๐ต๏ธ RESEARCH & DEEP DIVES
-
TranslatePress Flaw Enables Unauthenticated WordPress Account Takeover
CVE-2026-19632
A TranslatePress flaw enables unauthenticated attackers to take over WordPress administrator accounts.- More than 400,000 WordPress sites using TranslatePress are affected.
- TranslatePress versions up to and including 3.3.1 contain CVE-2026-19632, a CVSS 9.8 flaw; version 3.3.2 fixes it.
- The unauthenticated trp_get_translations_regular AJAX action exposes password-reset URLs and plaintext reset keys from translation dictionaries.
- Attackers can trigger a reset for a known administrator username or email, extract the reset link, set a new password, and seize the site.
- The exploit requires the administrator profile to use a published secondary language; default-language accounts are not affected.
๐ Coverage: cyberpress.org ยท ๐ via CVE ThreatInt, Cyber Security News (+1)
-
Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign
Hackers used legitimate RMM tools to gain remote access in a 46-country phishing campaign.- Corporate systems in 46 countries were targeted.
- Legitimate remote monitoring and management tools provided attackers with direct access.
- Convincing document lures delivered the campaign.
- Rapidly changing hosting infrastructure and signed software helped the activity blend with normal IT operations.
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Q2 2026 exploit activity spans AI frameworks, exposed systems and DeFi
Security researchers reported accelerated exploitation across enterprise, AI and DeFi technologies in Q2 2026.- Organizations using open-source AI agents and frameworks face newly tracked vulnerability exposure.
- Rapid7 counted 8,539 high- and critical-severity vulnerability disclosures, twice the year-earlier figure.
- Public proof-of-concept code increased 76%; 62% of newly exploited flaws required no authentication or user interaction.
- DeFi protocols suffered 99 Q2 exploits and $746 million in losses, including $328.6 million from eight bridge hacks.
๐ Source: rapid7.com ยท ๐ Coverage: securelist.com ยท ๐ via Securelist (Kaspersky)
-
Fake Indeed interview apps used to install Android spyware
Scammers are using fake Indeed interviews to spread Android spyware.- Job seekers targeted by scammers posing as employers on Indeed.
- Victims are tricked into installing fake Android interview apps.
- The apps deliver malware and spyware.
๐ Source: malwarebytes.com ยท ๐ Coverage: securityboulevard.com ยท ๐ via securityboulevard.com (discovered)
๐ฅ BREACHES & INCIDENTS
- (no items)
๐ CVEs & KEV
- (no items)
๐ ADVISORIES
- SonicWall NetExtender Flaws Enable Arbitrary File Writes as Root
SonicWall disclosed two vulnerabilities in its NetExtender Linux client.- SonicWall NetExtender Linux Client versions 10.3.5 and earlier are affected; Windows clients are not.
- CVE-2026-66152 is an 8.8-rated path traversal flaw in OPSWAT tarball handling that enables arbitrary file writes with root privileges.
- CVE-2026-66153 is a 7.0-rated improper link-resolution flaw in the NEService auto-upgrade process.
- The first flaw uses crafted directory traversal paths and requires network access plus user interaction; the second enables local symlink or temporary-file manipulation with low privileges.
- SonicWall reported no evidence of exploitation in the wild; the fixed release is NetExtender Linux Client 10.3.6 or later.
๐ Source: psirt.global.sonicwall.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ฐ UNDER-REPORTED
-
dindoor-deno-backdoor โ Cyber Security News
-
๐ Source for Mirage2FA Hijacks Microsoft 365 Sessions After Users Complete MFA โ any.run
-
๐ Source for INTERPOL Operation Jackal IV Arrests 58 in Black Axe Crackdown โ interpol.int