View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

New wp2shell WordPress Core RCE Flaw

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Inc Ransomware Exploits SonicWall SMA Zero-Days β€” Dark Reading
    New ransomware campaign actively chaining two SonicWall SMA zero-day vulnerabilities to gain root-level access on SonicWall mobile access appliances. Immediate patching and monitoring of SonicWall SMA devices is critical to prevent compromise.

  • Abbott Laboratories Investigates Two Cyber Incidents Amid Extortion Claims β€” BleepingComputer
    Abbott Labs confirmed unauthorized access to legacy Exact Sciences systems and a separate breach of its LabCentral portal with data theft. The incidents involve extortion threats, indicating active attacker presence targeting healthcare diagnostics infrastructure.

πŸ”“ VULNERABILITIES & CVEs

πŸ•΅οΈ THREAT RESEARCH & DEEP DIVES

  • Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver RAT β€” The Hacker News
    Checkmarx researchers uncovered a supply chain attack involving seven malicious npm packages targeting Vite frontend tooling. The campaign β€œViteVenom” uses a complex four-tier blockchain-based command-and-control infrastructure leveraging Tron and others, marking a novel C2 technique.

  • OpenSSL HollowByte Flaw Causes Memory Freeze with 11-Byte TLS Requests β€” The Hacker News
    Okta Red Team disclosed a denial-of-service bug in OpenSSL where crafted 11-byte TLS requests cause servers to reserve up to 131 KB of memory indefinitely until restart. The flaw was silently fixed in June with no CVE or advisory.

πŸ“‹ VENDOR BULLETINS & ADVISORIES

πŸ“° LESSER-KNOWN / UNDER-REPORTED

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check