๐ต๏ธ RESEARCH & DEEP DIVES
- IIS AppPool Can Escalate to SYSTEM via AD CS RPC Endpoint
Researchers disclosed an IIS AppPool-to-SYSTEM privilege-escalation path.- Affects Windows web servers running IIS worker processes as IIS AppPool identities.
- The path elevates an IIS AppPool process to NT AUTHORITY\SYSTEM through an AD CS RPC endpoint.
- The attack abuses SeImpersonatePrivilege with Potato-family tools or SPECTRE.
๐ Source: reddit.com ยท ๐ Coverage: reddit.com ยท ๐ via r/netsec
๐ ADVISORIES
-
Composer flaw lets malicious PHP packages expose sensitive files
CVE-2026-59944
A Composer flaw lets malicious packages expose sensitive files.- PHP Composer users, especially shared-hosting, multi-tenant, CI/CD and build environments, are affected.
- Composer 1.0โ2.2.29 and 2.3.0โ2.10.2 are vulnerable to CVE-2026-59944 and GHSA-96h3-5x6v-m776.
- Malicious packages can use path traversal or symbolic links in declared binaries to target files outside their package directory.
- Composer may change external files to world-readable and executable and register them under vendor/bin.
- Tampered vendor/composer/installed.json metadata or reused vendor directories can bypass earlier path checks.
๐ Source: github.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Critical Microsoft UFO Flaw Enables Unauthenticated Android Device Control
CVE-2026-73296
A flaw in Microsoft UFO enables unauthenticated remote control of connected Android devices.- Microsoft UFO versions before 3.0.8 are affected when Mobile MCP services allow remote access.
- CVE-2026-73296 has a CVSS score of 9.4 and exposes connected Android devices and emulators.
- Missing authentication and authorization in mobile_mcp_server.py lets network clients invoke MCP requests.
- The data and action servers use TCP ports 8020 and 8021 and can forward requests to ADB.
- Attackers can capture screenshots, retrieve device details, tap, swipe, type text, launch apps, and send key events.
๐ Source: github.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
๐ CVEs & KEV
-
CVE-2026-58574 โ CVSS 9.8 โ Dell PowerStore contains a Missing Authentication for Critical Function vulne...
-
CVE-2026-68951 โ CVSS 6.9 โ GROWI contains an incorrect authorization vulnerability. If this vulnerabilit...