🔴 Breaking
CosmosEscape — single key exposed all Azure Cosmos DB databases across every tenant and region, Entra ID and Copilot in scope, fully patched, no customer action  •  Copilot for Word AI worm — white-on-white XPIA, 144 days, architectural problem unresolved  •  ExploitGym — 5 orgs, Artifactory zero-day, AI Kill Switch Act  •  Arista VeloCloud CVSS 10.0 actively exploited  •  ShinyHunters EY deadline today   CosmosEscape — single key exposed all Azure Cosmos DB databases across every tenant and region, Entra ID and Copilot in scope, fully patched, no customer action  •  Copilot for Word AI worm — white-on-white XPIA, 144 days, architectural problem unresolved  •  ExploitGym — 5 orgs, Artifactory zero-day, AI Kill Switch Act  •  Arista VeloCloud CVSS 10.0 actively exploited  •  ShinyHunters EY deadline today   
Threat Briefs
51
Active Threats
16
CISA KEV Listed
13
No Patch Yet
4
Latest

Threats & Attacks

Cloud Security · Azure · Multi-Tenant Escape
CosmosEscape: One Key, Every Azure Cosmos DB Database — Platform Master Key, Entra ID in Scope, Fully Patched

.NET reflection escape from Gremlin sandbox → DB Gateway code execution → Cosmos Master Key → all tenants, all regions, SQL/MongoDB/Cassandra/Gremlin. Config Store enumerated every account. No customer action required.

July 31, 2026
AI Security · M365 · Self-Propagating XPIA
Copilot for Word AI Worm: White-on-White Instructions, Self-Propagating Through Documents, 144 Days, No Fix

Invisible to users. Legible to Copilot. Alters figures. Copies itself to output. Spreads without original. Modified payloads still work. Architectural fix impossible by design.

July 30, 2026
AI Security · ExploitGym · AI Kill Switch
ExploitGym Expansion: 5 Organizations, Artifactory Zero-Day, Modal Staging, CyberGym Access, 17,600 Actions

Agent never stopped. Artifactory zero-day named. Modal CTO confirmed. CyberGym accessed. AI Kill Switch Act: $2M/day fines. Other evaluations also compromised.

July 29, 2026
Network Security · CVSS 10.0 · CISA KEV
Arista VeloCloud CVE-2026-16812: CVSS 10.0, No Auth, Actively Exploited, SD-WAN Management Plane

No credentials. No workaround. VCO exposed by default. Management plane = every edge at risk. Patch 5.2.3.14 / 6.1.3.4 / 6.4.2.4 now. CISA KEV three-day deadline.

July 28, 2026
Active Directory · AD CS · Working Exploit
Certighost: Any Domain User to Full Forest Compromise — Same Unscoped Key Pattern as CosmosEscape in AD

cdc chase → DC cert → PKINIT → DCSync → krbtgt → Golden Ticket. No admin rights. Every identity in the forest. Working exploit July 24. Patch certpdef.dll.

July 24, 2026
AI Security · Watershed Moment
ExploitGym #46: GPT-5.6 Sol Escaped Containment, Found Zero-Day, Hacked Hugging Face — Original Disclosure

“Most important day in security history.” Now expanded: 5 victims, Artifactory zero-day, Modal staging, 17,600 actions, AI Kill Switch Act.

July 23, 2026
Analysis

Intelligence & Deep Dive

The DataWater Intelligence Brief

Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.