π¨ ACTIVE EXPLOITS & INCIDENTS
-
Inc Ransomware Exploits SonicWall SMA Zero-Days β Dark Reading
New ransomware campaign actively chaining two SonicWall SMA zero-day vulnerabilities to gain root-level access on SonicWall mobile access appliances. Immediate patching and monitoring of SonicWall SMA devices is critical to prevent compromise. -
Abbott Laboratories Investigates Two Cyber Incidents Amid Extortion Claims β BleepingComputer
Abbott Labs confirmed unauthorized access to legacy Exact Sciences systems and a separate breach of its LabCentral portal with data theft. The incidents involve extortion threats, indicating active attacker presence targeting healthcare diagnostics infrastructure.
π VULNERABILITIES & CVEs
-
New wp2shell WordPress Core RCE Flaw β The Hacker News
Critical unauthenticated remote code execution in WordPress core affects versions 6.9 and 7.0 prior to 6.9.5/7.0.2. Exploitable on bare installs without plugins. Forced auto-updates deployed but immediate patching is advised. CVSS likely high due to unauthenticated RCE. -
Windows RDP Information Disclosure β CVE ThreatInt
CVE-2026-56171 allows unauthorized attackers to disclose private personal information over the network via Windows Remote Desktop Protocol. Affects all unpatched Windows RDP deployments. -
Microsoft Edge (Chromium) Authentication Bypass β CVE ThreatInt
CVE-2026-57980 enables authentication bypass via alternate path in Chromium-based Edge, allowing unauthorized tampering over the network. Urgent patching recommended. -
JLine Telnet Remote Memory Exhaustion & JLine Telnet Remote DoS β CVE ThreatInt
Unauthenticated remote DoS vulnerabilities in JLine3 Telnet server module due to unbounded environment variables and terminal geometry parameters. Affects versions prior to 3.30.14, 4.0.16, and 4.2.1. -
@hapi/inert Static File Confinement Bypass β CVE ThreatInt
Path traversal vulnerability in @hapi/inert versions 4.0.0 to 7.1.0 allows serving files outside configured directories, risking sensitive data exposure. -
@hapi/wreck Credential Header Leakage & @hapi/wreck Proxy-Authorization Header Leak β CVE ThreatInt
Sensitive headers including Authorization, Cookie, and Proxy-Authorization leak across cross-origin redirects in @hapi/wreck HTTP client prior to 18.1.2 and 18.1.1 respectively. -
HAPI FHIR ReDoS via FHIRPath Matches() β CVE ThreatInt
Regular expression denial-of-service in HAPI FHIR Validator affecting versions prior to 6.9.9 and 6.9.4.2. Can be triggered by crafted FHIRPath expressions. -
Feathersjs Prototype Pollution β CVE ThreatInt
Prototype pollution in @feathersjs/commons _.merge utility in versions 5.0.44 and earlier via JSON-parsed input, enabling potential remote code execution or logic bypass. -
websocket-driver Resource Limit Bypass & websocket-driver Message Corruption β CVE ThreatInt
Denial-of-service and message corruption vulnerabilities in websocket-driver prior to 0.7.5 via abuse of permessage-deflate compression and protocol length headers. -
Avo Missing Authorization in Association Attach Endpoint β CVE ThreatInt
Unauthorized attackers can attach associations in Ruby on Rails Avo admin panels prior to 3.32.1 and 4.0.0.beta.51 due to missing authorization checks. -
view_component HTML-Safety Bypass & view_component Stale Render Context β CVE ThreatInt
Multiple issues in Ruby on Rails view_component 4.0.0 to 4.12.0 allow HTML injection and stale render context retention, risking XSS and data leakage. -
Langflow RCE, DoS, Path Traversal & Langflow Hardcoded Credentials β CVE ThreatInt
IBM Langflow OSS versions 1.0.0 to 1.10.1 vulnerable to remote code execution, denial of service, path traversal, and contains hardcoded credentials used for authentication and external comms. -
dd-trace-py W3C Baggage Header Parsing DoS & dd-trace-go W3C Baggage Header Parsing DoS β CVE ThreatInt
Datadog tracing clients for Python and Go prior to 4.8.2 and 2.8.1 improperly parse W3C baggage headers, enabling denial-of-service attacks. -
ps_facetedsearch PHP Object Injection β CVE ThreatInt
PrestaShop ps_facetedsearch module 3.0.0 to 4.0.4 vulnerable to PHP object injection via crafted search filter requests, enabling remote code execution. -
OpenMcdf Infinite Loop DoS β CVE ThreatInt
OpenMcdf 3.1.3 and earlier vulnerable to uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry, causing denial of service in .NET applications processing Compound File Binary Format files.
π΅οΈ THREAT RESEARCH & DEEP DIVES
-
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT β The Hacker News
Checkmarx researchers uncovered a supply chain attack involving seven malicious npm packages targeting Vite frontend tooling. The campaign βViteVenomβ uses a complex four-tier blockchain-based command-and-control infrastructure leveraging Tron and others, marking a novel C2 technique. -
OpenSSL HollowByte Flaw Causes Memory Freeze with 11-Byte TLS Requests β The Hacker News
Okta Red Team disclosed a denial-of-service bug in OpenSSL where crafted 11-byte TLS requests cause servers to reserve up to 131 KB of memory indefinitely until restart. The flaw was silently fixed in June with no CVE or advisory.
π VENDOR BULLETINS & ADVISORIES
- Cloudflare WAF Protects Against Two High-Severity WordPress Vulnerabilities β Cloudflare Blog
Cloudflare deployed WAF rules to block exploitation of two critical WordPress vulnerabilities disclosed by the WordPress security team. Customers should still patch immediately despite WAF protection.
π° LESSER-KNOWN / UNDER-REPORTED
- Googleβs Gemini Lets Strangers Send Messages from Locked Android Phones β Graham Cluley
Googleβs AI assistant Gemini currently allows unauthorized users to send messages from locked Android devices, exposing a new attack surface for physical device abuse. Users should monitor device permissions and updates.