🚨 ACTIVE EXPLOITATION
-
SonicWall SMA1000 zero-days exploited to deploy custom malware — bleepingcomputer.com
Two zero-day vulnerabilities in SonicWall SMA1000 appliances were exploited to install custom malware.- Applies to SonicWall SMA1000 6210, 7210, and 8200v VPN appliances
- Vulnerabilities: CVE-2026-15409 (critical SSRF) and CVE-2026-15410 (high-severity command injection)
- Attackers exploited /wsproxy endpoint to create unauthenticated WebSocket tunnels exposing internal services
- Used product_uuid from CouchDB to trigger command injection via sysCtrl.execRemoveHotfix RPC method
- Installed custom malware: KNUCKLEBALL dropper deploying Sou5 reverse proxy and ORANGETAIL Java webshell
-
WP2Shell Exploit Enables Remote Takeover of Millions of WordPress Sites — darkreading.com
Attackers are actively exploiting CVE-2026-60137 and CVE-2026-63030 to compromise WordPress sites.- Applies to millions of WordPress sites worldwide
- Vulnerabilities CVE-2026-60137 and CVE-2026-63030 allow pre-auth remote code execution
- Attackers chain both vulnerabilities to achieve remote takeover
- Exploit attempts began within three days of public disclosure
💥 BREACHES & INCIDENTS
-
Hackers steal $23.7M from Ostium via off-chain price feed manipulation — bleepingcomputer.com
Hackers stole $23.75 million from Ostium by manipulating off-chain price feeds.- Applies to Ostium decentralized trading platform on Arbitrum blockchain
- Attack targeted off-chain infrastructure feeding price data into the protocol
- Attackers submitted fake price reports to generate artificial profits
- Stolen funds came from liquidity provider vault, not trader collateral
- Exploiter swapped stolen USDC for Ethereum and laundered via TornadoCash
-
Estée Lauder suffers data breach via Oracle E-Business Suite vulnerability — bleepingcomputer.com
Estée Lauder experienced a data breach through an Oracle E-Business Suite flaw.- Applies to Estée Lauder customers and HR data managed via Oracle E-Business Suite
- Hackers exploited a vulnerability in Oracle E-Business Suite used for HR operations
- Data breach involves unauthorized access to sensitive customer and employee information
🕵️ RESEARCH & DEEP DIVES
-
Sandbox escapes found in Cursor, Codex, Gemini CLI, and Antigravity AI coding agents — bleepingcomputer.com
Researchers demonstrated sandbox escapes in four AI coding agents via file-based attacks.- Applies to Cursor, OpenAI Codex CLI, Google Gemini CLI, and Antigravity AI coding tools
- Sandbox escapes occur by writing files inside the sandbox that trusted host tools later execute
- Attack leverages prompt injection to craft malicious files triggering code execution outside sandbox
- Multiple vulnerabilities patched including CVE-2026-48124 in Cursor 3.0.0 and Codex CLI v0.95.0
- Google downgraded severity of Antigravity issues due to exploitation difficulty requiring social engineering
-
FreeRDP before 3.28.0 vulnerable to RCE via malicious CLI options in RDP files — cve.threatint.com
FreeRDP before version 3.28.0 allows remote code execution via crafted RDP files.- Applies to FreeRDP versions before 3.28.0
- Vulnerability in RDP file parser treating lines starting with '/' as CLI options
- Attackers can craft malicious RDP files to execute arbitrary commands remotely
- Exploits include bypassing certificate validation and exposing local filesystems
- No user interaction required for exploitation
⚠️ LESSER-KNOWN / UNDER-REPORTED
- JadePuffer ransomware targets AI model data with custom EncForge malware — bleepingcomputer.com
JadePuffer ransomware now encrypts AI model data using the EncForge malware.- Targets AI and machine learning infrastructure including model checkpoints, vector databases, and training datasets
- Uses Go-based EncForge ransomware targeting 180 file extensions specific to AI/ML formats
- Attack exploits Langflow vulnerability CVE-2025-3248 and exposed Docker socket for root access
- EncForge encrypts files with AES-256 and RSA-2048 hybrid scheme, appending .locked extension
- No evidence of data exfiltration; attack automates payload delivery via Python scripts within minutes
🔓 CVEs & KEV
- Other: 19 CVEs (worst 9.8)