🚨 ACTIVE EXPLOITS & INCIDENTS
- code-projects Online Job Portal DeleteUser.php SQL Injection — CVE-2026-15676. Critical SQLi in /Admin/DeleteUser.php allows unauthorized data manipulation. Exploitable in version 1.0, active exploitation suspected given public disclosure timing.
- WP 2FA < 3.1.1.2 Account Takeover via 2FA Setup Email Binding — CVE-2026-12988. Flaw allows attackers with partial access to hijack accounts by binding 2FA to attacker-controlled email. Immediate patch recommended.
- Newsletters < 4.15 Unauthenticated PHP Object Injection — CVE-2026-12583. Public form input deserialization leads to remote code execution risk. Urgent update advised.
- AI Engine < 3.5.5 Editor+ Arbitrary File Write via Path Traversal — CVE-2026-12511. Authenticated editors can write arbitrary files, enabling privilege escalation or persistence. Patch now.
- SureForms < 2.11.1 Unauthenticated Payment Amount Bypass — CVE-2026-11567. Payment validation bypass allows attackers to manipulate payment amounts on forms. Critical for ecommerce sites.
- Word Count and Social Shares <= 1.0 Arbitrary File Deletion — CVE-2026-11563. Lack of authorization and CSRF checks enable file deletion attacks. Immediate mitigation needed.
- code-projects Online Job Portal EditUser.php SQL Injection — CVE-2026-15675. SQLi in /Admin/EditUser.php allows unauthorized user data manipulation. Version 1.0 affected.
- itsourcecode Electronic Judging System add_judges.php SQL Injection — CVE-2026-15672. Injection in admin add_judges.php parameter fname. Exploitable for database compromise.
- louisho5 picobot exec.go OS Command Injection — CVE-2026-15669. Command injection in ExecTool.Execute function allows remote code execution. Version up to 0.2.0 vulnerable.
- keras-team/keras 3.12.0 Path Traversal via Symlink Validation Bypass — CVE-2026-12482. Malicious tar archives bypass safe extraction checks, risking arbitrary file writes. Patch recommended.
- louisho5 picobot web.go SSRF Vulnerability — CVE-2026-15668. Server-side request forgery in WebTool.Execute function, enabling internal network scanning and pivoting.
🕵️ THREAT RESEARCH & DEEP DIVES
- AI Security Report 2026 — Check Point Research documents AI’s evolution from attack assistant to autonomous operator, enabling fully automated cyberattacks. Highlights new AI-driven TTPs accelerating threat actor capabilities.
- Evaluating AI Models' Capability to Automate Voice Phishing Attacks shows up to 36% of surveyed U.S. adults are susceptible to AI-generated vishing scams using advanced voice synthesis (Llama FD, Gemini, ElevenLabs). Urges urgent defense improvements.
- Large Language Models in Misinformation Ecosystems introduces a framework analyzing LLM misuse beyond content generation, including attacks on social context and verification workflows, expanding misinformation threat surface.
- Firewall3D: Hardware Firewall for 3D Printers proposes a novel hardware-based defense against firmware-level attacks in additive manufacturing, addressing supply chain and insider threat risks in 3D printing environments.
- NetInjectBench: Benchmarking Indirect Prompt Injection in LLM Agents for Network Operations reveals an 82.5% unsafe tool-action rate under prompt injection attacks, with mitigation strategies reducing risk to 10%. Critical for LLM-based automation security.
- Devil in the Lens: Physical Prompt Injection Against Vision-Language Models on Wearables exposes new attack vectors via malicious physical text prompts targeting AI glasses, enabling stealthy indirect prompt injection bypassing human detection.
📰 LESSER-KNOWN / UNDER-REPORTED
- Distributed Denial of Science: Indirect Data Poisoning of AI Systems warns of adversaries poisoning public datasets, causing autonomous AI research agents to unknowingly propagate scientific fraud, threatening research integrity at scale.
- SafeGuard: Lightweight Client-Server Architecture for Real-Time Endpoint Threat Detection offers a low-cost EDR alternative for resource-constrained orgs, combining Flutter/Kotlin agents with Node.js backend for live monitoring and remote response.
- Survey on LLM Watermarking: Theory and Deployment provides a systematic review of watermarking techniques for LLM output attribution and misuse detection, highlighting gaps in deployment readiness and detection guarantees.