DEV Community

Mark0
Mark0

Posted on

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

This week saw a significant surge in cyber threats, marked by critical vulnerabilities and evolving attacker tactics. A pre-authenticated remote code execution (RCE) flaw in WordPress Core (wp2shell), chaining CVE-2026-63030 and CVE-2026-60137, is already being actively exploited, posing a severe risk to countless websites. Other zero-day vulnerabilities targeted SonicWall SMA VPN appliances (attributed to UTA0533) and Microsoft SharePoint Server (CVE-2026-58644), with the latter added to CISA's Known Exploited Vulnerabilities catalog. Furthermore, a denial-of-service (DoS) flaw dubbed HollowByte in OpenSSL could allow remote unauthenticated attackers to exhaust server memory with minimal payloads.

New and updated malware campaigns are also causing concern. OkoBot, an evolved infostealer, targets Windows users to phish cryptocurrency seed phrases by injecting into wallet processes and leveraging browser extensions. A new Go botnet, NadMesh, is actively scanning for exposed AI services like ComfyUI and Ollama to steal AWS keys and Kubernetes tokens. Ransomware operations, specifically Qilin, are employing aggressive kernel-level defense evasion techniques, including an EDR killer that exploits a vulnerable driver. The report also highlighted a data leak at India's Kudankulam Nuclear Power Plant due to a ransomware attack on a third-party vendor, and the ongoing activities of the Blind Eagle threat actor.

The article underscores the shrinking window between vulnerability disclosure and exploit weaponization, largely driven by AI-assisted tooling. This rapid pace necessitates immediate patching and proactive security measures. Recommendations include rapid patching, implementing controls to detect and remove backdoors, and adopting frameworks for governing expanding attack surfaces, especially in AI-driven development. The emphasis is on assuming public vulnerabilities are already being tested by attackers and prioritizing urgent fixes.


Read Full Article

Top comments (0)