Cybersecurity Weekly Briefing, 8-14 August
A publicly available exploit for XSS2Shell puts more than 500 million WordPress sites at risk
The firm pwn.ai has discovered a pre-authentication chain leading from XSS to code execution in WordPress Core, present since version 4.7 and therefore in virtually the entire CMS that powers more than 43 per cent of the web. The vulnerability, CVE-2026-64638 (CVSSv4 8.9 according to WordPress), exploits a discrepancy between `strip_tags()` and the `wp_kses_post()` sanitiser to inject active HTML into the login screen without requiring an account or user interaction.
The escalation to remote code execution requires an already authenticated administrator to interact with a malicious page, but researchers have demonstrated several attack vectors, including the installation of a plugin using Application Password credentials generated by the victim themselves. A Python exploit is already publicly available on GitHub, which exacerbates the risk to unpatched installations. WordPress fixed the vulnerability on 6 August in version 7.0.3, with a backport to branch 4.7.
It is recommended to update immediately and audit application passwords and unrecognised plugins.
The Storm-1175 ransomware group exploited the critical vulnerability in N-able’s N-central within a matter of hours
Microsoft Threat Intelligence has linked Storm-1175 – a financially motivated actor previously associated with the Medusa ransomware – to a new family of its own, dubbed StormEncryptor, which has been in operation since 2 August. All indications suggest that the initial attack vector is CVE-2026-18577 (CVSSv4 8.2 according to N-able), an authentication bypass in the N-central remote management platform that enables account takeover and is already listed in CISA’s KEV catalogue as an actively exploited vulnerability.
N-able has released a second mandatory hotfix—even for those who have already applied the first—after detecting that attackers are using the ‘Take Control’ function to move around managed systems and are registering a Cloudflare Tunnel service to maintain persistence even if access to the server is revoked. Storm-1175 combines AnyDesk or SimpleHelp to maintain remote access, Advanced IP Scanner for reconnaissance, and LSASS dumping with Mimikatz to steal credentials – a classic manual intrusion pattern prior to encryption.
It is recommended to update immediately to version 2026.3.1.10 and monitor for the creation of !!!README_FIRST!!!.txt files.
Three independent investigations undermine the promise of passkeys without compromising the cryptography
Three separate teams (SpecterOps, Unit 42 and independent researcher Dirk-jan Mollema) have demonstrated, over the past week, different attacks that circumvent passkey protection by reusing previously signed authentication material, rather than breaking the keys. SpecterOps found that Windows stored previous YubiKey signatures in plain text, accessible to non-privileged users, and that, when combined with validation weaknesses in Microsoft Entra ID, this allowed privileged users to be impersonated despite phishing-resistant MFA policies.
Microsoft has assigned CVE-2026-34348 (CVSSv3 6.5 according to Microsoft) to the event logging flaw and has implemented additional mitigations on the Entra side. Unit 42, with malware already installed on the machine, extracted from Chrome’s memory the Security Domain Secret that protects passkeys synchronised via Google Password Manager, enabling the retrieval of their private keys without Google currently providing a way to rotate it. Mollema demonstrated that a low-privileged process in an already compromised Windows session can use the Windows Hello for Business key, protected by TPM, without requiring a new PIN or biometric check, thereby generating a valid WebAuthn assertion against Entra ID.
None of the three attacks works without prior compromise of the endpoint, but they affect Windows and Google Chrome, with an installed base numbering in the hundreds of millions of devices.
A group with links to Russia has shut down a turbine using a private APN at a Polish power station
CERT Polska has detailed a second attack on the country’s energy sector, coming weeks after the incident that ESET attributed with medium confidence to Sandworm. The attackers compromised an exposed Fortinet device at a wind farm, jumped to a Teltonika cellular router via SSH and, from there, gained access to the private APN that the distribution operator uses to communicate with the RTU of a combined heat and power plant that supplies heat to 50,000 residents.
After a week of reconnaissance, they gained access to Siemens PLCs, put them into stop mode and password-protected the control logic, halting the steam turbine and water treatment; however, staff restored service before there was an actual disruption to heat or electricity supply. The group also irreversibly damaged the partition table of the Wago PLC used as an entry point, preventing it from booting up and erasing any forensic traces.
Organisations with similar architectures should immediately audit the administrative interfaces of cellular routers and require effective separation between DNP3 serial traffic to the RTU and any Ethernet interfaces connected to the corporate network.
The attack on the LiteLLM supply chain has affected more than 2,500 organisations
According to CloudSEK, the compromise of the LiteLLM Python library – a direct consequence of the previous attack on Aqua Security’s Trivy scanner – has affected more than 2,500 organisations and 434,000 CI/CD pipelines. The actor TeamPCP never attacked LiteLLM directly: its build pipeline automatically installed the compromised version of Trivy, which allowed the malicious versions 1.82.7 and 1.82.8 to be published on PyPI with a payload that executed on every Python invocation without the need for explicit import.
Although the packages were only active for 40 minutes – long enough to spread via ephemeral runners, caches and scheduled tasks – they exposed publishing credentials, cloud keys, SSH keys, tokens and AI provider keys. Affected organisations include Nvidia, AWS, Cisco, ServiceNow, Salesforce, Siemens, Deutsche Bahn and the London Stock Exchange Group.
CloudSEK recommends treating any secret accessible to LiteLLM as compromised and rotating credentials and sessions immediately.
◾ This newsletter is one of the deliverables of our Operational and Strategic Intelligence service. If you are interested in knowing the rest of the Operational and Strategic Intelligence contents included in the service, please contact us →
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities