> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
BdThemes Supply Chain Attack: Poisoned JSON Feed Creates Rogue WordPress Admins Without Touching a Single Plugin File
Attackers compromised BdThemes' vendor infrastructure and poisoned a promotional-banner JSON feed served to 100,000+ WordPress sites, hijacking admin sessions to plant rogue accounts and a persistent webshell — no plugin update required.
Inside the AI-Orchestrated EDR Evasion Lab: What Sophos Actually Found, and Why the Bug Wasn't in the Malware
Sophos recovered a fully autonomous malware R&D pipeline — a coordinator agent, four subordinate agents, a self-provisioned lab, and 80 evasion modules built against three EDR vendors. The interesting part isn't that it worked. It's the one thing in the whole pipeline that didn't.
First-of-Its-Kind Attack Pivots Through a Private Cellular APN to Sabotage Siemens PLCs at a Polish Power Plant
CERT Polska details a December 2025 attack that pivoted through a distribution operator's private cellular APN — from a compromised wind farm firewall to Siemens PLCs at a combined heat and power plant, halting a turbine.
Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph
Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.
Langflow's Third KEV Entry of the Year: CVE-2026-9198 Chains Auto-Login Bypass to Unauthenticated RCE
CVE-2026-9198 chains an unauthenticated auto-login token mint with an unsandboxed code-validation endpoint to give attackers full RCE on default IBM Langflow deployments, now under active exploitation and CISA KEV.
XSS2Shell: WordPress Pre-Auth Login XSS Chains to Full RCE (CVE-2026-64638)
CVE-2026-64638 lets an unauthenticated attacker plant XSS on WordPress's login screen with a single failed-login attempt, then chain DOM clobbering and a REST API JSONP callback to steal an admin's Application Password and execute PHP. Patch to 7.0.3.
Jenkins CVE-2026-70426: Remoting Deserialization Filter Bypass Enables Controller RCE
CVE-2026-70426 (CVSS 9.0) lets an attacker with agent-level access bypass Jenkins' JEP-200 class filter via a fallback path in Remoting, achieving code execution on the controller. Patch to 2.576 / LTS 2.568.2 now.
Microsoft Patches Four CVSS 9.9 Flaws Spanning Azure Service Bus, Azure SRE Agent, Entra Provisioning, and Active Directory
Microsoft quietly shipped fixes for four unrelated CVSS 9.9 flaws — an unauthenticated-adjacent RCE in Azure Service Bus and privilege-escalation bugs in Azure SRE Agent, Entra Provisioning Service, and on-prem Active Directory — all remotely exploitable and disclosed August 6.
SCTPhantom (CVE-2026-64564): An 18-Year-Old Linux Kernel SCTP Bug Gives Local Root and Escapes Containers
A use-after-free in the Linux kernel's SCTP ASCONF transport handling, present since 2008, lets a local attacker with SCTP reachability escalate to root and, on affected configurations, escape containers.
Metabase Zero-Day: Unauthenticated SQL Injection (CVSS 10.0) Exploited to Breach Framework and Tally
A pre-auth SQL injection in Metabase's password-reset endpoint let attackers hijack admin access on customer instances, hitting Metabase Cloud tenants Framework and Tally before a patch shipped.
CVE-2026-34486: Apache Tomcat's EncryptInterceptor Fix Was Incomplete — Now Under Active Exploitation
A second, incomplete patch for a Tomcat clustering flaw lets attackers bypass pre-shared-key encryption and reach Java deserialization on the cluster port — CISA gave federal agencies until today to fix it.
OVSwrap (CVE-2026-64531): 13-Year-Old Linux Kernel Bug in Open vSwitch Gives Any Local User Root
A 16-bit integer wraparound in the Linux kernel's Open vSwitch action parser (CVE-2026-64531, 'OVSwrap') lets any unprivileged local user become root — no OVS configuration, no CAP_NET_ADMIN, no container privileges required. A public PoC ships precomputed offsets for ~800 kernel builds.
15 TP-Link Omada Flaws Turn Zero-Touch Provisioning Into a Network Takeover Path
Forescout's Vedere Labs found 15 flaws in TP-Link's Omada zero-touch provisioning ecosystem — hardcoded crypto keys, a predictable RC4 cipher, and weak cert validation that chain into full controller and fleet compromise.
Cisco Ships Two CVSS 9.8+ 'Hardening Releases' for IOS XE and Catalyst SD-WAN in One Day
Cisco's August 5 disclosure batch bundles seven CWE-grouped IOS XE flaws (CVSS 9.8) and five Catalyst SD-WAN flaws (CVSS 9.9) into umbrella CVEs — the first big test of its new AI-driven, twice-monthly hardening-release disclosure model.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
Keyv npm Worm Hits 800+ Packages, Pulls C2 From an Ethereum Smart Contract
A compromised [email protected] release triggered a self-propagating npm worm that poisoned 800+ packages in hours, planting Claude Code and VS Code persistence hooks and fetching C2 addresses via live Ethereum smart-contract calls.
ExfilSquad's Power Pages Rampage Hits UK Police Legal Database, 14 Other Victims
A new extortion group, ExfilSquad, is scraping data straight out of misconfigured Microsoft Power Pages portals with no exploit required — its highest-profile victim so far is the UK's Police National Legal Database, exposing contact data for 135,000 officers and justice staff.
N-able's First Patch Didn't Hold: CVE-2026-18577 Bypasses the CVE-2026-18556 Fix for Full N-central Takeover
N-able's emergency fix for an N-central authentication bypass proved incomplete — a new CVE, CVE-2026-18577, lets attackers bypass the patch entirely for unauthenticated 'god-mode' access, and it's being actively exploited against MSPs.
Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)
Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi — no workarounds exist for either critical vCenter bug.
N-able N-central Authentication Bypass (CVE-2026-18556) Exploited to Hijack Managed Endpoints via Take Control and Cloudflare Tunnels
An authentication bypass in N-able's N-central RMM platform, tracked as CVE-2026-18556, was exploited in the wild to gain admin access and pivot into managed customer environments using Take Control and rogue Cloudflare tunnels.