View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

TranslatePress Flaw Enables Unauthenticated WordPress Account Takeover

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ’ฅ BREACHES & INCIDENTS

  • (no items)

๐Ÿ”“ CVEs & KEV

  • (no items)

๐Ÿ“‹ ADVISORIES

  • SonicWall NetExtender Flaws Enable Arbitrary File Writes as Root
    SonicWall disclosed two vulnerabilities in its NetExtender Linux client.
    • SonicWall NetExtender Linux Client versions 10.3.5 and earlier are affected; Windows clients are not.
    • CVE-2026-66152 is an 8.8-rated path traversal flaw in OPSWAT tarball handling that enables arbitrary file writes with root privileges.
    • CVE-2026-66153 is a 7.0-rated improper link-resolution flaw in the NEService auto-upgrade process.
    • The first flaw uses crafted directory traversal paths and requires network access plus user interaction; the second enables local symlink or temporary-file manipulation with low privileges.
    • SonicWall reported no evidence of exploitation in the wild; the fixed release is NetExtender Linux Client 10.3.6 or later.
      ๐Ÿ“„ Source: psirt.global.sonicwall.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ“ฐ UNDER-REPORTED

  • dindoor-deno-backdoor โ€” Cyber Security News

  • ๐Ÿ“„ Source for Mirage2FA Hijacks Microsoft 365 Sessions After Users Complete MFA โ€” any.run

  • ๐Ÿ“„ Source for INTERPOL Operation Jackal IV Arrests 58 in Black Axe Crackdown โ€” interpol.int

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check