Category: alerts
Category Added in a WPeMatico Campaign
Vulnerability Summary for the Week of August 24, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 4MOSAn Security Technology–4MOSAn GCB Doctor 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server. 2026-08-24 9.8 CVE-2026-78211… Read more
A Tale of Two SOCs: Insights From Two Red Team Assessments
Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed… Read more
Vulnerability Summary for the Week of August 17, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 101gen–Automation Web Platform Notifications and OTP for WooCommerce, Advanced Country Code The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the… Read more
Defending Against an Active Threat to Siemens S7 Series PLCs
Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood… Read more
Vulnerability Summary for the Week of August 10, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 1meril–Blog Floating Button Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions. 2026-08-13 7.1 CVE-2026-28170 4xmen–pm2panel An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execute arbitrary system commands on the host. The pm2panel.js handler… Read more
Vulnerability Summary for the Week of August 3, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info @fastify/aws-lambda–@fastify/aws-lambda @fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API Gateway authorizer claims. In the default configuration, the getter that populates this decoration reads the client-controlled x-apigateway-event and… Read more
#StopRansomware: Gunra Ransomware
Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data… Read more
Vulnerability Summary for the Week of July 27, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info @fastify/rate-limit–@fastify/rate-limit @fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can control a large address range (a /64 holds 2^64 distinct addresses) and the same address has multiple valid textual representations, an IPv6… Read more
CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs
CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have… Read more
Vulnerability Summary for the Week of July 20, 2026
High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info @fastify/static–@fastify/static @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot… Read more
