Roundcube Pre-Auth SQL Injection (CVE-2026-48842): Patched in May, Being Exploited Now

If you run Roundcube webmail, or your hosting provider does, this one needs attention today. CVE-2026-48842 is a pre-authentication SQL injection in Roundcube that an attacker can hit with no login at all, and it is under active exploitation in the wild. Roundcube shipped the fix back in May 2026. The problem is the gap between “patch exists” and “patch applied,” and on shared hosting that gap is exactly where webmail installs sit and rot.

We clean up compromised hosting environments for a living, and webmail is one of the most reliably neglected surfaces on any server. It gets installed once, exposed to the internet permanently, and then nobody touches it until something goes wrong. That is the population getting hit right now.

Read More

Malware Reaches the Terraform Registry: DPRK-Linked Actors Turn Your IaC Pipeline Into a Delivery Channel

For the first time, attackers have used HashiCorp’s public Terraform Registry to distribute malware. Two malicious Terraform providers and two Go modules delivered a Go-based implant that talks to its operators over a blockchain smart contract and a Slack bot, and the campaign links back to Graphalgo, a North Korea-attributed operation first documented in February. The provider counts are small so far, but the vector is the story: if a poisoned dependency can enter through your infrastructure-as-code, it enters with a direct line to your production credentials.

We spend a lot of time on the seam between deployment tooling and live infrastructure, and this is exactly the seam attackers are now probing. A malicious npm package infects a developer laptop. A malicious Terraform provider runs inside the process that provisions your cloud. Those are not the same blast radius.

Read More

MikroTrick: Two RouterOS Bugs Chained Into a Full Admin Takeover With No Password at All

Attackers were taking full administrative control of Internet-facing MikroTik routers over SSH without a password, without an SSH key, and without ever completing authentication. The chain, named MikroTrick by CERT Polska, was being used in the wild at least a day before MikroTik shipped patches. If a MikroTik router sits in front of your servers or hosting infrastructure, this is one to take seriously, because a compromised edge router is not just a compromised router. It is a foothold in front of everything behind it.

We see MikroTik gear constantly on the perimeter of hosting setups and server infrastructure we manage, and the reason this attack matters is that the router is the one device that sees all your traffic and holds the keys to your network layout. Here is how the chain works, how to tell if you were hit, and what to do about it.

Read More

The MemTensor Supply Chain Compromise: How Two Poisoned Packages Turned Into a Self-Spreading Credential Stealer

An attacker quietly pushed malicious versions of two legitimate MemTensor packages onto npm and PyPI, and anyone who installed the wrong version handed over their cloud keys, registry tokens, source-code access, and developer secrets. The payload is a Go-based stealer called sckit, and the ugly part is that it behaves like a worm: it carries the templates to reinstall itself into other npm packages, Python packages, and GitHub Actions workflows. This is not “a bad package got published.” This is a supply chain attack that tries to keep spreading through whoever it lands on.

We deal with the fallout of compromised developer machines and deployment pipelines regularly, and this one is worth understanding in detail because the delivery method, stealing a project’s own publishing tokens, is becoming the standard playbook. If your site’s build or deploy touches npm or PyPI, read the indicators below and check yourself today.

Read More

A cPanel Account Just Became a Root Shell: What CVE-2026-87899 Means for Shared Hosting

If you run a shared hosting box on cPanel & WHM, stop what you’re doing and check your build number. On September 22, cPanel shipped fixes for three separate vulnerabilities, and the headline one, CVE-2026-87899, is about as bad as it gets on a multi-tenant server: any logged-in cPanel account can run code as root and take over the entire machine.

We’ve spent years cleaning up compromised hosting environments, and this is the exact class of bug that turns a single throwaway account into a full server breach. Below is what actually matters, why it’s dangerous in practice, and what to do today.

Read More

WordPress CVE-2026-87902: Exploited Within Hours, and Why the pearcmd.php Trick Makes It Dangerous

A critical unauthenticated RCE flaw in WordPress core, CVE-2026-87902 (CVSS 9.2), went from patch to active exploitation in a matter of hours. WordPress shipped the fix on September 22, and the first exploitation attempt was logged the same day at 11:49 a.m. UTC. Attackers are chaining the flaw with a well-known PHP gadget, pearcmd.php, to write web shells to disk. If you run WordPress, this is a drop-everything-and-patch situation, and the mechanics are worth understanding because they explain both why the bug is serious and why most sites will survive it.

We monitor and clean WordPress sites at scale, and this is a textbook example of the pattern we see over and over: a core disclosure, a public advisory that hands attackers the recipe, and automated mass-probing before most admins have finished their morning coffee. AgentOffense flagged exactly this compressed timeline as an industry-wide trend in their research on disclosure-to-breach reaction windows, and CVE-2026-87902 is that trend playing out in real time, down to the hour. Here is what the flaw actually does, the classic trick that turns it into code execution, and exactly what to check.

Read More

ShinyHunters Claim to Have Breached the FBI and Hold Data on Every Employee

Late Monday night, a group calling itself ShinyHunters defaced the FBI’s own jobs site and claimed to be sitting on personal data for every current and former employee of the bureau, plus everyone who ever applied to become a special agent. No confirmation from the FBI has landed yet, so this is still a claim, not a confirmed breach, and the honest version of this story has to hold both things at once: some of what’s been shown checks out, and a lot of it doesn’t yet.

Read More

Comment2Shell: A WordPress Comment Can Now Turn Into Full Server Control (CVE-2026-93485)

WordPress patched a core vulnerability on September 17 that turns something as mundane as a blog comment into a path to full server compromise. Researchers are calling it Comment2Shell, tracked as CVE-2026-93485 with a CVSS score of 7.1, and it affects every WordPress core release from 4.7 through 7.1, which covers the overwhelming majority of WordPress sites running today. No authentication is required to fire the first stage. An attacker only needs a comment box that accepts input, which on most WordPress sites means anyone with a browser.

Read More

DORA Penetration Testing and TLPT Requirements: The Complete 2026 Guide

DORA, the EU’s Digital Operational Resilience Act, has been directly applicable law since 17 January 2025, and its testing requirements are where most financial firms run into trouble first. The regulation sets up two genuinely different testing obligations under one name, and conflating them is the single most common mistake we see: basic ICT testing that applies to nearly every in-scope entity every year, and Threat-Led Penetration Testing (TLPT), a far heavier, specialised exercise that only a defined subset of firms ever has to run. This guide separates the two clearly, explains exactly who has to do what, and walks through what a TLPT engagement actually involves phase by phase.

Read More

Not Just Banks: Why iGaming, Crypto Platforms and Shipping Companies in Cyprus Now Need Penetration Testing Too

Ask most Cyprus businesses which sectors get real cybersecurity scrutiny from regulators, and the answer is almost always “banks and investment firms.” That stopped being accurate a while ago. Between MiCA, the National Betting Authority’s licensing regime, IMO shipping cyber requirements, and the Central Bank of Cyprus’s oversight of electronic money institutions, several sectors that used to sit outside financial-grade regulation are now squarely inside it, each with its own testing expectations that a generic vulnerability scan does not come close to covering.

This guide covers what each of these sectors actually needs tested, why the risk profile is different from a standard business website, and what “in scope” really means if you operate a crypto platform, an iGaming site, a shipping company, or an EMI out of Cyprus.

Read More