Cve
Curated coverage and analysis in this editorial area.

KEV Beats CVSS: The Framework CISOs Use When Scores Lie
On August 31, 2026, vulnerability prioritization gained an official decision framework: CISA BOD 26-04 mandates four scoring variables…

Attacker's Own Infostealer Infection Exposes Full Arsenal of Colombian Blind Eagle Campaign
A consumer infostealer accidentally infected a threat actor's workstation, leaking browser history, local folders, credentials, and a…

Five Critical Flaws Hit WordPress Plugins and Theme: The GiveWP Case
WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP contain CVSS 9.8–10.0 vulnerabilities enabling unauthenticated site takeov…

ZBT Routers Ship With Two Factory Firmware Implants Granting Unauthenticated Remote Root. No Patch Available
VulnCheck disclosed on August 27, 2026 that ZBT routers sold worldwide — including in Italy — contain two factory-installed implants,…

ZBT Routers Ship with Factory-Installed Implants: Unauthenticated Remote Root for Anyone
VulnCheck disclosed two factory-installed firmware implants in routers from Shenzhen Zhibotong Electronics (ZBT): SPEAKINGSTONE and DA…

AI Honeypot: Real Attacks on LiteLLM and MCP Servers Reveal Three Patterns
Wiz Threat Research deployed AI/ML honeypots for 90 days and documented sustained, service-specific attacks. Three distinct patterns t…

CISA Adds Six CVEs to KEV: From Citrix RCE to SQL Server with Seven Years of Attacks
On August 26, 2026, CISA added six vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, triggering Binding Operationa…

ICS Isn't Safer — Just More Selective. Biometric Sector Remains Top Target
In Q2 2026, the global share of ICS computers with blocked malicious objects fell to 19.15%, the lowest since 2022. Yet the biometric…

Chrome 152 Patches 327 Vulnerabilities, Including Sandbox-Escape RCE
Google released Chrome 152.0.7977.64/.65 on August 26, 2026, with a record 327 security fixes — 10 rated critical. CVE-2026-79282, a u…

Hugging Face Kubernetes AI Agent Intrusion
Qualys mapped the stages of an autonomous AI agent's multi-day intrusion against Hugging Face's Kubernetes environment on July 9, 2026…

Kaltura Unpatched: RCE and File Read in mwEmbed, No Fix for Five Months
CERT/CC disclosed two critical unpatched vulnerabilities in Kaltura's mwEmbed library enabling remote code execution and arbitrary fil…

Gitea CVE-2026-60004: Real-World Victim Reports CPU Spike and Dropper
A Russian sysadmin documented an attack on their self-hosted Gitea instance via CVE-2026-60004. Hosting provider HOSTKEY flagged susta…