DEV Community

Mark0
Mark0

Posted on

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

This week's threat landscape was defined by critical core software vulnerabilities and the emergence of specialized malware targeting AI infrastructure. A significant 'wp2shell' exploit chain was identified in WordPress Core, allowing unauthenticated remote code execution (RCE) on standard installations. Simultaneously, a record-breaking Microsoft Patch Tuesday addressed 622 flaws, including a SharePoint RCE (CVE-2026-58644) that has already seen active exploitation in the wild and was added to the CISA KEV catalog.

Beyond traditional software, attackers are pivoting toward AI-centric targets and sophisticated evasion techniques. The NadMesh botnet was observed scanning for exposed AI services like Ollama and ComfyUI to harvest cloud credentials, while the Qilin ransomware group adopted a kernel-level EDR killer to disable security products. Other notable incidents include zero-day attacks against SonicWall VPN appliances and the discovery of the 'HollowByte' OpenSSL DoS vulnerability, which triggers memory exhaustion with a mere 11-byte payload.


Read Full Article

Top comments (0)