Security News

Cybersecurity news aggregator

📰
INFO News

Security Evening Update - August 07, 2026

  • # Daglega Framfærðaþjónustu
  • Dagsetning:** 2026-08-07 | **Tími:** 17:00 UTC | **Flokkun:** Fyrir innra notendur aðeins ## Þjónustu samantekt Þjónustuþjónustu er ennþá stjórnað af **virkri nýtingu á alvarlegum veikleikum** í fyrirtækiþjónustu og aukningu á **hugbúnaðarafhendingarinnar**. Þarf að uppfæra **JetBrains TeamCity**, **N-able N-central** og **Arista VeloCloud Orchestrator** á meðferð, allar undir vinnslu. **wp2shell** WordPress RCE veikleikinn er í breiddu nýtingu, og nýr alvarleg veikleikur í **Paperclip AI** býður á alvarlega hættu fyrir AI stjórnunarsvæði. Þar að auki hefur **ChainDrop** gíslatökuhugbúnaðurinn áhrif á hundruð af npm pakka, áhrif á milljónir af mánaðarlegum notendum. ## ⚠️ Þarf að gera á meðferð
  • *JetBrains TeamCity RCE og réttindaaukning** Fjöldi alvarlegra veikleika leyfir óauðkenndar fjarkeyrslu kóða og réttindaaukning í TeamCity CI/CD þjónum. Nýting er í vinnslu, sem býður á alvarlegu hættu fyrir útviklunarsvæði.
  • *CVE:** CVE-2026-63077 (CVSS: 9.8)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Allar á sérhæfðum útgáfum áður en 2026.1.3 og 2025.11.7
  • *Lagfært í:** Útgáfur 2026.1.3 og 2025.11.7
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [The Hacker News: CISA flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation](https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html)
  • *N-able N-central auðkenningarframhjáhlaup** Þjónarar nýta alvarlega auðkenningarframhjáhlaup (CVE-2026-18577) í N-able N-central RMM hugbúnaði, sem gefur stjórnendur aðgang að netkerfum sem stjóraðir eru af MPA.
  • *CVE:** CVE-2026-18577 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Rapid7 Research: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild](https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild)
  • *Arista VeloCloud Orchestrator fjarkeyrsla kóða** Alvarleg veikleikur í Arista VeloCloud Orchestrator (CVE-2026-16812) er í vinnslu, sem leyfir óauðkenndar fjarkeyrslu kóða á á sérhæfðum útgáfum.
  • *CVE:** CVE-2026-16812 (CVSS: 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** VCO 5.2.x áður en 5.2.3.14, 6.1.x áður en 6.1.3.4, 6.4.x áður en 6.4.1.1
  • *Lagfært í:** Útgáfur 5.2.3.14, 6.1.3.4, 6.4.1.1
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [CSO Online: Arista patches maximum severity vulnerability that is already being exploited](https://www.csoonline.com/article/4202502/arista-patches-maximum-severity-vulnerability-that-is-already-being-exploited.html)
  • *WordPress wp2shell óauðkennd fjarkeyrsla kóða** Alvarleg, óauðkennd fjarkeyrsla kóða veikleikur í WordPress kerfi (kallaður wp2shell) er í breiddu nýtingu. Hann sameinar REST API veikleika með SQL innsetningu til að ná að kóða.
  • *CVE:** CVE-2026-63030 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfur 6.9.0-6.9.4 og 7.0.0-7.0.1
  • *Lagfært í:** Útgáfur 6.9.5 og 7.0.2
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
  • *Paperclip AI auðkenningarframhjáhlaup** Alvarleg auðkenningarframhjáhlaup (CVE-2026-41679) í Paperclip AI leyfir óauðkenndum þjónum að sjálfauðkenndum, réttindaaukning og fjarkeyrslu kóða á vél, sem leiðir til fullar stjórnarplána aðgengis.
  • *CVE:** CVE-2026-41679 (CVSS: 10.0)
  • *Staða:** Birt
  • *Veikar útgáfur:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SC Media: Paperclip authorization bug exploited, leads to control plane takeover](https://www.scworld.com/news/paperclip-authorization-bug-exploited-leads-to-control-plane-takeover) ## 🔍 Þjónustu aðgerð
  • *Afhendingarhugbúnaður áhrifar npm kerfi:** **ChainDrop** gíslatökuhugbúnaðurinn hefur áhrif á yfir 400 npm pakka, sem saman taka tvo milljónir af mánaðarlegum notendum. Aðgerðin notar stjórnendur sem hafa verið hættir til að innsetja óþýðandi kóða með `preinstall` tengjum, samlagðu útviklara aðgangslykilorð og býður á aðgang með Claude Code og VS Code tengjum. [Elastic Security Labs: Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages](https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain)
  • *Þjónustu aðgerð TeamPCP breiddar aðgerðir:** Þjónustu aðgerðin **TeamPCP**, tengd nýjasta LiteLLM PyPI aðgerð, hefur verið að gera aðgerðir á afgreiningu og setja upp sjálfvirkandi botnet á meðferð frá 2020. Þeir notar aðgerðir eins og ShadowRay og notar aðgerðir frá fyrri kryptojöklinga aðgerðum. [The Hacker News: TeamPCP Linked To Redis Attacks Dating Back To 2020](https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html)
  • *Innbrot í SharePoint í Sviss:** Nákvæmlega 200 reikningar á Svissarþjónustu fyrir IT (FOITT) voru áhrif á veikleika á SharePoint (CVE-2026-50522). Þetta sýnir hættuna á internetþjónum sem notast við sameiningarpláti. [SC Media: Swiss Federal IT Agency FOITT compromised about 200 accounts](https://www.scworld.com/brief/swiss-federal-it-agency-foitt-compromised-about-200-accounts-due-to-sharepoint-flaws)
  • *Oracle SQL innsetning leiðir til SYSTEM aðgangs:** Þjónarar nýta SQL innsetningu veikleika í Oracle gagnagrunnum til að sameina og keyra **Khunt** tól í gagnagrunns OJVM, sem leyfir SYSTEM nákvæmum aðgerðum á undirbúningi Windows vélum og undirbúningi endapunkta. [The Hacker News: Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM](https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html) ## 📋 Uppfærslur og uppfærslur
  • *🏢 Cisco SD-WAN Manager:** Alvarleg auðkenningarframhjáhlaup (CVE-2026-20127, CVSS 10.0) er í vinnslu. Uppfærslur eru til í fjölda aðgreininga áður en 20.9.8.2. CISA hefur gefið út vinnsluþjónustu. [BSI Germany: Cisco Catalyst SD-WAN Manager: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2676)
  • *🏢 Cisco IOS XR:** Fjöldi alvarlegra réttindaaukninga og þjónustuneitunar veikleika (þar með CVE-2026-20046, CVE-2026-20040) hefur verið lagað. Þeir aðgreiningar eru vinnslu á vélum og tengjum sem nota óþýðandi IOS XR hugbúnað. [NCSC Netherlands: Kwetsbaarheden verholpen in Cisco IOS XE Software](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0279)
  • *ClamAV þjónustuneitun veikleikar:** Fjöldi þjónustuneitunar veikleika í ClamAV, sem áhrif á nágrannarvélir frá Cisco, cPanel og Debian, hefur verið lagað. Sumar CVE hefur 9.8 stig. [Cisco Security: ClamAV Vulnerabilities Affecting Cisco Products: August 2026](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26)
  • *n8n útviklunarsvæði:** Alvarlegar veikleikar sem leyfa RCE og aðgangslykilorð (CVE-2026-27577, CVE-2026-27493) hefur verið lagað í útgáfum 1.123.67, 2.32.1 og 2.31.5. [The Hacker News: n8n Sandbox Escape Lets Workflow Editors Run OS Commands](https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html) ## Daglegar áætlanir 1. **Uppfæra TeamCity, N-central og Arista VeloCloud Orchestrator á meðferð.** Þessi kerfi eru undir vinnslu og gefa þjónum aðgang að djúpum netkerfum. 2. **Uppfæra öll WordPress útgáfur til 6.9.5/7.0.2 eða nýrra** til að minnka ávöxtun á virkri nýtingu á wp2shell RCE veikleiknum. 3. **Athuga npm afhendingar og útviklunarsvæði** fyrir tekin af ChainDrop gíslatökuhugbúnað, með fokus á `preinstall` tengja og óvæntar VS Code/Claude Code tengjum. 4. **Athuga ytri aðgang að SharePoint og svipaðum sameiningarpláti** og tryggja að þeir eru uppfærðir á nýjasta alvarlega veikleika. ## 🔗 Heimildir - [The Hacker News: CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation](https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html) - [Rapid7 Research: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild](https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild) - [Elastic Security Labs: Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages](https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain) - [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce) - [SC Media: Paperclip authorization bug exploited, leads to control plane takeover](https://www.scworld.com/news/paperclip-authorization-bug-exploited-leads-to-control-plane-takeover)
Read Full Article →

# Evening Executive Threat Digest **Date:** 2026-08-07 | **Time:** 17:00 UTC | **Classification:** For Internal Use Only

## Executive Summary The threat landscape remains dominated by **active exploitation of critical vulnerabilities** in enterprise infrastructure and a surge in **software supply chain attacks**. Immediate patching is required for **JetBrains TeamCity**, **N-able N-central**, and **Arista VeloCloud Orchestrator**, all under active attack. The **wp2shell** WordPress RCE vulnerability is seeing widespread exploitation, and a new, critical flaw in **Paperclip AI** poses a severe risk to AI management platforms. Additionally, the **ChainDrop worm** has compromised hundreds of npm packages, impacting billions of monthly installs.

## ⚠️ Immediate Action Required * **JetBrains TeamCity RCE & Privilege Escalation** Multiple critical vulnerabilities allow unauthenticated remote code execution and privilege escalation in TeamCity CI/CD servers. Exploitation is active in the wild, posing a severe risk to development environments. * **CVE:** CVE-2026-63077 (CVSS: 9.8) * **Status:** Active exploitation detected * **Vulnerable:** All on-premises deployments prior to 2026.1.3 and 2025.11.7 * **Fixed:** Versions 2026.1.3 and 2025.11.7 * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation](https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html)

* **N-able N-central Authentication Bypass** Attackers are exploiting a critical authentication bypass flaw (CVE-2026-18577) in N-able N-central RMM software, granting administrative access to customer networks managed by MSPs. * **CVE:** CVE-2026-18577 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Not specified in source — check vendor advisory * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Rapid7 Research: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild](https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild)

* **Arista VeloCloud Orchestrator Command Injection** A critical OS command injection vulnerability (CVE-2026-16812) in Arista VeloCloud Orchestrator is being actively exploited, allowing unauthenticated remote code execution on on-premises deployments. * **CVE:** CVE-2026-16812 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** VCO 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.1.1 * **Fixed:** Versions 5.2.3.14, 6.1.3.4, 6.4.1.1 * **Workaround:** None mentioned in source * **Reference:** [CSO Online: Arista patches maximum severity vulnerability that is already being exploited](https://www.csoonline.com/article/4202502/arista-patches-maximum-severity-vulnerability-that-is-already-being-exploited.html)

* **WordPress wp2shell Unauthenticated RCE** A critical, unauthenticated RCE vulnerability in WordPress core (dubbed wp2shell) is being widely exploited. It combines a REST API flaw with SQL injection to achieve code execution. * **CVE:** CVE-2026-63030 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Versions 6.9.0-6.9.4 and 7.0.0-7.0.1 * **Fixed:** Versions 6.9.5 and 7.0.2 * **Workaround:** None mentioned in source * **Reference:** [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)

* **Paperclip AI Authorization Bypass** A critical authorization bypass (CVE-2026-41679) in Paperclip AI allows unauthenticated attackers to self-register, escalate privileges, and execute arbitrary code on the host, leading to full control plane takeover. * **CVE:** CVE-2026-41679 (CVSS: 10.0) * **Status:** Disclosed * **Vulnerable:** Not specified in source — check vendor advisory * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [SC Media: Paperclip authorization bug exploited, leads to control plane takeover](https://www.scworld.com/news/paperclip-authorization-bug-exploited-leads-to-control-plane-takeover)

## 🔍 Threat Activity * **Supply Chain Worm Compromises npm Ecosystem:** The **ChainDrop** worm has compromised over 400 npm packages, collectively receiving two billion monthly installs. The attack uses stolen maintainer credentials to inject malicious code via `preinstall` hooks, harvesting developer tokens and establishing persistence via Claude Code and VS Code extensions. [Elastic Security Labs: Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages](https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain) * **Threat Actor TeamPCP Expands Operations:** The threat actor **TeamPCP**, linked to the recent LiteLLM PyPI compromise, has been conducting supply chain attacks and deploying self-propagating botnets since at least 2020. Their TTPs include exploiting vulnerabilities like ShadowRay and reusing infrastructure from earlier cryptojacking campaigns. [The Hacker News: TeamPCP Linked To Redis Attacks Dating Back To 2020](https://thehackernews.com/2026/08/teampcp-linked-to-redis-attacks-dating.html) * **Swiss Government SharePoint Breach:** Approximately 200 accounts at the Swiss Federal IT Agency (FOITT) were compromised via exploitation of a critical SharePoint vulnerability (CVE-2026-50522). This incident underscores the risk of internet-facing collaboration platforms. [SC Media: Swiss Federal IT Agency FOITT compromised about 200 accounts](https://www.scworld.com/brief/swiss-federal-it-agency-foitt-compromised-about-200-accounts-due-to-sharepoint-flaws) * **Oracle SQL Injection Leads to SYSTEM Access:** Attackers are exploiting SQL injection flaws in Oracle databases to compile and execute the **Khunt** toolkit within the database's OJVM, achieving SYSTEM-level command execution on underlying Windows hosts and evading endpoint detection. [The Hacker News: Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM](https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html)

## 📋 Patches & Updates * **🏢 Cisco SD-WAN Manager:** A critical authentication bypass (CVE-2026-20127, CVSS 10.0) is actively exploited. Patches are available for multiple affected releases prior to 20.9.8.2. CISA has issued an emergency directive. [BSI Germany: Cisco Catalyst SD-WAN Manager: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2676) * **🏢 Cisco IOS XR:** Multiple high-severity privilege escalation and DoS vulnerabilities (including CVE-2026-20046, CVE-2026-20040) have been patched. Affected systems include routers and switches running vulnerable IOS XR software. [NCSC Netherlands: Kwetsbaarheden verholpen in Cisco IOS XE Software](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0279) * **ClamAV DoS Vulnerabilities:** Multiple Denial of Service vulnerabilities in ClamAV, affecting downstream products from Cisco, cPanel, and Debian, have been patched. Some CVEs score up to 9.8. [Cisco Security: ClamAV Vulnerabilities Affecting Cisco Products: August 2026](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26) * **n8n Workflow Automation:** Critical vulnerabilities enabling RCE and credential exposure (CVE-2026-27577, CVE-2026-27493) have been patched in versions 1.123.67, 2.32.1, and 2.31.5. [The Hacker News: n8n Sandbox Escape Lets Workflow Editors Run OS Commands](https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html)

## Today's Priorities 1. **Patch TeamCity, N-central, and Arista VeloCloud Orchestrator immediately.** These systems are under active attack and provide attackers with deep network access. 2. **Update all WordPress instances to 6.9.5/7.0.2 or later** to mitigate the actively exploited wp2shell RCE vulnerability. 3. **Audit npm dependencies and developer environments** for signs of the ChainDrop worm, focusing on `preinstall` scripts and unexpected VS Code/Claude Code extensions. 4. **Review external access to SharePoint and similar collaboration platforms** and ensure they are patched against the latest critical vulnerabilities.

## 🔗 References

  • [The Hacker News: CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation](https://thehackernews.com/2026/08/cisa-flags-teamcity-cve-2026-63077-rce.html)
  • [Rapid7 Research: CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild](https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild)
  • [Elastic Security Labs: Shai-Hulud strikes again: CHAINDROP worm hits 400+ npm packages](https://www.elastic.co/security-labs/shai-hulud-chaindrop-npm-supply-chain)
  • [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
  • [SC Media: Paperclip authorization bug exploited, leads to control plane takeover](https://www.scworld.com/news/paperclip-authorization-bug-exploited-leads-to-control-plane-takeover)

Share this article