WordPress Plugin Scripts Tampered

June 15, 2026 Faeem 0

Overview A major supply‑chain attack has struck the WordPress ecosystem, with trusted JavaScript files from PushEngage, OptinMonster, and TrustPulse — all owned by Awesome Motive — […]

Palo Alto Warns of Active Exploitation

June 15, 2026 Faeem 0

Overview Palo Alto Networks has confirmed active exploitation of a recently disclosed PAN‑OS vulnerability — CVE‑2026‑0257 — that allows unauthorized access to GlobalProtect VPN portals. The flaw, rated CVSS 7.8, is an authentication bypass affecting the portal and gateway components of PAN‑OS. Attackers can leverage it to initiate VPN connections without valid credentials, bypassing security controls entirely. Vulnerability Details Attribute Description CVE ID CVE‑2026‑0257 Severity CVSS 7.8 – High Type Authentication Bypass Affected Components GlobalProtect Portal and Gateway First Observed Exploitation May 17, 2026 Threat Actor Unknown (under investigation) The vulnerability permits attackers to set up unauthorized VPN sessions and gain gateway‑level access. While the scope of exploitation remains limited, the activity marks a serious risk for organizations running unpatched PAN‑OS instances. Exploitation Activity Palo Alto Networks observed probing and connection attempts against GlobalProtect portals beginning mid‑May. Only a small portion of devices established VPN sessions, and no lateral movement or post‑access behavior has been detected so far. “Only a small portion of the probed devices actually established VPN sessions, resulting in gateway‑connected events,” the company noted. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE‑2026‑0257 to its Known Exploited Vulnerabilities (KEV) catalog, ordering federal agencies to mitigate the flaw by June 1, 2026. Indicators of Compromise (IoCs) Organizations should review GlobalProtect logs for gateway‑connected events matching the following hard‑coded client configuration values from a PoC exploit: Parameter […]

WinRAR Vulnerability Exploited

June 15, 2026 Faeem 0

Overview Russian state‑aligned hackers are actively exploiting a known WinRAR flaw — CVE‑2025‑8088 — to steal passwords, session cookies, and sensitive files from Ukrainian organizations. Despite being patched in July 2025, the vulnerability remains a favored entry point for groups like SHADOW‑EARTH‑066 and Earth Dahu (Gamaredon), proving that unpatched software continues to be one of the most reliable attack vectors for persistent threat actors. Exploitation Chain and Attack Scope Two independent intrusion sets are weaponizing the same WinRAR flaw to deploy the GIFTEDCROOK information stealer. Threat Actor Alias / Tracking ID Primary Target Delivery Method SHADOW‑EARTH‑066 CERT‑UA UAC‑0226 Military innovation centers and law enforcement in Ukraine Spear‑phishing RAR archives Earth Dahu (Gamaredon) Russia‑aligned APT Espionage operations via Cloudflare Workers HTML Application files (HTA) Both groups continued producing new exploit samples through April 2026, with other actors like Sandworm, Turla, and Void Rabisu also observed using the same vulnerability. Technical Details of CVE‑2025‑8088 CVE‑2025‑8088 is a path traversal flaw rated CVSS 8.4 that allows attackers to write files outside the extraction directory using NTFS Alternate Data Streams. When a victim opens a malicious RAR archive with an outdated WinRAR version: Payload Stage Component Function Stage 1 LNK shortcut in Startup […]

Linux Kernel Vulnerability

June 11, 2026 Faeem 0

Overview A working proof‑of‑concept (PoC) exploit has been released for CVE‑2026‑46316, a critical Linux kernel vulnerability that enables guest‑to‑host escape in KVM environments on ARM64 systems. The flaw, dubbed […]

Hackers Abuse AWS CloudTrail and Google Cloud

June 11, 2026 Faeem 0

Overview Cloud logging services — the very tools meant to protect cloud environments — are now being weaponized by attackers. Researchers from Unit 42 have documented how threat actors are abusing AWS CloudTrail and Google Cloud Logging to evade detection and exfiltrate logs, turning visibility systems into blind spots for security teams. The New Target: Cloud Logging Infrastructure As organizations shift to cloud computing, services like CloudTrail and Cloud Logging record every API call, resource change, and user action — forming the core of cloud auditing and incident response. But that same visibility makes them a high‑value target. An attacker who can tamper with logs can move undetected, erase evidence, or even spy on the victim’s environment in real time. Platform Logging Service Purpose AWS CloudTrail Tracks API calls and resource changes Google Cloud Cloud Logging Records user actions and system events Two Attack Models Identified Unit 42 researchers outlined two distinct attack patterns: When logs are missing or altered, tools like SIEM, SOAR, and CSPM go blind — leaving attackers free to escalate privileges and exfiltrate data without detection. Defense Evasion Techniques Attackers use multiple methods to silence or poison cloud logs: Technique AWS Method Google Cloud Equivalent Stop Logging stop‑logging API call halts writes to S3 bucket Disable sink to stop log delivery […]

Ivanti Sentry Vulnerability

June 11, 2026 Faeem 0

Overview A maximum‑severity vulnerability in Ivanti Sentry — tracked as CVE‑2026‑10520 — is now being actively exploited by attackers to gain root‑level access on Internet‑exposed secure […]

Microsoft Fixes BitLocker Recovery Bug

June 11, 2026 Faeem 0

Overview Microsoft has released a fix for a BitLocker recovery issue affecting Windows Server 2025 devices that booted into recovery mode after installing the April 2026 security update. The […]