<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>HACK/PROJECT — Daily Threat Intelligence — CRITICAL</title><link>https://hackproject.pages.dev/en/</link><description>Daily Threat Intelligence</description><language>en</language><item><title>The AI-agent builder that runs a stranger&#x27;s code: CVE-2026-0770 in Langflow</title><link>https://hackproject.pages.dev/en/a/langflow-validate-rce-en.html</link><guid>https://hackproject.pages.dev/en/a/langflow-validate-rce-en.html</guid><pubDate>Wed, 22 Jul 2026 08:00:00 +0100</pubDate><description>Langflow is a visual tool for building flows and agents on top of language models. The function meant to «validate» user-supplied code, validate_code(), instead passes it to exec() with no sandbox: CVE-2026-0770 lets an unauthenticated attacker run arbitrary commands on the server. CVSS 9.8. Added to the CISA KEV catalog on 21 July 2026, with public proof-of-concept code already available. Patch now and keep instances off the public internet.</description></item><item><title>The heart of WordPress, run by someone who never logged in: the WP2Shell chain</title><link>https://hackproject.pages.dev/en/a/wordpress-wp2shell-en.html</link><guid>https://hackproject.pages.dev/en/a/wordpress-wp2shell-en.html</guid><pubDate>Wed, 22 Jul 2026 08:00:00 +0100</pubDate><description>WordPress runs a huge share of the public web. Two flaws in its core — a SQL injection in WP_Query (CVE-2026-60137) and a REST API batch-route confusion (CVE-2026-63030) — chained into an exploit dubbed &quot;WP2Shell&quot; let an unauthenticated attacker run code remotely on a default install. Disclosed on 17 July, exploited within days, added to the CISA KEV catalog on 21 July. WordPress shipped patches and force-pushed them via auto-update.</description></item><item><title>Four Joomla extensions, one pattern: the unauthenticated-upload wave that plants ghost admins</title><link>https://hackproject.pages.dev/en/a/joomla-upload-rce-wave-en.html</link><guid>https://hackproject.pages.dev/en/a/joomla-upload-rce-wave-en.html</guid><pubDate>Mon, 20 Jul 2026 08:00:00 +0100</pubDate><description>In a few weeks four widely installed Joomla extensions — SP Page Builder, iCagenda, PageBuilder CK and Balbooa Forms — landed in CISA&#x27;s catalog of exploited vulnerabilities, all with the same flaw: an endpoint reachable with no login that accepts a file upload without checking its type. The result is a PHP web shell executed on the server. In at least one case the observed payload plants a hidden Super Administrator with an @secure.local email and scatters &quot;PHP File manager&quot; backdoors across several folders. No named actor: what stands out is the same mistake repeated in different products.</description></item><item><title>The module that moves the payments, taken without a login: CVE-2026-46817 in Oracle E-Business Suite</title><link>https://hackproject.pages.dev/en/a/oracle-ebs-payments-en.html</link><guid>https://hackproject.pages.dev/en/a/oracle-ebs-payments-en.html</guid><pubDate>Mon, 20 Jul 2026 08:00:00 +0100</pubDate><description>Oracle Payments is the payment engine inside Oracle E-Business Suite: the point where the company&#x27;s finance applications talk to banks and card networks. CVE-2026-46817 (CVSS 9.8) lets an unauthenticated attacker with only HTTP access compromise and take over the module. The exploit hits the ibytransmit endpoint of the File Transmission component, which invokes an internal Java function directly: patched in late May, the flaw was exploited in the wild from 27 June — before any public PoC — and added to the CISA KEV catalog on 15 July.</description></item><item><title>A token nobody signed: SimpleHelp accepted forged logins and opened every managed endpoint</title><link>https://hackproject.pages.dev/en/a/simplehelp-oidc-bypass-en.html</link><guid>https://hackproject.pages.dev/en/a/simplehelp-oidc-bypass-en.html</guid><pubDate>Mon, 20 Jul 2026 08:00:00 +0100</pubDate><description>SimpleHelp is remote-support software: whoever controls it controls the computers it manages. CVE-2026-48558 (CVSS 10.0) is an authentication bypass in the OIDC flow: when single sign-on is configured, identity tokens were accepted without verifying their cryptographic signature. A remote, unauthenticated attacker could therefore submit a forged token with arbitrary claims and obtain a full technician session — in some configurations bypassing MFA too. The flaw was exploited in the wild to deliver the TaskWeaver loader and the Djinn stealer, and was added to the CISA KEV catalog on 29 June.</description></item><item><title>The box built to run malware, run by whoever knocks: two RCEs in FortiSandbox</title><link>https://hackproject.pages.dev/en/a/fortisandbox-oscmd-en.html</link><guid>https://hackproject.pages.dev/en/a/fortisandbox-oscmd-en.html</guid><pubDate>Sun, 19 Jul 2026 08:00:00 +0100</pubDate><description>FortiSandbox is the box where suspicious files are detonated safely. Two unauthenticated OS command injection flaws — one in the WEB UI, one in an API endpoint — let anyone execute commands on the appliance itself. Patched quietly in April and June under a &quot;Known Exploited: No&quot; label, both were added to the CISA KEV catalog on 16 July: a sign someone had started using them, with the patch already months old.</description></item><item><title>SonicWall SMA1000: you patch, you reset the passwords, and they are still in</title><link>https://hackproject.pages.dev/en/a/sonicwall-sma1000-mfa-en.html</link><guid>https://hackproject.pages.dev/en/a/sonicwall-sma1000-mfa-en.html</guid><pubDate>Sat, 18 Jul 2026 08:00:00 +0100</pubDate><description>Two zero-days in SonicWall SMA1000 remote-access appliances, chained and exploited before disclosure. The first is an unauthenticated SSRF with a maximum score; the second reaches root. But the detail that matters is what they took: not just passwords, the TOTP MFA seeds and the active session databases — the one thing a reset does not rotate.</description></item><item><title>The thirty-euro router that wiretapped foreign ministries</title><link>https://hackproject.pages.dev/en/a/apt28-router-dns-en.html</link><guid>https://hackproject.pages.dev/en/a/apt28-router-dns-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>APT28 turned thousands of home routers into a wiretapping network aimed at foreign ministries and law enforcement, hijacking DNS to steal already-authenticated OAuth tokens. No exotic malware — just the least-defended infrastructure on earth, and a US court order letting the FBI reach into five thousand privately owned devices to clean them up.</description></item><item><title>Axios: the manifest, the RAT, and the token nobody revoked</title><link>https://hackproject.pages.dev/en/a/axios-npm-en.html</link><guid>https://hackproject.pages.dev/en/a/axios-npm-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>On 31 March 2026 two malicious axios releases added a booby-trapped dependency without touching a single line of source code. npm had rolled out OIDC Trusted Publishing to stop exactly this. The actor walked around it with an old classic token.</description></item><item><title>Medusa and UMMC: The Clinic That Learned to Run Offline</title><link>https://hackproject.pages.dev/en/a/medusa-ummc-en.html</link><guid>https://hackproject.pages.dev/en/a/medusa-ummc-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>On 19 February 2026 Mississippi&#x27;s largest health system went dark: 35 clinical sites shut, the state&#x27;s only Level I trauma center paralysed. But the instructive story isn&#x27;t how they got in — nobody has made that public — it&#x27;s how the oncology unit rebuilt a working clinic with no IT at all.</description></item><item><title>Qilin and the Interest on Technical Debt: Logging Into a VPN Without a Password</title><link>https://hackproject.pages.dev/en/a/qilin-checkpoint-en.html</link><guid>https://hackproject.pages.dev/en/a/qilin-checkpoint-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>A logic flaw in certificate validation during the IKEv1 key exchange let attackers open an authenticated Check Point VPN session without knowing any password. Qilin had been using it for a month before the vendor noticed. But the bug isn&#x27;t the story — the story is that it only bites organisations that never switched off a dead protocol.</description></item><item><title>The SIEM that never asked for a password</title><link>https://hackproject.pages.dev/en/a/splunk-cve-2026-20253-en.html</link><guid>https://hackproject.pages.dev/en/a/splunk-cve-2026-20253-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>CVSS 9.8, pre-auth, RCE. The flaw isn&#x27;t in Splunk proper but in an internal PostgreSQL component that accepts whatever credential you hand it. A pre-auth hole in the tool companies buy to notice intrusions.</description></item><item><title>Two Attackers, One Network: Storm-2603 and the End of the Single Intrusion</title><link>https://hackproject.pages.dev/en/a/storm2603-warlock-en.html</link><guid>https://hackproject.pages.dev/en/a/storm2603-warlock-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>Storm-2603 abuses an authentication bypass in SmarterMail to install Velociraptor as a C2 and stage Warlock ransomware. But the detail that matters surfaced later: inside one compromised network Microsoft found two unrelated crews working in parallel, each unknowingly covering the other&#x27;s tracks.</description></item><item><title>Volt Typhoon stopped watching. Now it&#x27;s looking for the stop button</title><link>https://hackproject.pages.dev/en/a/volt-typhoon-ot-en.html</link><guid>https://hackproject.pages.dev/en/a/volt-typhoon-ot-en.html</guid><pubDate>Wed, 15 Jul 2026 08:00:00 +0100</pubDate><description>For five years Volt Typhoon hid inside US critical infrastructure and touched nothing. In 2026 Dragos catches it manipulating engineering workstations to learn which conditions halt an industrial process. And it no longer sources its own access — a broker inside its own apparatus hands it over.</description></item></channel></rss>