Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.
The wire
Thursday, Aug 277 stories
- The Hacker NewsAmazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers
Researchers disclosed a vulnerability in Amazon's Kiro IDE that allows attackers to steal sensitive local data through prompt injection and the IDE's 'Kiro Powers' feature. The flaw, which affects version 0.7.45 on Windows, enables malicious repository content to manipulate the AI agent into transmitting information to external endpoints without explicit user consent. Amazon has resolved the issue in version 0.8.140, though users of older versions remain exposed to this low-difficulty exploitation path.
AdvisoryAmazon - Help Net SecurityUnknown PaperCut NG/MF vulnerability is under active attack
PaperCut Software has warned that attackers are currently exploiting an undisclosed vulnerability in its PaperCut NG and PaperCut MF print management platforms. While no specific CVE ID has been assigned yet, the vendor advises administrators whose Application Servers are exposed to the public internet to immediately restrict web access to trusted IP addresses. Organizations should also monitor their server logs for signs of compromise, such as missing entries or specific database error messages, as a definitive patch is still under investigation.
Reported exploitedPaperCut - The Hacker NewsSpark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Researchers at Acronis have identified a targeted cyber operation affecting individuals and organizations in Cambodia, centered on the deployment of the open-source Spark RAT. The multi-stage intrusion chain leverages the Bring Your Own Vulnerable Driver (BYOVD) technique, specifically exploiting a vulnerability in the OPSWAT AppRemover component ardrv.sys assigned as CVE-2026-36425. Attackers distribute phishing emails containing lures such as local government notices and health documents to deliver malicious archives that execute a signed Tencent binary. Once executed, the malware employs DLL side-loading to escalate privileges and neutralize security software, including Microsoft Defender, Huorong Internet Security, and Tencent PC Manager. While the infrastructure shares tactical similarities with the Silver Fox threat actor group, particularly in the use of specific vulnerable drivers and persistence mechanisms, Acronis classifies this activity as an unattributed cluster due to a lack of definitive code or infrastructure overlap.
ResearchOPSWAT AppRemover - Help Net SecurityPreviously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
CISA has designated CVE-2026-8452 as actively exploited, adding it to its Known Exploited Vulnerabilities catalog following the public release of a proof-of-concept exploit by watchTowr Labs. This vulnerability affects Citrix NetScaler ADC and Gateway appliances configured with specific virtual servers, where a memory overflow can lead to denial of service or potentially unauthenticated remote code execution. While Citrix issued patches on June 30, 2026, attackers began leveraging the flaw shortly after the technical details were shared, deploying web shells for initial access.
Reported exploitedCitrix NetScaler ADC - BleepingComputerCISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, directing federal agencies to patch affected Citrix NetScaler ADC and NetScaler Gateway appliances by Saturday. Although initially disclosed in June as a memory overflow risk limited to denial-of-service impacts, recent research confirms that threat actors are using the bug to achieve remote code execution as root. With over 22,000 exposed appliances identified online, the directive under BOD 26-04 highlights the critical need for immediate remediation against these active attacks.
Reported exploitedNetScaler ADC - The Hacker NewsCISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
CISA has updated its Known Exploited Vulnerabilities catalog with six critical flaws affecting major enterprise infrastructure, including a denial-of-service issue in Citrix NetScaler ADC/Gateway (CVE-2026-8452). The list also includes remote code execution bugs in Microsoft SQL Server (CVE-2019-1068) and Ajax.NET Professional (CVE-2021-23758), alongside kernel and privilege escalation vulnerabilities in the Linux Kernel (CVE-2022-0995), Red Hat ABRT (CVE-2015-5287), and Red Hat libuser (CVE-2015-3246). Security researchers have observed active exploitation of the Citrix flaw, where attackers deploy PHP web shells and execute discovery commands from multiple countries. These additions follow Cisco Talos reporting on a Chinese cybercrime group targeting global server ecosystems, prompting federal agencies to remediate the highest-priority items by August 29, 2026.
Reported exploitedCitrix NetScaler ADC - SecurityWeekRecent Citrix NetScaler Vulnerability Exploited in the Wild
CISA has directed US government organizations to urgently remediate CVE-2026-8452, a high-severity flaw in Citrix NetScaler that is currently being actively attacked. Although initially described by the vendor as a potential denial-of-service issue, security researchers have confirmed that the vulnerability allows for unauthenticated remote code execution on devices configured as AAA virtual servers or Gateway VPN servers. Active exploitation involves attackers deploying web shells and running reconnaissance commands, prompting CISA to add the bug to its Known Exploited Vulnerabilities catalog with an August 29 deadline. To mitigate the risk, administrators must update their appliances to fixed versions 14.1-72.61 (FIPS), 13.1-63.18, or 13.1-37.272.
Reported exploitedCitrix NetScaler
Wednesday, Aug 2612 stories
- BleepingComputerCritical Avada WordPress theme flaw enables zero-click RCE
Researchers at Wordfence have disclosed a critical vulnerability chain, tracked as CVE-2026-18431, that allows unauthenticated attackers to execute arbitrary PHP code on websites using the Avada theme and Fusion Builder plugin. With a CVSS score of 9.8, this zero-click exploit combines six distinct security flaws to compromise the server, enabling actions such as database access or the creation of rogue administrator accounts. A proof-of-concept exploit is now available following discovery by Wordfence’s agentic framework, Argus. ThemeFusion has addressed the issue in recent updates; administrators should immediately upgrade to Avada 7.16.1 and Fusion Builder 3.16.1 to mitigate the risk.
PoC publicAvada - The Hacker NewsFBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice has announced the seizure of infrastructure supporting the Chinese state-sponsored threat actor QTFY, specifically targeting the QScan and QTRouter botnets. These platforms were utilized to breach critical U.S. institutions, including NASA, the Federal Reserve, and the Department of Energy, by exploiting vulnerabilities in vendor products such as Ivanti, Fortinet, Citrix, Microsoft, F5, Atlassian, Check Point, and BeyondTrust. Notable exploits included zero-days like CVE-2024-8190 in Ivanti appliances and N-days such as CVE-2018-13379 in Fortinet SSL-VPN, allowing the group to maintain persistence and obfuscate traffic through compromised OpenWrt-based devices.
IncidentQScan - BleepingComputerHackers target Microsoft SharePoint RCE chain with PoC exploit
Threat intelligence firm Defused reports that attackers are actively chaining Microsoft SharePoint vulnerabilities CVE-2026-55040 and CVE-2026-63520 to execute remote code on exposed infrastructure. The attack sequence begins with an unauthenticated JWT validation bypass that elevates privileges, followed by exploitation of a flaw in Business Connectivity Services to achieve full system compromise. Public proof-of-concept exploits for both issues were released in August, and the authentication bypass has been observed in the wild since shortly after its disclosure. While Microsoft has identified the RCE component as a high-value target, CISA issued an emergency directive on August 18 requiring federal agencies to patch the server immediately due to active exploitation.
Reported exploitedMicrosoft SharePoint - BleepingComputerUbiquiti patches three max severity security vulnerabilities
Ubiquiti has issued security updates for its UniFi Protect, UniFi OS, and UniFi Talk products to remediate three newly disclosed maximum-severity vulnerabilities. These flaws, tracked as CVE-2026-77537, CVE-2026-77550, and CVE-2026-77554, allow remote attackers to execute unauthorized actions without requiring prior authentication or user interaction. Administrators should upgrade to UniFi Protect Application version 7.2.105 or later, UniFi Talk Application version 5.3.2 or later, or UniFi OS Server version 5.1.21 or earlier to mitigate these risks.
PatchUniFi Protect - Bishop FoxA GUID is Not a Credential: Unauthenticated RCE in Veeam Service Provider Console
Bishop Fox demonstrated that a combination of two critical vulnerabilities in Veeam Service Provider Console allows attackers to achieve unauthenticated remote code execution without any prior credentials. CVE-2026-58073 permits an attacker to impersonate a connected backup agent to steal its certificate, while CVE-2026-58072 enables arbitrary file writes using that stolen identity. By chaining these flaws, researchers achieved full control over the console server running version 9.2.1. Organizations must upgrade to Veeam Service Provider Console 9.3.0 immediately and review logs for signs of exploitation.
PoC publicVeeam Service Provider Console - The Hacker NewsUnpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
CERT/CC has disclosed two critical, unpatched vulnerabilities in the Kaltura mwEmbed player library, specifically affecting html5lib versions v2.45 and v2.103 and earlier. The flaws, identified as CVE-2026-19913 and CVE-2026-19912, originate from unsafe deserialization in the mwEmbedLoader.php endpoint, allowing unauthenticated remote attackers to read arbitrary files and execute code without requiring a valid session token. Although no official patch is currently available because the vendor could not be reached, administrators are advised to immediately restrict external access to the endpoint and enforce strict allow-lists for the ServiceUrl parameter to mitigate these risks.
PoC publicmwEmbed - BleepingComputerHackers now exploit critical Gitea flaw in code injection attacks
CISA has confirmed that attackers are actively using a critical code injection vulnerability in Gitea to deploy cryptocurrency mining malware on self-hosted servers. Tracked as CVE-2026-60004, this flaw allows authenticated users with repository write access—and effectively any unregistered attacker due to default open registration—to execute arbitrary shell commands through the diffpatch API endpoint. The agency added the issue to its Known Exploited Vulnerabilities catalog and mandated federal civilian executive branch agencies apply fixes by August 28. Users should upgrade to Gitea version 1.27.1 immediately to mitigate these attacks.
Reported exploitedGitea - Help Net SecurityCritical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
CISA has confirmed active exploitation of CVE-2026-60004, a critical code injection flaw in the Gitea Git platform, listing it in its Known Exploited Vulnerabilities catalog. Attackers leverage the diffpatch endpoint to execute arbitrary shell commands, allowing them to deploy cryptocurrency miners on self-hosted instances where open registration is enabled. A detailed incident report highlights how automated scanners compromised outdated deployments within seconds, granting access to sensitive configuration files and environment variables. Administrators are advised to immediately upgrade to Gitea v1.27.2, disable unauthenticated account creation, and rotate all exposed secrets.
Reported exploitedGitea - Kaspersky SecurelistExploits and vulnerabilities in Q2 2026
Kaspersky's Q2 2026 report confirms that proof-of-concept exploits are now publicly available for critical weaknesses in Microsoft Windows Defender, BitLocker, and the Linux kernel. The release of functional code for issues like the "BlueHammer" TOCTOU vulnerability in Windows Defender and local privilege escalation bugs in the Linux page cache allows attackers to immediately target unpatched systems. Organizations should apply patches urgently to mitigate these newly exposed risks.
PoC publicWindows Defender - SecurityWeekChrome 152 Patches Over 300 Vulnerabilities
Google has released version 152 of its Chrome browser, resolving more than 300 security vulnerabilities, the bulk of which were identified through internal AI-assisted testing. Ten of these defects are rated as critical severity, primarily involving use-after-free errors in components like Angle and Aura. While most issues were found by Google's own teams, external researchers also contributed high-value findings, with one critical bug designated CVE-2026-79282 earning a bounty. No evidence of active exploitation was reported alongside the advisory.
PatchGoogle Chrome - The Hacker NewsCritical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload
CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, warning that attackers are actively using this critical remote code execution flaw in Gitea. Discovered by researcher Shai Rod, the vulnerability affects all versions from 1.17 onward and allows anyone with write access to a repository to execute arbitrary shell commands as the Gitea service user. Because open registration is often enabled by default, unauthenticated users can easily gain the necessary write privileges to trigger the exploit via the diffpatch endpoint. Recent incident reports indicate threat actors are leveraging this bug to deploy cryptocurrency-mining payloads onto compromised servers. Administrators must urgently upgrade to version 1.27.1 to mitigate the risk.
Reported exploitedGitea - SecurityWeekCISA Warns of Exploited Gitea Vulnerability
CISA has identified active exploitation of a remote code execution flaw in the self-hosted Git hosting platform Gitea. The vulnerability, designated as CVE-2026-60004, enables attackers with repository write access to inject malicious Git hooks through the diffpatch API endpoint. This defect was remediated in release version 1.27.1, and the agency has mandated that federal systems apply the patch immediately.
Reported exploitedGitea
Tuesday, Aug 259 stories
- The Hacker NewsA Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a vulnerability in NVIDIA NemoClaw that permits attackers to hijack local Ollama instances via malicious webpages, specifically on Windows and WSL configurations. By exploiting DNS rebinding against unauthenticated API endpoints bound to all network interfaces, threat actors can inject hidden instructions into AI model chat templates, thereby compromising agent behavior without user knowledge. While a patch for macOS and Linux is available in NemoClaw v0.0.35, affected Windows users should restrict exposure of port 11434, as no specific fix has yet been released for those platforms.
ResearchNVIDIA NemoClaw - SecurityWeekWordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing attackers to log in as any user, including administrators. The flaws, identified as CVE-2026-61979 and CVE-2026-15981, affect a widely used plugin with over 10,000 installations of its free edition alone. While patches are available, the lack of clear security advisories for paid versions complicates remediation efforts, making active mitigation essential.
Reported exploitedWordPress - The Hacker NewsMarimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo has patched a high-severity code injection vulnerability, tracked as CVE-2026-75149, which permitted attackers to execute unauthorized Model Context Protocol (MCP) commands within their notebook software. The flaw, rated 8.7 on the CVSS v4 scale, affects versions prior to 0.23.15 and allows a crafted notebook to launch a local subprocess containing attacker-controlled data when opened in edit mode. This risk arises before any notebook cells are executed, effectively bypassing standard execution boundaries. Users are advised to upgrade immediately to version 0.23.15 or later to mitigate this threat.
PatchMarimo Notebook Software - BleepingComputerHackers breached over 270 Zimbra servers in ongoing attacks
Over 270 internet-facing instances of Zimbra Collaboration Suite have been compromised through active exploitation of CVE-2026-73570, a high-severity remote code execution vulnerability. Synacor addressed this flaw, which involves command injection in the SNMP component when notifications are enabled, by releasing version 10.1.20. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog following reports from CERT Polska and Shadowserver, prompting urgent patching directives for federal agencies.
Reported exploitedZimbra Collaboration Suite - Help Net SecurityUnpatched Zimbra servers are falling to CVE-2026-73570 attacks
Shadowserver reports that at least 274 internet-exposed Zimbra Collaboration Suite instances have been breached through active exploitation of CVE-2026-73570. This unauthenticated code injection vulnerability impacts installations using the optional zimbra-snmp package with SNMP notifications enabled, allowing attackers to execute arbitrary OS commands. Synacor released a patch in version 10.1.20 on July 20, 2026, and CISA has now added the issue to its Known Exploited Vulnerabilities catalog, mandating remediation for federal agencies. With thousands of potentially vulnerable systems still unpatched, administrators are urged to apply the update immediately and audit their systems for signs of intrusion.
Reported exploitedZimbra Collaboration Suite - The Hacker NewsAttackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Attackers are actively targeting the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, leveraging two critical flaws to assume administrative control of vulnerable sites. The campaign exploits CVE-2026-61979 and CVE-2026-15981, which stem from a flawed signature validation process that incorrectly treats malformed inputs as successful verifications, enabling unauthorized session creation. Since a proof-of-concept exists for these authentication bypasses, site administrators should immediately update to version 17.0.6 of the Standard edition to mitigate this high-risk threat.
Reported exploitedminiOrange SAML 2.0 Single Sign On plugin - SecurityWeekCISA Warns of Exploited Oracle WebLogic Vulnerability
CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog, warning that this critical remote code execution flaw is being actively used against Oracle WebLogic environments. The vulnerability, rated with a perfect CVSS score of 10, affects both the Oracle HTTP Server and the WebLogic Server Proxy plugin, allowing attackers to compromise systems without authentication. Federal agencies were directed to apply the fix from Oracle's January 2026 security update by August 27, following reports that the bug has been targeted by China-linked threat actors since early in the year.
Reported exploitedOracle HTTP Server - The Hacker NewsActively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
CISA has listed CVE-2026-21962 in its Known Exploited Vulnerabilities catalog after confirming active attacks against Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. This maximum-severity flaw (CVSS 10.0) stems from improper access control, allowing unauthenticated attackers over HTTP to gain full control or modify critical data. Although Oracle released patches earlier this year, threat actors have intensified exploitation efforts, with federal agencies required to remediate by August 27, 2026.
Reported exploitedOracle HTTP Server - Qualys Security BlogCVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
A proof-of-concept exploit has become available for CVE-2026-69414, a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine within Microsoft Defender. This flaw enables local attackers with low privileges to execute code as NT AUTHORITY\SYSTEM on affected systems, including Windows 11 25H2 and Windows Server 2025. Microsoft assigned the CVE identifier on August 14, 2026, but no security update is currently available. Organizations relying on CISA Binding Operational Directive (BOD) 26-04 must address this risk within 14 days, necessitating immediate mitigation strategies until the vendor releases a formal patch.
PoC publicMicrosoft Defender
Monday, Aug 249 stories
- Dark ReadingExploited Zimbra Flaw Highlights Shrinking Window to Patch
CISA has mandated that federal agencies patch a critical remote code execution vulnerability in Zimbra Collaboration Suite by August 24, following confirmed active exploitation in the wild. The flaw, identified as CVE-2026-73570, allows unauthenticated attackers to execute arbitrary commands on servers where SNMP notifications are enabled, a setting that is active by default in affected versions. Zimbra addressed the issue in version v10.1.20, urging organizations to update immediately while treating exposed instances as potential security incidents requiring log review and incident response procedures.
Reported exploitedZimbra Collaboration Suite - BleepingComputerUnpatched Calix flaw lets hackers bypass NAT to expose internal devices
Security researchers disclosed CVE-2026-75501, an unpatched missing authentication vulnerability affecting Calix GS7 XGS residential routers running EXOS/6.6.47 firmware. The flaw allows remote attackers to bypass Network Address Translation and firewall protections by sending unauthenticated SOAP requests to the exposed MiniUPnPd control endpoint on the WAN interface. This enables threat actors to create permanent port-forwarding rules that expose internal assets, such as IP cameras and NAS devices, to the public internet without vendor remediation.
PoC publicCalix GS7 XGS - BleepingComputerHackers target WordPress sites in miniOrange auth bypass attacks
Threat actors are actively chaining two critical authentication bypass vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses using HMAC-SHA1 and misinterpreted OpenSSL verification errors to log in as site administrators. Although fixed versions were released in July for all editions of the plugin, incomplete vendor disclosure regarding the paid tiers left many installations vulnerable to recent exploitation attempts. Site owners should manually update to patched releases, such as version 17.06 for the Standard edition, as automatic dashboard alerts may not trigger for premium versions.
Reported exploitedminiOrange SAML SSO Plugin - The Hacker News⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
U.S. government agencies warn that threat actors are leveraging artificial intelligence to generate exploit scripts for internet-exposed Siemens S7 Series PLCs, posing an active risk to critical infrastructure sectors like water and energy. Meanwhile, GitLab is facing immediate danger as CVE-2026-19478, a high-severity code injection flaw, is being actively exploited by unauthenticated attackers to modify public projects. Other significant developments include the leakage of live API keys for 659 Stripe merchants, the discovery of 768 corporate AWS keys with full administrative rights in public repositories, and the release of RedC2 4.0 Linux backdoors via trojanized npm packages.
Reported exploitedSiemens PLCs - Check Point Research24th August – Threat Intelligence Report
Major vendors including GitLab, Cisco, and Citrix have released urgent patches for critical vulnerabilities that are already seeing exploitation or carry maximum severity scores. Notably, GitLab fixed CVE-2026-19478 in its Community and Enterprise editions, a CVSS 9.4 code injection flaw, while Citrix addressed authentication bypass issues CVE-2026-19489 and CVE-2026-19490 in NetScaler ADC and Gateway. These fixes coincide with significant breach disclosures affecting Latvia's CSDD and Japan's Sakura Internet, as well as warnings regarding active AI-assisted attacks on Siemens S7 PLCs and a new Cl0p extortion campaign targeting PTC Windchill via CVE-2026-12569.
Reported exploitedSnowflake Copilot - SecurityWeek91 Vulnerabilities Patched in Spring Application Framework
Broadcom has released updates for the Spring application framework addressing 91 vulnerabilities across various modules, including Spring Security, Spring AI, and Spring GraphQL. Among these fixes is a critical flaw in Spring Security’s embedded LDAP server (CVE-2026-59270) that permits unauthorized modification of directory entries, alongside over a dozen high-severity issues enabling remote code execution and data leakage. The scale of this update impacts more than 200,000 downstream components, highlighting how the increased use of AI-assisted coding by Broadcom has accelerated the emergence of security defects in the ecosystem.
PatchSpring Framework - The Hacker NewsCritical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
Red Hat and the Keycloak project have released security updates to remediate a critical vulnerability in the identity access management platform that allows unauthenticated attackers to hijack user accounts. The flaw, identified as CVE-2026-18963 and scored 9.1 by Red Hat, stems from improper state validation during the password reset process, enabling an attacker to force a credential change without verification tokens. To secure their infrastructure, administrators should upgrade upstream Keycloak instances to version 26.7.2, or apply the corresponding fixes in Red Hat build of Keycloak versions 26.4.15 and 26.6.6. While no active exploitation has been confirmed, Red Hat recommends disabling the "Forgot password" feature in all realms as a temporary mitigation if immediate patching is not possible.
PatchKeycloak - BleepingComputerCISA orders urgent patching of actively exploited Zimbra flaw
CISA has directed U.S. federal agencies to patch a critical vulnerability in Zimbra Collaboration Suite within three days due to active exploitation in the wild. Tracked as CVE-2026-73570, this command injection flaw in the SNMP monitoring component allows unauthenticated attackers to achieve remote code execution if SNMP notifications are enabled. Zimbra addressed the issue in version 10.1.20, and security teams should update immediately while monitoring for suspicious file creation or service restarts.
Reported exploitedZimbra Collaboration Suite - The Hacker NewsUAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux RootkitReported exploitedUAT-10147
Sunday, Aug 231 story
- Help Net SecurityWeek in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
A threat actor identified as TheHatman claims to have exfiltrated millions of employee records from the Microsoft Azure environments of several Fortune 500 companies, including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services. In related developments, US federal agencies issued a joint warning stating that the Medusa ransomware group has successfully infiltrated more than 500 organizations since its inception in June 2021.
Reported exploitedWindows 11
Friday, Aug 212 stories
- PatchstackOne slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
DigitalOcean's security team detected active exploitation of two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On WordPress plugin. These flaws allow unauthenticated attackers to forge SAML assertions and assume control of administrator accounts, posing a severe risk to site integrity. A significant portion of affected installations remained unaware of the threat because the plugin ships seven distinct commercial editions under a single WordPress slug, with paid versions patched silently without public advisories or database entries. To mitigate this immediate risk, administrators must manually verify their specific edition version and apply the relevant vendor fix or implement the temporary hotfixes documented by DigitalOcean.
Reported exploitedminiOrange - The Hacker NewsMicrosoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has demonstrated a technique to weaponize Microsoft Defender's internal BTR.sys driver, enabling administrators to execute arbitrary kernel-level file and registry operations on Windows systems from Windows 7 through Windows 11 25H2. The proof-of-concept tool, BTRCLI, leverages a hard-coded encryption key within the driver to install it as a boot service, allowing the removal of locked security components like WdFilter.sys during system startup before user-mode defenses initialize. Although the method requires existing administrative privileges and no traditional software flaw was exploited, the capability to strip endpoint protection using a native, signed Windows component poses a significant risk to defensive architectures.
PoC publicWindows Defender