๐ต๏ธ RESEARCH & DEEP DIVES
-
GiveWP flaw enables unauthenticated PHP object injection and remote code execution
GiveWP sites are exposed to unauthenticated remote code execution.- GiveWP sites with one published donation form and one active payment gateway are affected.
- Unauthenticated attackers can inject PHP objects and execute arbitrary commands on the server.
- Exploitation depends on the object-injection chain being fully reachable in the installed version.
๐ Coverage: patchstack.com ยท ๐ via patchstack.com (discovered)
-
Bauman University Leak Exposes GRU Cyber Training Pipeline
Leaked Bauman University records expose a GRU cyber-training pipeline.- Bauman Moscow State Technical Universityโs Department No. 4 trained about 250 career and reserve students for GRU-linked roles.
- Students studied special intelligence, information-technical effects, and information-technology protection.
- Records link graduates and supervisors to GRU Military Units 26165, 74455, and 29155, associated with APT28 and Sandworm.
- Training covered password attacks, server exploitation, malware development, vulnerability research, penetration testing, cryptography, and intrusion detection.
- Practical exercises examined phishing, self-extracting archives, renamed UltraVNC binaries, command-and-control infrastructure, script deobfuscation, and system-call monitoring.
๐ Source: dti.domaintools.com ยท ๐ Coverage: hendryadrian.com ยท ๐ via Cyber Security News
-
A crafted link can open Slack Desktopโs debugging port
A crafted link can open Slack Desktopโs remote debugging port.- The issue affects users of Slackโs desktop application.
- A single link can open a debugging port in the app.
- Slack reportedly does not plan to patch the behavior.
- No CVE has been assigned.
๐ Coverage: trustsig.eu ยท ๐ via r/netsec
๐ CVEs & KEV
-
CVE-2026-75005 โ CVSS 8.7 โ Apache APISIX: Unauthenticated CPU-exhaustion DoSInefficient Algorithmic Comp...
-
CVE-2026-81625 โ CVSS 8.7 โ Stack buffer overflow in Greenbone OS and openvas-scannerA remote attacker wi...
-
CVE-2026-74848 โ CVSS 7.0 โ Apache APISIX: Cross-user response poisoning in serverless pluginsInconsisten...
-
CVE-2026-75020 โ CVSS 7.0 โ Apache APISIX: ldap-auth plugin cross-subtree identity impersonationImproper ...
๐ ADVISORIES
- ๐ Source for Rently Smart Home flaw exposed master PINs and user permissions โ msrc.microsoft.com