DEV Community

Mark0
Mark0

Posted on

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

This week's cybersecurity landscape was dominated by critical zero-day vulnerabilities and high-impact RCE exploits. A significant discovery in WordPress core, dubbed "wp2shell," allows unauthenticated attackers to execute code through a chain of REST API confusion and SQL injection vulnerabilities. Simultaneously, SonicWall SMA 1000 series appliances were targeted by a sophisticated threat actor using zero-day exploits, while CISA added a major Microsoft SharePoint RCE flaw to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild exploitation.

Beyond traditional web vulnerabilities, the rise of AI-specific threats became evident with the emergence of the NadMesh botnet, which specifically hunts for exposed AI services like Ollama and ComfyUI to steal cloud credentials. In the malware space, the OkoBot framework introduced advanced browser injection techniques to drain cryptocurrency wallets, and the Qilin ransomware group adopted specialized EDR-killing drivers to disable security tools. These developments underscore a trend where attackers are moving faster than patch cycles and leveraging automated tooling to weaponize flaws with increasing speed.


Read Full Article

Top comments (0)