A 9.8 CVSS authentication bypass in cPanel & WHM and WP Squared allows unauthenticated remote attackers to gain admin access via a CRLF injection in the login/session flow. Providers report in-the-wild exploitation as early as February, and a public PoC is available; a naive Shodan query surfaces ~1.5M internet-exposed cPanel instances. Emergency upgrades to fixed versions are strongly advised; port blocks on 2083/2087 are only stopgaps.
Source: Rapid7
‘Copy Fail’ Linux kernel flaw (CVE-2026-31431) enables local root across major distros
A logic error introduced in 2017 in the kernel’s authencesn cryptographic template allows local privilege escalation to root on virtually all Linux distributions. Patches are rolling out; defenders should prioritize updates across fleets and review local hardening until fully remediated.
Source: Security Week
GitHub Enterprise Server RCE with a single git push (CVE-2026-3854)
A critical bug in GitHub Enterprise Server’s handling of special elements during push processing allowed remote code execution triggered by a crafted git push. Enterprises running GHES should apply the vendor fixes immediately and audit exposure of CI/CD integrations tied to push events.
Source: SCMagazine
Fresh LiteLLM SQLi (CVE-2026-42208) exploited within 36 hours of disclosure
Attackers rapidly abused a new SQL injection flaw in the LiteLLM proxy’s API key verification to read—and potentially modify—backend database contents. This is the second exploitation wave in five weeks, underscoring how quickly AI-adjacent infrastructure is being targeted; patch, rotate secrets, and restrict network access to proxies.
Source: Security Week
SAP npm supply chain attack (“Mini Shai-Hulud”) plants credential-stealing malware
Researchers uncovered a coordinated campaign that trojanized SAP-related npm packages tied to CAP/JavaScript ecosystems to exfiltrate developer credentials. Organizations should immediately inventory affected packages, rotate npm and cloud secrets, and implement package pinning and provenance checks in build pipelines.
Source: TheHackerNews
CISA adds actively exploited Windows Shell and ScreenConnect bugs to KEV
CISA placed ConnectWise ScreenConnect (CVE-2024-1708) and a Microsoft Windows Shell issue on its Known Exploited Vulnerabilities catalog, signaling confirmed active abuse. Federal agencies—and enterprises that map to KEV for prioritization—should expedite remediation per KEV deadlines and verify compensating controls.
Source: TheHackerNews
Hundreds of internet-facing VNC servers expose ICS/OT environments
Forescout identified tens of thousands of exposed RDP/VNC servers, with hundreds traceable to industrial and operational technology networks. Direct remote access into ICS elevates the risk of disruptive intrusions—remove remote management from the public internet, enforce VPN and MFA, and segment OT from IT.
Source: Security Week
You May Also Be Interested In...
Chrome 147 and Firefox 150 ship critical security updatesMicrosoft won’t patch PhantomRPC: Feature or bug?
Google fixes CVSS 10 Gemini CLI CI RCE in npm package and GitHub Action