITERED malware, domain admin escalation, weaponized Google Workspace compliance rule. Defense, AI, and medical research data.
No credentials. No interaction. PostgreSQL Sidecar reachable through port 8000 proxy. AWS out of the box. watchTowr exploit chain published.
No credentials. No interaction. 14 days before Oracle said a word. 68% universities. 500,000 student records from University of Nottingham.
Intelligence & Deep Dive
Further Coverage
Largest Patch Tuesday ever. Wormable HTTP.sys. MiniPlasma patched. RoguePlanet now CVE-2026-50656 — Microsoft confirms patch in development.
Unauthenticated attackers forge GlobalProtect cookies, bypass MFA. CVSS 9.1. Active exploitation confirmed. June 19 CISA deadline passed.
22,052 incidents. Ransomware in 44%. Supply chain attacks doubled. Median exploit timeline 5 days vs 43-day patch time.
Command injection in SD-WAN Manager CLI. Root via crafted file upload. No patch. Chains after CVSS 10.0 auth bypass.
Microsoft documented how a hidden GitHub issue comment tricked Claude into reading /proc/self/environ. Patched in v2.1.128. “Comment and Control” class affects all major AI agents.
GHOST STADIUM phishing. Banking trojans in fake streaming apps. FBI, Group-IB, Kaspersky all warning.
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise. Trusted by enterprise and government security leaders.
