Cybersecurity Weekly Briefing, 1-7 August
The wp2root chain converts the WordPress wp2shell RCE into root access on Linux without touching the disk
On 17 July, Searchlight Cyber’s Assetnote team disclosed wp2shell, a pre-authentication remote code execution exploit that chains together two WordPress Core vulnerabilities, CVE-2026-63030 (CVSSv3 9.8 according to WPScan) and CVE-2026-60137 (CVSSv3 9.1), which is already listed in CISA’s KEV catalogue due to active exploitation against an installed base of over 500 million sites.
The Calif.io research group has gone one step further with wp2root: a 21-year-old use-after-free vulnerability in PHP’s legacy Serializable code allows a ROP chain to be reconstructed from the running binary and native code to be executed without invoking any disabled functions or accessing disk. From there, it triggers Copy Fail (CVE-2026-31431, CVSSv3 7.8 according to the vendor), the April vulnerability in the Linux kernel that exploits the AF_ALG cryptographic interface and the `splice()` function to overwrite the setuid-root binary `/usr/bin/su` in the page cache and gain a root shell. As nothing is modified on disk, integrity tools such as AIDE or Tripwire do not detect anything, and the kernel vulnerability affects virtually any distribution built since 2017. The researchers themselves point out that an AI-powered coding agent (Codex) assembled the entire chain in under an hour under human supervision.
It is recommended to update WordPress to 6.9.5 or 7.0.2 and apply the kernel patches for Copy Fail.
Misconfigured Firebase in tl;dv exposes video conference calls by governments in 23 countries
Researcher bobdahacker discovered that any user of the tl;dv meeting note-taking tool (which claims to have over 2 million users) can use the Firestore API to view all active video calls to which the bot is invited, and join them by impersonating an AI note-taker with an 80 per cent success rate.
An analysis of more than 180,000 records of completed calls exposed meetings held by government agencies in 23 countries, major universities and Fortune 500 companies, with more than 1,000 meetings leaving transcripts and participants’ email addresses publicly accessible, including one from Ukraine’s Ministry of Digital Transformation.
The cause is the absence of tenant-isolation rules in the Firestore ‘meetings’ collection, and the vulnerability remained active at the time of publication.
Google confirms that AI is behind the flood of patches in Chrome and uncovers a flaw that had gone undetected for 13 years
Google has acknowledged that the unprecedented rise in vulnerabilities fixed in Chrome during 2026 is due to the use of a Gemini-based agent harness that analyses the browser’s source code. Between Chrome 149 and 150 alone, 1,072 security flaws were fixed – more than in the previous 23 releases combined – and the latest version adds a further 370, bringing the total to over 1,800 so far this year.
The case that validated this approach was CVE-2026-3545 (CVSSv3 9.6), an insufficient data validation issue in the Navigation component that had remained undiscovered for thirteen years and allowed a compromised renderer to trick the browser into reading local files, achieving a sandbox escape via manipulated HTML pages.
Given the scale of deployment of Chrome and its Chromium-based derivatives, organisations must adopt a much more aggressive update schedule than usual and review their browser patch deployment windows.
Pass-ta-key: new techniques allow Google’s synchronised passkeys to be stolen without a password or fingerprint
Researchers at Unit 42 have detailed three attack techniques, grouped under the name Pass-ta-key, which allow malware already installed on a Windows computer with a TPM to hijack accounts protected by Google’s synchronised passkeys without stealing a password, without a fingerprint and without unlocking the device.
The base variant extracts the device’s identity key from Chrome’s LevelDB database and uses it to sign requests to Google’s Cloud Authenticator whilst impersonating the legitimate device, working against relying parties that do not validate the ‘User Verified’ flag (demonstrated against eBay prior to its fix). The Silver variant forces the device to re-enrol and registers a user verification key controlled by the attacker, achieving a reusable bypass of biometrics or PINs. The ‘Golden’ variant is the most serious: it extracts from Chrome’s memory the 32-byte master secret that encrypts all the account’s synchronised passkeys, allowing them to be decrypted and sold, with no possibility of revocation in Google’s current implementation.
Credential providers are advised to strictly require and validate `userVerification=required` and to avoid exposing sensitive key material on the client side.
Critical vulnerabilities in Cisco SD-WAN require all enterprise deployments to be patched
Cisco has released security updates to address several critical vulnerabilities in Catalyst SD-WAN, three of which have a CVSSv3 score of 9.9: CVE-2026-20303, CVE-2026-20304 and CVE-2026-20310.
The vulnerabilities allow access controls to be bypassed, privileges to be escalated and unauthorised access to sensitive information on a platform widely deployed in corporate WAN networks. Although Cisco states that there is no evidence of active exploitation, no temporary mitigations are available and all deployment models, including cloud-managed and government environments, are affected.
The operational recommendation is to update immediately to the patched versions, as the only effective measure is to install the published patches.
◾ This newsletter is one of the deliverables of our Operational and Strategic Intelligence service. If you are interested in knowing the rest of the Operational and Strategic Intelligence contents included in the service, please contact us →
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities