< ciso
brief />
Tag Banner

All news with #active exploitation tag

777 articles · page 4 of 39

Critical Check Point SmartConsole Authentication Bypass

🔒 Check Point released a jumbo hotfix (July 22, 2026) addressing multiple security hardening issues across firewall and management products. The advisory details several CVEs, including CVE-2026-16232, an authentication bypass affecting Management when exposed to the internet without IP restrictions, which was observed in the wild. The update provides mitigation guidance, IoCs, and installation instructions for the hotfix; customers are urged to apply it and follow best practices.
read more →

Active exploitation of Windmill path traversal bug

🛡️ A high-severity path traversal flaw in open-source developer platform Windmill (CVE-2026-29059, CVSS 7.5) has been observed exploited in the wild to read arbitrary files via the get_log_file endpoint. The issue allowed attackers to access sensitive files such as /etc/passwd and, where configured, the SUPERADMIN_SECRET value, enabling superadmin access. Windmill patched the vulnerability in version 1.603.3 by adding filename sanitization; about 170 vulnerable systems across 24 countries were identified.
read more →

Ubuntu snap-confine local root escalation CVE

🔒 A high-severity vulnerability in Ubuntu's snap-confine component (CVE-2026-8933) lets any local user gain full root on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. Qualys TRU published research on July 21 showing two race conditions introduced after a hardening change to set-capabilities; attackers can exploit a brief ownership window via FUSE mounts and symlinks, then bypass AppArmor to execute commands as root. Canonical has issued patches and admins are urged to update snapd immediately.
read more →

Critical SharePoint RCE Exploited to Steal Machine Keys

🔒 Microsoft SharePoint's critical CVE-2026-50522 vulnerability is being actively exploited in the wild to steal machine keys and preserve access post-patch. Researchers observed attackers leveraging a public proof-of-concept to trigger deserialization-based remote code execution against on-premises SharePoint, allowing creation of forged authentication tokens. Microsoft fixed the flaw in July, but security firms advise rotating exposed credentials and confirming patches.
read more →

Critical wp2shell WordPress flaws exploited widely

🔒 Hackers are actively exploiting the wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) in WordPress Core to install persistent webshells and malicious plugins. The exploit abuses the REST API batch-processing feature to achieve unauthenticated remote code execution. WordPress released emergency patches (7.0.2, 6.9.5, 6.8.6) and forced automatic updates while researchers report mass scanning, plugin abuse, and backdoor deployments.
read more →

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation

🛡️ Microsoft patched a critical SharePoint Server deserialization flaw, CVE-2026-50522 (CVSS 9.8), which is now being actively exploited. DEVCORE researcher splitline reported the issue; Microsoft warned authenticated attackers with Site Owner privileges could execute remote code. Security firms and CISA observed attackers stealing machine keys and urged credential rotation even after patching.
read more →

Critical GlobalProtect VPN Bug Now Used in Ransomware

🔒 Palo Alto Networks patched a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) on May 13 after Rapid7 observed active exploitation from May 17. Arctic Wolf reports the Qilin ransomware gang is leveraging the flaw to gain unauthorized VPN access and deploy ransomware, with incidents in June resulting in domain-wide encryption. CISA added the vulnerability to its Known Exploited Vulnerability catalog and ordered federal agencies to remediate within three days.
read more →

Fake CAPTCHA Click-Fraud Used to Activate Malware

🔒 Ukraine's CERT-UA warns that Russian-linked Sandworm actors are using fake CAPTCHA prompts on compromised sites to trick users into pasting and executing PowerShell commands on their PCs. The campaign, attributed to UAC-0145, began surging in June and has compromised at least ten websites, deploying a reconnaissance tool called ScoutCurl. These "ClickFix" attacks coerce victims to run legitimate tools like PowerShell, making them effective and dangerous.
read more →

Widespread wp2shell WordPress RCE and exploitation

🛡️ Attackers are actively exploiting two critical WordPress flaws, CVE-2026-63030 and CVE-2026-60137, together dubbed wp2shell, enabling unauthenticated remote code execution on default installations. Researchers report rapid abuse following public exploit release, extensive scanning, and post-exploitation activity including malicious plugin uploads, web shells, and creation of backdoor admin accounts. Organizations are urged to patch and inspect sites for indicators of compromise.
read more →

Weekly cyber recap: critical bugs, active exploits

⚠️ This week saw small inputs produce severe outcomes: unauthenticated RCEs in WordPress Core, SonicWall SMA zero-days exploited in the wild, OpenSSL DoS via an 11-byte payload, and a SharePoint RCE added to CISA's KEV catalog. Other notable items include the OkoBot malware framework targeting crypto wallets, the NadMesh botnet harvesting cloud keys, and a long list of high-priority CVEs that require immediate patching and investigation.
read more →

Critical ServiceNow RCE Flaw Now Observed Exploited

🛡️ Security researchers report active exploitation of a pre-auth sandbox escape and remote code execution bug (CVE-2026-6875) in the ServiceNow AI Platform. The vulnerability, disclosed in early April and patched for hosted and self-hosted instances in mid-July, allows unauthenticated actors to execute code by escaping the platform sandbox. Defused confirmed in-the-wild attacks days after patches were released, though ServiceNow states it is not currently aware of exploitation against instances and urges customers to apply updates immediately.
read more →

Hackers Abuse ViPNet Updates to Target Russian Agencies

🔍 Researchers at Kaspersky say an advanced threat actor, tracked as HelloNet, has abused the ViPNet update mechanism since at least May to deliver a loader and proxy targeting Russian organizations, including government agencies. Attackers dropped a malicious DLL (wtsapi32.dll, "HelloInjector") into the local ViPNet Update System to be sideloaded by the legitimate updater, gaining persistence and elevated privileges. The campaign delivers additional modules—HelloProxy, HelloExecutor, HelloCleaner, and a Rust-based HelloBackdoor—enabling command execution, file transfer, reconnaissance, and log removal. Kaspersky assigns low-confidence attribution to a Chinese-speaking APT and recommends close monitoring of systems running ViPNet, especially traffic on ports 5003, 5060, and 443.
read more →

Critical wp2shell RCE in WordPress core requires patch

🔒 Public proof-of-concept exploits have been released for the critical "wp2shell" pre-authentication remote code execution chain affecting WordPress Core. The attack combines two flaws, CVE-2026-63030 and CVE-2026-60137, impacting WordPress 6.9.x and 7.0.x, prompting forced auto-updates to versions 6.9.5 and 7.0.2. Administrators are urged to patch immediately or apply temporary WAF/REST API mitigations while updates are applied.
read more →

CISA urges immediate patching of Fortinet FortiSandbox

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) has added two critical FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply patches by July 19. Both flaws are OS command injection bugs with CVSS scores of 9.1 and have documented in-the-wild exploitation. Fortinet released fixes in FortiSandbox versions 4.4.9 and 5.0.6; CISA advised discontinuing cloud services where mitigations are unavailable.
read more →

CISA orders urgent FortiSandbox patches for agencies

🔒 CISA has ordered U.S. federal agencies to urgently patch two actively exploited critical vulnerabilities in the Fortinet FortiSandbox platform. The flaws (CVE-2026-39808 and CVE-2026-25089) were fixed by Fortinet in April and June, and allow unauthenticated remote command injection with low complexity. Defused and CISA confirmed in-the-wild exploitation, and agencies must remediate by Sunday, July 19. Administrators are advised to upgrade affected deployments to the latest released versions to block attacks.
read more →

CISA Lists Exploited SharePoint RCE in KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Microsoft SharePoint Server vulnerability, CVE-2026-58644 (CVSS 9.8), to its Known Exploited Vulnerabilities catalog, requiring Federal agencies to patch by July 19, 2026. Microsoft confirmed the flaw enables remote code execution via deserialization of untrusted data and has been exploited in the wild; fixes were issued on Patch Tuesday, July 14, 2026. Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. CISA also warned of active exploitation of multiple SharePoint flaws and recommended hardening steps including applying updates, enabling AMSI, rotating IIS machine keys, limiting internet exposure, and tightening access controls.
read more →

Patch surge strains defenders amid AI‑driven finds

🔥 This week’s Threat Source highlights a record Microsoft Patch Tuesday that fixed 622 vulnerabilities, including two zero‑days being actively exploited. Cisco Talos discloses UAT‑11795, a Russian‑speaking group using trojanized installers to deliver the Python-based Starland RAT and an in-memory PowerShell implant called WLDR agent. The newsletter outlines detection guidance and emphasizes the operational stress on IT teams facing accelerated vulnerability discovery driven by frontier AI research.
read more →

Weekly roundup: emerging cyber threats and takedowns

🛡️ This week’s roundup highlights a wave of opportunistic attacks where familiar software and weak defaults are abused to escalate damage quickly. Reports include malicious NuGet packages that deliver spyware via game cheats, trojanized installers distributing sophisticated RATs, and a fast-spreading Rust ransomware incident that encrypted a network within 24 hours. Additional items cover actively exploited CVEs added to CISA’s KEV, guidance for coordinated vulnerability disclosure, large-scale fraud and money‑laundering disruptions in Europe, evasive Windows bind-link techniques, fake GitHub repos spreading an infostealer, and misuse of Chrome Sync for covert surveillance.
read more →

CISA urges immediate SharePoint hardening now

🔒 CISA has warned that three Microsoft SharePoint vulnerabilities are being actively exploited and urged organizations to immediately patch on-premises SharePoint deployments. Administrators should follow Microsoft’s mitigation guidance, enable AMSI integration, hunt for indicators of compromise, and rotate machine keys where appropriate. The agency added CVE-2026-33201, CVE-2026-45659, and the newly listed CVE-2026-56164 to its Known Exploited Vulnerabilities catalog and required rapid remediation for federal agencies.
read more →

CISA orders federal patching for exploited Oracle EBS flaw

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch systems by Saturday to mitigate active exploitation of a critical Oracle E-Business Suite vulnerability, tracked as CVE-2026-46817. The flaw in the Oracle Payments File Transmission component allows unauthenticated HTTP access leading to system takeover in low-complexity attacks. Oracle issued fixes in its May 2026 Critical Security Patch Update and urged immediate patching, while security firms and CISA have observed active exploitation. Shadowserver reports over 1,000 Internet-exposed Oracle EBS instances, many in the U.S., prompting CISA to add the flaw to its list of known exploited vulnerabilities and mandate remediation under BOD 26-04.
read more →