View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA says ransomware gangs are exploiting a Microsoft SharePoint RCE

๐Ÿšจ ACTIVE EXPLOITATION

  • CISA says ransomware gangs are exploiting a Microsoft SharePoint RCE flaw CVE-2026-45659 CISA says ransomware gangs are exploiting a Microsoft SharePoint RCE flaw.

    • Microsoft SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition are affected.
    • CVE-2026-45659 enables arbitrary code execution on unpatched SharePoint servers.
    • Attackers exploit deserialization of untrusted data using low-privilege, low-complexity attacks.
    • Shadowserver tracks more than 8,500 internet-exposed SharePoint servers, including over 200 unpatched systems. ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • Suspected Iranian Campaign Hits Water Utilities Across 12 U.S. States Suspected Iranian hackers have targeted water utilities in at least 12 U.S. states.

    • Municipal water and wastewater utilities in at least 12 U.S. states are affected.
    • Internet-connected programmable logic controllers, including Rockwell Automation/Allen-Bradley PLCs, were targeted.
    • Attackers accessed PLCs remotely, changed passwords, and disabled operator monitoring and control.
    • Reported effects included manual operations, loss of water pressure, flooding, and a temporary boil-water advisory in Georgia. ๐Ÿ“„ Source: cisa.gov ยท ๐Ÿ“Ž Coverage: therecord.media ยท ๐Ÿ‘ via securityboulevard.com (discovered)
  • AI Chrome Extension Returns With Malicious Update and Uninstall Tracking A malicious Chrome AI extension returned to enterprise browsers.

    • Chrome users and enterprise endpoints were affected by the "AI Sidebar with DeepSeek, ChatGPT, Claude and more" extension.
    • The extension previously scraped ChatGPT and DeepSeek conversations and exceeded 300,000 installs with a 4.6-star rating.
    • Version 1.7.2.0 was distributed from July 20โ€“31, 2026, followed by version 1.7.3.0.
    • Version 1.7.3.0 added a 21-line payload that opened affiliate links after updates and uninstall events.
    • Google CDN-delivered version 1.7.3.0 was classified as Trojan.GenericFCA.Script.37952. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek, r/cybersecurity
  • ErrTraffic Uses Polygon Smart Contracts to Hide ClickFix Malware Infrastructure ErrTraffic uses Polygon smart contracts and ClickFix lures to deliver malware.

    • Visitors to compromised WordPress sites are targeted, primarily on Windows.
    • The ErrTraffic MaaS has delivered Vidar, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader.
    • Injected JavaScript queries Polygon smart contracts through RPC services to resolve changing delivery infrastructure.
    • Fake Cloudflare Turnstile or reCAPTCHA prompts trick victims into running commands in Windows Run, PowerShell, or Command Prompt.
    • Compromised sites can be identified by the errtraffic_session= value in the HTTP Set-Cookie header. ๐Ÿ“„ Source: watchguard.com ยท ๐Ÿ“Ž Coverage: cyberpress.org ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ RESEARCH & DEEP DIVES

  • Researchers Chain Windows 11 USB Plug and Play to SYSTEM Access Researchers demonstrated SYSTEM access through Windows Plug and Play.

    • Windows 11 systems are affected, including fully updated machines.
    • Plug and Play can fetch signed vendor software for an emulated USB device.
    • Researchers chained privileged installation components to gain SYSTEM access.
    • The attack can also run over Remote Desktop when Plug and Play or low-level USB redirection is enabled. ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Malicious MCP Servers Split Instructions to Steal AI Coding-Agent Secrets Malicious MCP servers can trick AI coding agents into exfiltrating secrets.

    • AI coding assistants connected to MCP servers are affected.
    • Targets include SSH keys, environment secrets, source code, and customer data.
    • Attackers split harmful instructions into routine-looking fragments across the assistant's existing input channels. ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Sandworm adopts fake IT interviews to deliver malware Russia-linked Sandworm is using fake IT job interviews to deliver malware.

    • Russia-linked Sandworm targets IT job applicants.
    • The group uses fake job interviews as a malware delivery vector. ๐Ÿ“Ž Coverage: cert.gov.ua ยท ๐Ÿ‘ via @campuscodi@mastodon.social
  • Windows kernel design leaves SMAP effectively disabled on standard IOCTL paths Windows kernel SMAP protections can be bypassed through standard IOCTL dispatch paths.

    • Windows 11 kernel code reached through standard IOCTL dispatch is affected.
    • SMAP fails to block kernel access to user-mode memory on the normal syscall path.
    • Syscall entry arrives with RFLAGS.AC=1, effectively disabling SMAP for that execution path.
    • A stack pivot into user-mode memory can therefore proceed without triggering SMAP.
    • Microsoft's 2020 assessment said enabling SMAP would require changes at roughly 2,900 locations. ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: sibouzitoun.tech ยท ๐Ÿ‘ via r/netsec, r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • CVE-2026-58231 โ€” CVSS 10.0 โ€” Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)SAP Commerce C...
  • CVE-2026-15555 โ€” CVSS 8.8 โ€” Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss des...
  • CVE-2026-73160 โ€” CVSS 8.7 โ€” cti-transmute Unauthenticated SSRF via Hostnames Resolving to Internal IP Add...
  • CVE-2026-15560 โ€” CVSS 8.1 โ€” Openjdk-orb: unauthed class loading via iiop in eapwhen EAP runs with -secmgr...
  • CVE-2026-71217 โ€” CVSS 7.5 โ€” Iperf3: iperf3 server accepts unbounded peer-controlled json parameters enabl...
  • CVE-2026-15567 โ€” CVSS 7.5 โ€” Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on...
  • [CVE-2026-15565](https://cve.threatint.com/CVE/C

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check