View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

GiveWP flaw enables unauthenticated PHP object injection and RCE

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • GiveWP flaw enables unauthenticated PHP object injection and remote code execution
    GiveWP sites are exposed to unauthenticated remote code execution.

    • GiveWP sites with one published donation form and one active payment gateway are affected.
    • Unauthenticated attackers can inject PHP objects and execute arbitrary commands on the server.
    • Exploitation depends on the object-injection chain being fully reachable in the installed version.
      ๐Ÿ“Ž Coverage: patchstack.com ยท ๐Ÿ‘ via patchstack.com (discovered)
  • Bauman University Leak Exposes GRU Cyber Training Pipeline
    Leaked Bauman University records expose a GRU cyber-training pipeline.

    • Bauman Moscow State Technical Universityโ€™s Department No. 4 trained about 250 career and reserve students for GRU-linked roles.
    • Students studied special intelligence, information-technical effects, and information-technology protection.
    • Records link graduates and supervisors to GRU Military Units 26165, 74455, and 29155, associated with APT28 and Sandworm.
    • Training covered password attacks, server exploitation, malware development, vulnerability research, penetration testing, cryptography, and intrusion detection.
    • Practical exercises examined phishing, self-extracting archives, renamed UltraVNC binaries, command-and-control infrastructure, script deobfuscation, and system-call monitoring.
      ๐Ÿ“„ Source: dti.domaintools.com ยท ๐Ÿ“Ž Coverage: hendryadrian.com ยท ๐Ÿ‘ via Cyber Security News
  • A crafted link can open Slack Desktopโ€™s debugging port
    A crafted link can open Slack Desktopโ€™s remote debugging port.

    • The issue affects users of Slackโ€™s desktop application.
    • A single link can open a debugging port in the app.
    • Slack reportedly does not plan to patch the behavior.
    • No CVE has been assigned.
      ๐Ÿ“Ž Coverage: trustsig.eu ยท ๐Ÿ‘ via r/netsec

๐Ÿ”“ CVEs & KEV

  • CVE-2026-75005 โ€” CVSS 8.7 โ€” Apache APISIX: Unauthenticated CPU-exhaustion DoSInefficient Algorithmic Comp...

  • CVE-2026-81625 โ€” CVSS 8.7 โ€” Stack buffer overflow in Greenbone OS and openvas-scannerA remote attacker wi...

  • CVE-2026-74848 โ€” CVSS 7.0 โ€” Apache APISIX: Cross-user response poisoning in serverless pluginsInconsisten...

  • CVE-2026-75020 โ€” CVSS 7.0 โ€” Apache APISIX: ldap-auth plugin cross-subtree identity impersonationImproper ...

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for Rently Smart Home flaw exposed master PINs and user permissions โ€” msrc.microsoft.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check