🚨 ACTIVE EXPLOITATION
-
Active Exploitation of Windmill CVE-2026-29059 Allows Unauthenticated Arbitrary File Read — thehackernews.com
Hackers are exploiting a path traversal flaw in Windmill to read arbitrary server files without authentication.- Applies to Windmill open-source developer platform versions prior to 1.603.3
- Vulnerability CVE-2026-29059 affects the get_log_file API endpoint allowing path traversal via unsanitized filename parameter
- Attackers use ../ sequences to read arbitrary files including sensitive ones like /etc/passwd and /proc/1/environ
- If SUPERADMIN_SECRET environment variable is set, attackers can authenticate as superadmin and execute arbitrary code
- Exploitation observed globally with about 170 vulnerable systems across 24 countries targeted
-
Vulnerability in Adobe Acrobat Chrome Extension Enabled Theft of WhatsApp Data — securityweek.com
A flaw in Adobe Acrobat Chrome extension allowed attackers to steal WhatsApp messages and contacts.- Applies to Adobe Acrobat Chrome extension with approximately 329 million installs
- Vulnerability is a UXSS cross-origin data disclosure flaw (CVE-2026-48294)
- Attack requires victim to visit a malicious website that triggers the exploit
- Exploit abuses extension's internal messaging to activate dormant Hermes engine
- Hermes engine bridges to WhatsApp Web to exfiltrate chats, contacts, and account info
💥 BREACHES & INCIDENTS
- Data Breaches at Suno and Paidwork Expose Tens of Millions of User Records — securityweek.com
Hackers leaked tens of millions of user records from Suno and Paidwork platforms.- Suno AI music generator breached in Nov 2025, exposing 55.3 million unique emails and source code
- Leaked Suno data includes names, emails, phone numbers, Stripe payment records with partial card info
- Paidwork gig platform breached in Mar 2026, leaking 23.3 million unique emails and 11 GB of user data
- Paidwork data includes names, password hashes, addresses, birthdates, phone numbers, bank details, transactions
- Data breaches revealed by Have I Been Pwned and reported by SecurityWeek
🕵️ RESEARCH & DEEP DIVES
-
Authentication Bypass in Check Point Security Management Enables Remote Admin Command Execution — cve.threatint.com
Check Point Security Management has an authentication bypass vulnerability allowing remote admin command execution.- Affects Check Point Security Management and Multi-Domain Security Management products
- Vulnerability allows unauthenticated remote attackers to execute administrative commands on Management Server
- Successful exploitation may enable command execution on managed Security Gateways
- Exploitation requires network access to Management Server without firewall protection or unrestricted Trusted Clients
- Impacted versions include R82.10 (Jumbo Hotfix Take 36 or below), R82 (Jumbo Hotfix Take 118 or below), R81.20 (Jumbo Hotfix Take 158 or below), and all versions of R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
-
Authentication Bypass in Check Point SmartConsole Allows Remote Admin Access — cve.threatint.com
Check Point SmartConsole has an authentication bypass vulnerability enabling remote admin access.- Applies to Check Point SmartConsole versions R77.30 through R82.10 with specific Jumbo Hotfixes
- Vulnerability allows unauthenticated remote attackers to obtain an application login token
- Attackers can authenticate with full administrative privileges and modify security policies
- Exploitation requires internet access to Management Server IP and unrestricted Trusted Clients configuration
- Check Point confirms active exploitation affecting a very small number of customers
📌 THREAT RESEARCH & DEEP DIVES
-
Enterprise GenAI amplifies ransomware risk by accelerating attacks via compromised identities — bleepingcomputer.com
Enterprise generative AI can accelerate ransomware attacks when AI identities are compromised.- Applies to enterprises deploying AI assistants and AI agents with access to business systems
- AI assistants retrieve data; AI agents perform actions with delegated permissions
- Attackers exploit compromised AI identities to speed up reconnaissance, credential abuse, and data theft
- AI amplifies existing ransomware tactics rather than creating new attack methods
- Examples include AI-generated phishing, automated reconnaissance, and AI chatbots for ransom negotiations
-
Proofpoint: Over One-Third of Ransomware Victims Face Second Extortion Demand — techcrunch.com
Proofpoint found that over one-third of companies paying ransomware ransoms received a second extortion demand.- Applies to ~950 companies surveyed by Proofpoint across various sectors
- Over one-third of companies that paid ransom were targeted with a second extortion demand
- Ransomware attacks now use multiple leverage tactics, including threats to release stolen data
- Examples include Klue and Change Healthcare where data was retained and re-extorted despite ransom payments
- UK law enforcement found stolen victim data retained on LockBit servers after ransom payments
🔓 CVEs & KEV
- 20 CVEs reported this run, with the highest severity rating at 8.1.