๐ต๏ธ RESEARCH & DEEP DIVES
- Dark Caracal Deploys GoCaracal Malware Framework in Latin America
Dark Caracal is using the new GoCaracal framework for cyberespionage.- Dark Caracal targets Latin American organizations, including a Venezuelan communications organization.
- Arctic Wolf analyzed about 250 GoCaracal samples and identified lightweight and extended builds.
- GoCaracal steals files and credentials, logs keystrokes, and provides interactive remote shells.
- Spanish-language financial and document-themed domains deliver malicious SVG files, with GoCaracal deployed alongside updated Bandook.
- The extended build uses an Ethereum-based database to locate backup command-and-control servers.
๐ Source: arcticwolf.com ยท ๐ Coverage: darkreading.com ยท ๐ via Dark Reading
๐ ADVISORIES
-
Trump order restricts risky foreign equipment in U.S. bulk-power system
Trump has declared a national emergency over foreign equipment risks to the U.S. bulk-power system.- The order affects U.S. bulk-power system equipment, excluding local electric distribution facilities.
- Covered equipment includes foreign-produced electrical hardware, critical components, software, firmware, digital services, maintenance services and remote-access capabilities.
- The Energy Secretary can prohibit post-Aug. 26, 2026 acquisitions, imports, transfers or installations tied to covered foreign entities.
- Officials cite risks including sabotage, unauthorized access, malicious remote actions, supply disruption and digital backdoors.
๐ Source: whitehouse.gov ยท ๐ Coverage: cyberscoop.com ยท ๐ via CyberScoop
-
Critical Avada WordPress Theme Flaw Enables Unauthenticated RCE
Wordfence disclosed a critical unauthenticated RCE in the Avada WordPress theme.- WordPress sites using Avada and its bundled Fusion Builder are affected; the theme has over 1 million sales.
- Avada versions up to and including 7.16 are vulnerable with Fusion Builder up to and including 3.16; CVE-2026-18431.
- A six-step chain of authorization and input-validation weaknesses enables unauthenticated arbitrary file writes.
- Attackers can write and execute arbitrary PHP, requiring both components to be active and certain administrator-authored content to be present.
๐ Coverage: therepository.email ยท ๐ via BleepingComputer
๐ CVEs & KEV
-
CVE-2026-65641 โ CVSS 9.3 โ A vulnerability allowing an unauthenticated network attacker to coerce SMB au...
-
CVE-2026-65646 โ CVSS 8.7 โ Improper neutralization of special elements in Plesk allows remote authentica...
-
CVE-2026-65647 โ CVSS 8.7 โ Improper symlink resolution before file access in Plesk allows remote authent...
-
CVE-2026-77298 โ CVSS 8.7 โ SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policySeaweed...
-
CVE-2026-55182 โ CVSS 8.6 โ LibreNMS: Remote Code Execution by Signal Alert Transportation ModuleLibreNMS...
-
CVE-2026-65642 โ CVSS 8.6 โ Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 th...
-
CVE-2026-77317 โ CVSS 8.1 โ SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read ...
-
CVE-2026-80182 โ CVSS 7.6 โ In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token,...
-
CVE-2026-77368 โ CVSS 7.6 โ SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbit...
-
CVE-2026-77611 โ CVSS 7.1 โ SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwr...