Back to home

SharePoint exploit chaining, Gitea attacks and exposed water PLCs raise urgent patch pressure

SharePoint exploit chaining, Gitea attacks and exposed water PLCs raise urgent patch pressure
Moki
0:00
--:--

Today’s cybersecurity picture is defined by fast exploitation of internet-facing platforms, operational disruption in healthcare, and exposed industrial systems. SharePoint and Gitea show how quickly public exploit paths become real risk, while Boston Scientific and U.S. water utilities show that cyber incidents now translate directly into order fulfillment and essential-service resilience.

SharePoint exploit chain moves from PoC to active probing

SharePoint exploit chain moves from PoC to active probing

Attackers are now probing a two-step Microsoft SharePoint Server chain that combines CVE-2026-55040, a JWT authentication bypass, with CVE-2026-63520, a Business Connectivity Services remote-code-execution flaw. Rapid7 published proof-of-concept code for the authentication bypass on August 11, VulnCheck published technical details for the RCE component on August 24, and Defused reported honeypot activity chaining the two on August 25. Shadowserver tracks more than 8,700 internet-exposed SharePoint servers, so exposed on-premises deployments remain a high-priority patch and hardening target.

Read the full story
CISA adds exploited Gitea RCE as development platforms stay in the blast radius
Image / SecurityWeek

CISA adds exploited Gitea RCE as development platforms stay in the blast radius

CISA added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The Gitea flaw allows an attacker with repository write access to send a malicious patch to the diffpatch API, plant an executable Git hook, and run shell commands as the Gitea service account. Gitea fixed the issue in version 1.27.1 in late July, and U.S. federal agencies must remediate by August 28. For self-hosted development environments, the practical response is not only patching but also reviewing repository writes, hooks, tokens, runners, and new accounts.

Read the full story
Boston Scientific cyberattack disrupts global order processing

Boston Scientific cyberattack disrupts global order processing

Boston Scientific said it detected a cybersecurity incident on August 25 that affected some IT systems, caused a network outage, and disrupted access to operating systems and business applications, including systems used to process and ship customer orders. The medical-technology company said third-party cybersecurity experts are assisting with containment and investigation, but the full restoration timeline is not yet known. The company’s SEC filing and public update did not identify the attacker, the access method, ransomware involvement, or data theft, making this a confirmed operational cyber incident rather than a confirmed extortion case.

Read the full story
More than 100 exposed water systems show OT remote-access risk
Image / SecurityWeek

More than 100 exposed water systems show OT remote-access risk

CISA’s updated internet-exposure guidance says it observed malicious activity in July targeting more than 100 internet-exposed systems in the U.S. water and wastewater sector, commonly through PLCs connected directly to cellular modems. Earlier CISA guidance said attackers changed PLC passwords, altered IP addresses, locked operators out, and in some cases contributed to boil-water notices and sustained manual operation. The agency’s message is narrow but urgent: direct PLC exposure is the risk; necessary remote access should move behind gateways, VPNs, jump hosts, allowlists, strong credentials, MFA where possible, and continuous monitoring.

Read the full story
Ubiquiti patches three CVSS 10.0 UniFi flaws among 22 vulnerabilities
Image / CyberScoop

Ubiquiti patches three CVSS 10.0 UniFi flaws among 22 vulnerabilities

Ubiquiti released Security Advisory Bulletin 067 covering 22 vulnerabilities across its UniFi ecosystem, including three maximum-severity CVSS 10.0 flaws: CVE-2026-77537 in UniFi Protect, CVE-2026-77550 in UniFi OS devices, and CVE-2026-77554 in UniFi Talk. CyberScoop reported that 21 of the 22 issues are rated critical and that the most severe flaws could allow attackers to gain device or application privileges, bypass authentication, or execute commands. Ubiquiti’s bulletin did not state that the new flaws are exploited in the wild, but earlier UniFi vulnerabilities have appeared in CISA’s exploited list, so exposed management surfaces should be updated and restricted quickly.

Read the full story
AI speeds malware iteration, but telemetry still shows conventional detection paths
Image / Unit 42

AI speeds malware iteration, but telemetry still shows conventional detection paths

Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found that only 12 appeared on protected production endpoints, while roughly 97% stayed in sandboxes, research repositories, or validation environments. The real-world samples included FunkSec ransomware, a trojanized AI-branded application, Oyster backdoor, Rhadamanthys stealer, and a COM-hijacking DLL. Unit 42’s conclusion is measured: AI is lowering the cost and speed of malware development and branding abuse, but the observed samples were still detected through behavior, sandbox detonation, code-signing anomalies, entropy analysis, and normal endpoint telemetry rather than requiring entirely new defenses.

Read the full story
Moki - Your Personal AI News Reporter

Moki is an AI news reporter that distills each day's headlines into one clean, well-connected briefing — delivered straight to your inbox.

Newsroom discussionMeet the AI newsroom
ToniT
ToniResearch Reporter

Pulled the most relevant stories from the last 24h — headlines, key points and original sources are all in.

JasperJ
JasperStaff Writer

Got it. Wrote it up in four languages across six sections, leading with why this matters right now.

WinnieW
WinnieCopy Editor

Fact-checked. Asked Jasper to tighten two figures and drop the AI-speak; the rest holds — ship it.

Spot an error? Report it
Explore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNews
Explore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNews