top of page

ALL POSTS

Critical Apache Solr Vulnerability Exposes Clusters to Remote Exploitation

Key Findings Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 contain hardcoded default credentials that allow unauthenticated remote administrative access CVE-2026-44825 affects only installations using the command-line authentication tool, not manually configured systems Industrial IoT converters using USR-W610 devices have a critical CVSS 9.8 vulnerability (CVE-2026-7786) with embedded plaintext credentials USR device manufacturer has not responded to vulnerability coo

WordPress Malware Hides C2 Instructions in Steam Profile Comments

Key Findings New malware campaign discovered on approximately 1,980 WordPress sites using Steam Community profile comments to store encoded command-and-control instructions Malware uses invisible Unicode characters hidden within visible Steam profile comments to deliver payloads, making detection difficult Infected sites load external malicious JavaScript and contain a server-side backdoor capable of modifying PHP files for persistent access Campaign first detected in July 20

Halo Security and Netrio Honored with 2026 MSP Today Product of the Year Awards

Key Findings Halo Security's attack surface management platform won the 2026 MSP Today Product of the Year Award, marking the second consecutive year for the honor The platform combines automated asset discovery, vulnerability scanning, dark web monitoring, and penetration testing with expert human analysis Award judges praised both the product's technical strength and Halo Security's commitment to supporting channel partners The solution integrates with major tools including

Hackers Exploited Meta's AI Support Bot to Compromise Instagram Accounts

Key Findings Meta's AI support assistant was exploited to hijack high-profile Instagram accounts including the Obama White House account and U.S. Space Force Chief Master Sergeant account over the weekend of May 31 Hackers used a VPN to spoof location, then tricked the AI bot into adding unauthorized email addresses to target accounts and resetting passwords The exploit bypassed two-factor authentication entirely and was defeated only by accounts with multi-factor authenticat

High-Severity Infrastructure Vulnerabilities Expose Critical Systems and Live Surveillance Feeds

Key Findings Ivanti ITSM vulnerability CVE-2026-9614 carries CVSS score of 8.8 and allows authenticated privilege escalation to administrator access KMW CCTV vulnerability CVE-2026-5386 has critical CVSS score of 9.1 and enables unauthenticated password reset on camera systems SaaS Ivanti deployments already patched automatically; on-premises versions 2025.4 and prior require immediate manual updates KM-IP521 and KM-IP421 camera models affected; vendor patches available but K

Critical TP-Link Router Vulnerability Requires Immediate Patching

Key Findings TP-Link Archer BE450v1 and BE7200 v1 routers contain authenticated command injection vulnerability tracked as CVE-2026-5509 with CVSS score of 8.5 Successful exploitation grants attackers arbitrary command execution with elevated privileges, enabling full router compromise and sensitive data interception Firmware versions below 1.3.0 Build 20260416 remain vulnerable on both affected models Official patches are available and immediate installation is critical for

CVE-2026-8732: WP Maps Pro Vulnerability Allows Unauthorized WordPress Admin Account Creation Without Password

Key Findings CVE-2026-8732 in WP Maps Pro allows unauthenticated attackers to create WordPress administrator accounts remotely CVSS score of 9.8 indicates critical severity Over 2,858 attacks blocked in 24 hours, indicating active mass exploitation Affects all versions through 6.1.0; patched in version 6.1.1 released May 20, 2026 Plugin installed on 15,000+ WordPress sites according to Envato Market sales data Exploitation began before most site owners had time to patch after

Malicious Codex UI Tool with 27,000 Downloads Caught Stealing OpenAI Refresh Tokens

Key Findings Popular codexui-android npm package with 27,000 weekly downloads contained malicious code stealing OpenAI authentication credentials Malicious code hidden in published package only, not in public GitHub repository, evading standard audits Attackers stole access tokens, ID tokens, account IDs, and refresh tokens from local auth.json files Refresh tokens do not expire, allowing attackers indefinite account impersonation Same threat actor deployed malicious Android

Fileless Infostealer Attacks Target Claude Code Users Through Counterfeit Anthropic Platforms

Key Findings Active credential theft campaign targeting Claude Code users exploiting rapid AI tool adoption Attack chain begins with SEO poisoning directing victims to spoofed Anthropic installation pages Fileless infostealer uses MP3/HTA polyglot payload and in-memory execution to evade detection Command and control infrastructure routes through Russian IP infrastructure at 185.177.239.255 Anthropic's systems have not been compromised; attack targets individual users lacking

Massive 17 Million Device Botnet Successfully Dismantled by Dutch Authorities

Key Findings Dutch authorities dismantled a botnet comprising at least 17 million infected devices across computers, tablets, and smartphones Police seized over 200 servers hosted within the Netherlands that controlled the botnet infrastructure The operation was linked to ASOCKS, a Russia-based residential proxy service used for criminal activities A security researcher's report to the National Cyber Security Centre (NCSC) triggered the investigation The botnet was taken offl

Signal Users Targeted in Coordinated Phishing Campaign to Steal Backup Recovery Keys

Key Findings Attackers are conducting a coordinated phishing campaign targeting Signal users by impersonating Signal Support via text messages The campaign specifically seeks backup recovery keys, which decrypt entire message archives stored on Signal's servers, not just future communications Journalists, activists, and human rights workers are confirmed targets, with reports of campaigns against Chinese activists and German officials A 64-character recovery key grants access

ChatGPT Web Summary Vulnerability Enables Phishing Attacks Through Malicious Page Redirects

Key Findings Permiso Security discovered ChatGPhish, a vulnerability in ChatGPT that exploits the AI's trust in Markdown links and images to enable prompt injection and phishing attacks Attackers can embed malicious payloads in web pages that ChatGPT summarizes, causing automatic image fetching that leaks user IP addresses, User-Agent data, and Referer information The vulnerability transforms ChatGPT's response interface into a phishing surface by rendering malicious links, f

PAN-OS GlobalProtect Authentication Bypass Vulnerability Under Active Exploitation in the Wild

Key Findings CVE-2026-0257 is an authentication bypass vulnerability actively exploited in the wild against Palo Alto Networks PAN-OS appliances Threat actors can forge valid VPN authentication cookies without credentials if specific certificate configurations exist CISA added this flaw to the Known Exploited Vulnerabilities catalog due to active exploitation campaigns A single threat actor orchestrated at least two waves of attacks starting May 17, 2026, successfully obtaini

Russian-Linked GREYVIBE Hacking Group Uses AI to Target Ukraine

Key Findings Russian-linked threat actor GREYVIBE has conducted persistent cyberattacks against Ukraine and Ukrainian entities since at least August 2025 The group operates from Russian time zones and aligns with Kremlin state interests, particularly intelligence gathering related to the Russo-Ukrainian war GREYVIBE employs five distinct attack chains using spear-phishing, fake CAPTCHA pages, and fraudulent websites to deliver custom malware The group leverages generative AI

19.6 Billion Open Files Exposed on the Internet Without Password Protection

Key Findings 19.6 billion files exposed across 535,480 publicly accessible cloud storage buckets on AWS S3, Google Cloud, Azure, DigitalOcean, and Alibaba 685,047 credential and key files including .env files, private keys, and password vault databases sitting unprotected 985,645 database exports (.sql files) and 733,040 backup files (.bak) accessible without authentication Over two-thirds of exposed storage located on AWS due to its dominance as the default cloud provider No

Critical FortiClient EMS Vulnerability Exploited in Active Campaign Delivering EKZ Infostealer

Key Findings Threat actors are actively exploiting CVE-2026-35616, a critical FortiClient EMS vulnerability with a CVSS score of 9.1, to deploy credential-stealing malware across enterprise networks Attackers abuse legitimate FortiClient management pathways to push malicious PowerShell commands, evading traditional network monitoring solutions A new infostealer payload named EKZ Infostealer masquerades as vendor software updates and extracts credentials from Chrome and Firefo

Critical Security Updates: Privilege Escalation and Remote Code Execution Vulnerabilities Patched in OpenVPN Connect and Veeam

Key Findings Critical privilege escalation vulnerability (CVE-2026-9560, CVSS 9.4) in OpenVPN Connect for macOS allows local attackers to gain root access Affected versions 3.5.1 through 3.8.1 contain insecure local IPC handling in the privileged helper component Version 3.8.2 patches the vulnerability along with authentication and profile management bugs Enterprise deployments require immediate updates to secure corporate endpoints Multiple critical flaws discovered in Veeam

The CISO Whisperer's Essential Guide to Gartner's Security & Risk Management Summit 2026

Key Findings Twelve cybersecurity vendors identified as high-activity players ahead of Gartner Security & Risk Management Summit 2026 (June 1-3, National Harbor, Maryland) Market shift driven by enterprise demand for autonomous, continuous validation and remediation rather than detection alone AI serving dual role as both accelerant of threats and enabler of enterprise-scale automation Vendors clustering around security operations, exposure management, identity, compliance, a

Critical Flaw Found in Langflow AI's Architecture

Key Findings Critical vulnerability CVE-2026-7524 in Langflow OSS framework allows arbitrary file reading and remote code execution with CVSS score of 9.8 Flaw exploits symlink handling in archive extraction across Docling, Docling Serve, and Unstructured API modules Attackers can steal JWT secrets, forge authorization tokens, and execute arbitrary Python code through chatbot queries Affects versions 1.0.0 through 1.9.1; patch available in version 1.9.2 Separate critical vuln

CrowdStrike Dismantles Glassworm Botnet Targeting Open-Source Developer Supply Chain

Key Findings CrowdStrike, Google, and Shadowserver dismantled the Glassworm botnet by simultaneously taking down four command-and-control servers that powered a sophisticated supply chain attack campaign The Russia-based threat group infected over 300 GitHub repositories and compromised hundreds of open-source packages across npm, Python, and VSCode extensions since early 2025 Glassworm deployed a multi-layered resilience strategy using the Solana blockchain, BitTorrent DHT,

  • Youtube

© 2025 by Explain IT Again. Powered and secured by Wix

bottom of page