Week in review

AUSCERT Week in Review for 7th Aug 2026

Greetings, A major new software supply chain attack has highlighted the growing risks facing organisations that rely on open source code. Researchers have uncovered a self-propagating malware campaign, dubbed ChainDrop, which has compromised more than 1,300 packages in the Node Package Manager (npm) ecosystem, affecting packages that collectively receive around two billion downloads each month. The attack reportedly began when a threat actor gained access to the GitHub account of the maintainer behind several widely used caching libraries, including Keyv and Cacheable. From there, the malware spread through interconnected projects, ultimately impacting packages associated with a range of technology vendors and organisations. What makes ChainDrop particularly concerning is its ability to spread automatically. Malicious code was inserted into legitimate software packages and published through trusted GitHub Actions workflows, allowing the compromised releases to appear authentic. Once an affected package was installed, a hidden pre-installation script executed automatically, downloading additional components and launching an information-stealing payload. According to security researchers, the malware is designed to collect a wide range of sensitive information, including GitHub and npm access tokens, cloud credentials, Kubernetes secrets, database credentials, and keys for services such as AWS, Azure and Google Cloud. The stolen data is then encrypted and exfiltrated, while the malware searches for new opportunities to compromise additional repositories and packages. Security experts warn that any developer workstation or CI/CD environment that installed an affected package should be considered compromised. Recommended response measures include rebuilding impacted systems, rotating exposed credentials, reviewing repositories for unauthorised changes, and strengthening dependency management controls. As investigations continue, the number of affected packages may grow, reinforcing the importance of ongoing vigilance across the software supply chain. Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Date: 2026-08-04 Author: Dark Reading N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments. The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend. Rails patches critical Active Storage flaw with RCE potential Date: 2026-08-01 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0171.2] A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). Rails is a popular open-source web application framework written in Ruby for building websites and web apps. It uses the built-in Rails component Active Storage for handling file uploads and attachments. Rails maintainers published an advisory about the CVE-2026-66066 flaw, which received a critical severity rating. Massive ChainDrop npm supply-chain attack infects hundreds of packages Date: 2026-08-04 Author: Bleeping Computer [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ASB-2026.0172] Self-propagating malware named 'ChainDrop' has compromised more than 1,300 packages with a combined 2 billion monthly downloads on the Node Package Manager (npm) registry. Infected packages include very popular ones such as Keyv and Cacheable, flat-cache and file-entry-cache, all caching utilities from the same maintainer. The supply-chain attack started after the threat actor compromised the GitHub account of Keyv’s maintainer, and quickly spread to packages associated with major organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan. Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction Date: 2026-08-01 Author: The Hacker News [See AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8857] Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in arbitrary code execution in the context of the current user without requiring any user interaction. The update also resolves another high-severity flaw (CVE-2026-48448, CVSS score: 8.6) stemming from SQL injection that could pave the way for arbitrary file reads. New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Date: 2026-08-05 Author: Security Week The new attack methods, named ‘Pass-ta-key’ by Palo Alto Networks, focus on Google-synced passkeys. The security firm’s researchers showed how a threat actor could use the techniques to take over accounts without needing privilege escalation or user interaction. In a Pass-ta-key attack, malware already present on a Windows machine running Chrome can examine the browser’s local synchronization database to identify which online accounts the user has protected with passkeys, along with associated usernames and encrypted credential material. ASB-2026.0171.2 – UPDATE Ruby on Rails (Active Storage): CVSS (Max): 9.5 Ruby on Rails has released security updates to address a critical vulnerability in Active Storage that could allow an attacker to perform arbitrary file reads and potentially achieve remote code execution under vulnerable image processing configurations. ASB-2026.0172 – npm packages: CVSS (Max): None A large-scale npm supply chain attack, dubbed ChainDrop, compromised hundreds of widely used npm packages. ESB-2026.9044 – Adobe Campaign Classic: CVSS (Max): 10.0 This update addresses critical vulnerabilities that could result in arbitrary code execution and arbitrary file system read. ESB-2026.9115 – Cisco Catalyst SD-WAN: CVSS (Max): 9.9 Cisco has released software updates that address these vulnerabilities. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 31st July 2026

Greetings, Organisations using JetBrains TeamCity On-Premises are being urged to patch a newly disclosed critical security vulnerability that could allow attackers to bypass authentication and execute malicious commands on affected servers. The flaw, tracked as CVE-2026-63077, impacts all versions of TeamCity On-Premises and has been rated particularly severely because it enables remote code execution with the privileges of the TeamCity server process. TeamCity Cloud customers are not affected, as mitigations have already been implemented by JetBrains. TeamCity is widely used by development teams to automate software building, testing, and deployment processes. According to JetBrains, successful exploitation of the vulnerability could expose sensitive project data, system configurations, stored credentials, and potentially compromise software build pipelines and release artifacts. These risks make the issue especially significant for organisations that rely on TeamCity as a core component of their software delivery environment. While JetBrains stated there is currently no evidence of active exploitation, the warning carries added weight given TeamCity’s history as a target for cybercriminals, including ransomware operators and state-sponsored threat actors in 2023 and 2024. Past vulnerabilities in the platform have been rapidly exploited in real-world attacks, prompting experts to recommend swift remediation whenever critical flaws are disclosed. JetBrains has already addressed the issue in TeamCity versions 2025.11.7 and 2026.1.3 and strongly recommends upgrading as soon as possible. For customers unable to immediately move to the latest releases, the company has also provided a security patch plugin for supported versions dating back to TeamCity 2017.1. Additional security measures, including restricting access through VPNs and limiting exposure of internet-facing TeamCity services, are also recommended to reduce the risk of compromise. Critical VM Escape Vulnerability Patched in VMware ESXi Date: 2026-07-29 Author: Security Week [AUSCERT has informed the affected members via Critical MSINs] [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8797/] Broadcom published a new security advisory on Wednesday, informing VMware product users that patches are available for several vulnerabilities affecting ESXi, vCenter, Workstation, and Fusion. Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. An attacker with local admin privileges on a VM with this adapter can exploit it to execute arbitrary code on the host. CVE-2026-47876 has been described by VMware as a VM escape. Cisco warns of FMC static credential flaw exploited in zero-day attacks Date: 2026-07-29 Author: Bleeping Computer [AUSCERT has published security bulletin for this – https://portal.auscert.org.au/bulletins/ESB-2026.8812/] Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account. Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Date: 2026-07-25 Author: The Hacker News Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap pointer. Enough of those and an automated probe can locate the libraries in memory. Two more notebooks then fire the payload. No administrator rights, no CI or runner access, no victim interaction, no access to anyone else's project. US, Australia Release OT Isolation Guidance for Critical Infrastructure Date: 2026-07-29 Author: Security Week The US cybersecurity agency CISA and Australia’s Cyber Security Centre (ACSC) have published joint guidance detailing how critical infrastructure (CI) organizations can isolate vital OT and supporting systems. Aimed at boosting cyber resilience, the CI Fortify – Advice for isolating vital systems guidance also includes details on how these systems can be operated in isolation for long periods, to ensure the continuity of critical services in case of disruption or crisis. The document is designed to help OT owners, operators, and cybersecurity teams improve their preparedness, response, and recovery. Origin Energy boss confirms almost a million Australians compromised by data breach Date: 2026-07-28 Author: Cyber Daily Aussie energy supplier Origin has said it has completed its initial investigations into a cyber security incident first disclosed on 22 July. “We have now completed the initial phase of our review into Origin’s customer data security incident,” Origin CEO Frank Calabria said in a 28 July statement. “At this point in time, we believe the information of approximately 900,000 current and former customers was accessed.” ESB-2026.8651 – macOS Sequoia 15.7.8: CVSS (Max): 9.1* Apple has released security updates for macOS Sequoia 15.7.8 to address multiple security vulnerabilities. Users are advised to install the update to help protect their systems. ESB-2026.8797 – VMware Products: CVSS (Max): 7.8 Broadcom has released security updates for VMware Aria Operations to address a high-severity local privilege escalation vulnerability. ESB-2026.8812 – Cisco Secure FMC Software: CVSS (Max): 5.3 Cisco has released a security update for Secure Firewall Management Center (FMC) to address a critical static credential vulnerability that has been exploited in zero-day attacks. ESB-2026.8839 – GitLab Community & Enterprise Edition: CVSS (Max): 8.5 GitLab has released GitLab 19.2.1 patch updates for Community and Enterprise Editions to address security vulnerabilities and bug fixes. ESB-2026.8857 – Adobe Campaign Classic: CVSS (Max): 10.0 Adobe has published security updates for Adobe Campaign addressing multiple vulnerabilities. Users are advised to apply the available updates to mitigate potential security risks. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 24th July 2026

Greetings, Origin Energy has confirmed that unauthorised access to customer information has occurred, marking what is believed to be the largest publicly known cyber incident to affect an Australian energy retailer. The company, which serves more than 4.8 million customers, announced it is still investigating the extent of the breach and determining how many may have been impacted. According to Origin, the compromised information may include customers’ names, addresses, dates of birth, phone numbers, and limited banking information such as the last four digits of a credit card or the last three digits of a bank account. The company has stressed that full banking and credit card details do not appear to have been exposed. Chief Executive Frank Calabria apologised to customers, acknowledging the trust placed in the company and assuring customers that securing systems and preventing further unauthorised access remains a top priority. Origin says it will contact affected customers directly once it has confirmed who was impacted. The breach came to light after a media outlet was contacted by an alleged hacker who provided a sample of customer records. Following notification of the incident, Origin alerted authorities and informed the Australian Securities Exchange. The incident adds to a growing list of major Australian cyber security breaches in recent years, following attacks on organisations including Optus, Medibank, and Qantas. Cyber security experts are urging Origin customers to remain vigilant for suspicious emails, text messages and phone calls, as criminals often leverage stolen personal information in follow-up scams. While some customers have recently experienced delays receiving energy bills, Origin says those issues are linked to July pricing changes and are not connected to the data breach investigation. Critical ServiceNow code execution flaw now exploited in attacks Date: 2026-07-20 Author: Bleeping Computer Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows. Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks. WordPress Core "wp2shell" RCE flaws get public exploits, patch now Date: 2026-07-18 Author: Bleeping Computer [See AUSCERT Bulletin https://portal.auscert.org.au/bulletins/ESB-2026.8154] Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x. The flaws were discovered by Adam Kues of Searchlight Cyber, which says an unauthenticated attacker can exploit them against a default WordPress installation. Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Date: 2026-07-21 Author: The Hacker News A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw. Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Date: 2026-07-22 Author: Security Week [AUSCERT has published security bulletins for these Oracle updates] Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. CISA orders urgent action on actively exploited Langflow RCE flaw Date: 2026-07-22 Author: Bleeping Computer The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. Tracked as CVE-2026-0770, this critical security flaw allows unauthenticated threat actors to gain remote code execution as root in low-complexity attacks. ESB-2026.8410 – Mozilla Thunderbird: CVSS (Max): 10.0* A large number of vulnerabilities was patched in Mozilla Thunderbird, with the most severe being tracked as CVE-2026-16367 for a sandbox escape due to invalid pointer in the Disability Access APIs component. ESB-2026.8355 – Tenable Security Center: CVSS (Max): 9.9 Tenable Security Center has underlying third party libraries which were found to contain vulnerabilities. Updated versions are now available from the providers, which Tenable has implemented to address potential impacts of these identified vulnerabilities. ESB-2026.8317 – Atlassian Products: CVSS (Max): 10.0 83 high severity vulnerabilities and 18 critical severity third party vulnerabilities have been fixed in new versions of Atlassian products. Some of the patched vulnerabilities include remote code execution, denial of service and improper authorization. ASB-2026.0144 – Oracle Communications: CVSS (Max): 9.8 Oracle has released a critical patch update containing 168 new security patches or Oracle Communications. Many of these vulnerabilities can be remotely exploitable without authentication over a network. It has also been exploited in the CISA KEV. ESB-2026.8151 – roundcube: CVSS (Max): 10.0 Multiple vulnerabilities in roundcube such as account takeover, cross-site scripting, SSRF bypass, information disclosure and denial of service have been fixed in a new version release. Roundcube strongly recommends patching with the latest version. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 17th July 2026

Greetings, The Office of the Australian Information Commissioner (OAIC) has concluded its preliminary inquiries into the 2025 Qantas data breach, determining that there is currently insufficient evidence to warrant a formal regulatory investigation or enforcement action against the airline. The decision follows an almost year-long review of the incident, which affected approximately 5.12 million Australians and was one of the country's most significant privacy breaches in recent years. The breach occurred when a threat actor successfully carried out a phone-based social engineering, or “vishing”, attack against an employee at an overseas third-party contact centre used by Qantas. The attacker convinced the employee they were speaking with legitimate IT support and ultimately gained access to customer information through a customer relationship management platform. Qantas detected unusual activity within days, contained the incident, revoked access to the compromised account and began its incident response process. According to the OAIC, approximately 5.67 million customer records were affected, including names, email addresses, phone numbers and Qantas Frequent Flyer details. Around 1.7 million records also contained additional information such as addresses, dates of birth, and gender. Importantly, the compromised system did not store credit card details, financial information, passwords, PINs or passport details. After examining Qantas’ privacy governance, security controls, staff training, third-party oversight arrangements and incident response processes, the OAIC concluded there was no indication the airline had failed to take reasonable steps to protect personal information or ensure compliance with privacy obligations. The regulator noted that Qantas had implemented security audits, mandatory cyber-awareness training, contractual privacy requirements for service providers and a prompt breach response program. While the OAIC has closed its preliminary inquiries, it emphasised that the decision is not an endorsement of Qantas’ practices and that future investigations remain possible if new information emerges. The report highlights the growing threat of sophisticated social engineering attacks and reinforces the importance of strong cyber security controls, employee awareness training, and rapid incident response capabilities. SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now Date: 2026-07-14 Author: Bleeping Computer [AUSCERT has contacted members about this vulnerability where possible] SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. CVE-2026-15409 is a critical (CVSS 10.0) server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface that allows a remote, unauthenticated attacker to force an appliance to make requests to unintended locations. CVE-2026-15410 is a high-severity (CVSS 7.2) post-authentication code injection flaw in the SMA1000 Appliance Management Console that could allow a remote authenticated administrator to execute arbitrary operating system commands. CISA warns admins to patch actively exploited SharePoint flaws Date: 2026-07-15 Author: Bleeping Computer The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions, including SharePoint Server Subscription Edition (the latest on-premises version, which uses a "continuous update" model). Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting Date: 2026-07-14 Author: ASD ACSC Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Public Service Announcement of the decade-plus FSB Center 16 cyber activity by providing additional tactics, techniques, and procedures (TTPs) to enable defenders to more fully understand and counter the threat. SAP warns of critical flaws in NetWeaver and Commerce Cloud Date: 2026-07-14 Author: Bleeping Computer SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The first critical issue patched this month is a memory corruption security issue (tracked as CVE-2026-44747) stemming from an out-of-bounds write weakness in the NetWeaver Application Server ABAP (AS ABAP), the runtime environment, application server, and development platform for core SAP enterprise software. "SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability," SAP says. "This has high impact on confidentiality, integrity, and availability of the application." RabbitMQ Vulnerability Threatens Enterprise Systems Date: 2026-07-14 Author: Security Week A vulnerability in RabbitMQ could allow attackers to obtain the broker’s confidential OAuth secret, potentially posing a serious threat to enterprises, according to cybersecurity firm Miggo. RabbitMQ is a popular open source message broker that routes, buffers, and distributes messages, enabling asynchronous communication between applications. Tracked as CVE-2026-5721 (CVSS score of 8.7), the security defect impacts an open management endpoint that returns the OAuth secret to anyone, without authentication. ESB-2026.7869 – VMware Avi Load Balancer: CVSS (Max): 9.8 Broadcom has released updates for VMware Avi Load Balancer to fix seven vulnerabilities, including a critical authentication bypass flaw (CVE-2026-47865). ESB-2026.7892 – Zoom: CVSS (Max): 9.8 Zoom has released updates to address a critical account takeover vulnerability (CVE-2026-53412) affecting Windows-based Zoom products. ESB-2026.7904 – Adobe ColdFusion: CVSS (Max): 9.9 Adobe has released security updates for ColdFusion to address multiple critical vulnerabilities, including arbitrary code execution and server-side request forgery (SSRF). ESB-2026.8009 – Splunk Enterprise: CVSS (Max): 9.8 Splunk has released security updates for Splunk Enterprise to address multiple vulnerabilities affecting Windows and Unix/Linux platforms. ASB-2026.0129 – Microsoft ESU: CVSS (Max): 9.9 Microsoft has released its July 2026 Patch Tuesday update, addressing 335 vulnerabilities across Windows, Exchange Server, and other products, including multiple critical remote code execution and privilege escalation flaws. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more

Week in review

AUSCERT Week in Review for 10th July 2026

Greetings, The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) has issued a critical alert following a large-scale cyber campaign targeting vulnerabilities in website content management systems (CMS) across the globe, including Australia. Small and medium-sized businesses have been particularly affected, with attackers actively scanning websites for weaknesses in popular CMS platforms and plugins. According to the ACSC, malicious actors are exploiting known vulnerabilities that enable unauthenticated file uploads, remote code execution and other forms of server compromise. Their primary objective is to deploy webshells, which are malicious scripts that provide remote access and control over web servers. Once installed, webshells can be used to deface websites, steal credentials and sensitive data, distribute additional malware, or provide a foothold for broader network compromise. The campaign is exploiting vulnerabilities in a range of widely used CMS products and plugins, particularly within the WordPress ecosystem, as well as other platforms including Craft CMS, MaxSite CMS, MetInfo CMS and Joomla components. The ACSC noted that this activity highlights the growing cyber threat landscape, with advances in artificial intelligence contributing to faster identification and exploitation of newly disclosed vulnerabilities. Website owners and administrators are being urged to inspect systems for signs of compromise, review logs for suspicious activity, isolate affected servers and restore websites from known-good backups where necessary. The ACSC also recommends prioritising patching, monitoring for unauthorised file creation and restricting file access to reduce the risk of webshell deployment. Organisations should ensure all website software and plugins remain up to date and consider additional controls to detect unusual processes and limit potential movement within corporate networks. Max severity Adobe ColdFusion flaw now exploited in attacks Date: 2026-07-06 Author: Bleeping Computer [Please see AUSCERT Bulletin: https://portal.auscert.org.au/bulletins/ESB-2026.7232/] [AUSCERT has contacted affected members where applicable] Attackers are now exploiting a maximum-severity Adobe ColdFusion vulnerability tracked as CVE-2026-48282, according to vulnerability intelligence company KEVIntel. ColdFusion is a commercial web app development platform designed to help build and deploy enterprise-grade websites. The CVE-2026-48282 security flaw affects ColdFusion versions 2025.9, 2023.20, and earlier, and can be exploited by attackers without privileges to gain remote code execution on unpatched systems. Critical Cursor AI Code Editor Flaws Could Lead to OS-Level Remote Code Execution Date: 2026-07-03 Author: Security Week Two critical vulnerabilities in the popular AI code editor Cursor could lead to remote code execution on the underlying operating system, Cato Networks reports. The security defects are tracked as CVE-2026-50548 and CVE-2026-50549 (CVSS score of 9.8) and are referred to as DuneSlide, given that they lead to remote code execution (RCE) outside of the IDE’s sandbox. According to Cato, the flaws abuse Cursor’s automatic terminal command execution inside the sandbox, which does not prompt the user for approval, and can be triggered when a victim prompts the IDE to ingest an attacker-controlled payload. BeyondTrust warns of critical flaws in remote access software Date: 2026-07-07 Author: Bleeping Computer BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication. The first vulnerability, tracked as CVE-2026-40138, affects the company's RS remote desktop and assistance platform (versions 25.3.2 or earlier) and the PRA enterprise cybersecurity solution (versions 25.3.2 or earlier). This vulnerability stems from an improper authentication weakness in the authentication subsystem, and successful exploitation enables attackers without privileges to bypass access controls and access targeted appliances, including accounts with elevated privileges. Critical Gitea Flaw Under Active Exploitation, Researchers Warn Date: 2026-07-07 Author: Security Week Threat actors are exploiting a vulnerability in Gitea’s reverse-proxy authentication mechanism to access internet-accessible instances by supplying only a valid username. Specific to Gitea’s official Docker images, the critical-severity security defect is tracked as CVE-2026-20896 (CVSS score of 9.8) and can be exploited with a single HTTP header, Sysdig Sr. Director of Threat Research Michael Clark says. The issue exists because, in Gitea Docker images before 1.26.3, the default settings allow connections from any source IP address instead of enforcing an allowlist, security researcher Ali Mustafa, who was credited for finding the bug, explains. Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities Date: 2026-07-07 Author: The Hacker News A suspected China-aligned threat activity cluster has been observed exploiting Roundcube webmail software belonging to physics and engineering departments of U.S. and Canadian universities as part of a new campaign. The activity involves the exploitation of now-patched, critical security flaws in the open-source email solution, such as CVE-2024-42009 (CVSS score: 9.3), to siphon credentials, followed by either the deployment of a web shell for persistent access or a known post-exploitation tool called VShell. ASB-2026.0125 – ALERT CMS and Plugins: CVSS (Max): 10.0* ACSC has published a critical alert warning of a large-scale campaign actively exploiting vulnerabilities in multiple CMS platforms to compromise websites, urging organisations to patch affected systems and check for signs of compromise. ESB-2026.7592 – IBM MQ container software: CVSS (Max): 10.0 IBM has released updates to fix multiple vulnerabilities affecting IBM MQ Operator and Queue manager container images. The update addresses security issues including Improper Privilege Management, Exposure of Sensitive Information to an Unauthorized Actor, and Improper Validation of Integrity Check Value in components such as OpenSSL, WebSphere Application Server Liberty, and Java SE. ESB-2026.7596 – ALERT Palo Alto Prisma Browser: CVSS (Max): 9.6* Palo Alto Networks has incorporated Chromium security fixes into its products. These fixes are included in Google’s Chrome 150 release, which addresses 433 security fixes, including 20 Critical vulnerabilities affecting components such as Browser, V8, ANGLE, Skia, Blink, and FileSystem. ESB-2026.7647 – ALERT Juniper Networks CTPView: CVSS (Max): 10.0 Juniper Networks has released CTPView 9.3R2-3, addressing multiple vulnerabilities. Juniper SIRT is not aware of any malicious exploitation, and no workarounds are available. ESB-2026.7681 – OpenPLC v3: CVSS (Max): 9.9 Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to the filesystem. Through the standard OpenPLC program compilation process, this may be escalated to arbitrary native code execution, potentially resulting in code execution as the OpenPLC runtime user. Stay safe, stay patched and have a good weekend! The AUSCERT team

Learn more