π VENDOR BULLETINS & ADVISORIES
- F5 Patches Multiple NGINX, BIG-IP Vulnerabilities β SecurityWeek
F5 released critical patches addressing multiple vulnerabilities in NGINX and BIG-IP products. Exploits could allow attackers to modify configurations, restart processes, cross security boundaries, leak memory, and execute arbitrary code. Immediate patching is advised to prevent active exploitation.
π VULNERABILITIES & CVEs
-
CVE-2026-6424: Use-after-free in ESET Linux Security Products β CVE ThreatInt
A use-after-free flaw in ESET Linux security products can trigger kernel panic, potentially leading to denial of service or escalation. No authentication required; patch or mitigate promptly. -
CVE-2026-6423: Local Privilege Escalation in ESET Inspect Connector β CVE ThreatInt
An unauthenticated ALPC IPC channel flaw allows local privilege escalation in ESET Inspect Connector. Attackers with local access can gain elevated privileges. Immediate updates recommended. -
CVE-2026-58078: Unauthenticated SQL Injection in Joomla Quix Page Builder Pro β CVE ThreatInt
Critical unauthenticated SQLi in Joomla extension Quix Page Builder Pro. Exploitation can lead to data exfiltration and full site compromise. Patch or disable affected versions immediately. -
Multiple WordPress plugin vulnerabilities with high impact:
- WP Bulk Delete β€1.4.2: Authenticated SQL Injection
- WP TripAdvisor Review Slider β€14.6: Authenticated SQL Injection
- Tutor LMS β€4.0.0: Authenticated SQL Injection via Stored Quiz Answers
- Uncanny Automator β€7.3.1.4: Unauthenticated PHP Object Injection leading to arbitrary file deletion
- Loco Translate β€2.8.5: CSRF leading to Remote Code Execution
- WPBot β€8.5.6: Authorization Bypass allowing arbitrary actions
- WPBot β€8.5.6: Unauthenticated arbitrary chat session hijacking
- The Cache Purger β€2.3.20: Authorization Bypass
- Themify Builder β€7.7.7: Authorization Bypass
- Digits β€9.1.0.5: Privilege Escalation
- Tickera β€3.6.0.0: Stored XSS via shortcode attribute
- Tickera β€3.6.0.0: Authenticated SQL Injection
- wpForo Forum β€3.1.1: Stored XSS via profile field
- SysBasics Customize My Account for WooCommerce β€4.4.14: Stored XSS
- WPFunnels β€3.12.8: Privilege Escalation via arbitrary option update
- Quiz and Survey Master β€11.2.0: Authenticated SQL Injection
- Breakdance β€2.7.1: Unauthenticated Stored Cross-Site Scripting
These WordPress plugin vulnerabilities mostly require authenticated access but include some unauthenticated attack vectors. Many allow SQLi, XSS, privilege escalation, or arbitrary file deletion. Immediate review and patching of affected plugins is critical to prevent site compromise.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- OpenAIβs GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 β The Hacker News
OpenAI disclosed GPT-Red, an internal red-teaming AI designed to automatically discover and exploit prompt injection vulnerabilities in GPT models. This tool is used to adversarially train and harden GPT-5.6 before deployment, highlighting the growing use of AI in offensive and defensive security testing.
π° LESSER-KNOWN / UNDER-REPORTED
- Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers β Graham Cluley
An app in India allows anyone with a smartphone to remotely stop e-rickshaws without authentication, exposing a critical IoT security risk. Also covered: AI-generated scam pitches targeting authors, illustrating evolving social engineering tactics leveraging AI.