- ## Öfugt samantekt Þýðingin er úr ensku yfir á íslensku. ## Öfugt samantekt Þýðingin er úr ensku yfir á íslensku. ## ⚠️ Þörf á áfangi á skammti
- *🏢 Microsoft Edge margar kritískar veikleikar** Fjölmargir kritískir veikleikar leyfa fjarkeyrslu kóða, upplýsingar útgeyingu og auðkenningarframhjáhlaup. CERT-FR segir að veikleikarnir séu í virkri nýtingu.
- *CVE:** CVE-2026-3909 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfur fyrir 146.0.7680.153
- *Lagfært í:** Síðustu útgáfur (uppfæra í 146.0.7680.153 eða nýrra)
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Exploit-DB: [local] Microsoft Edge 150.0.4078.48 - RCE](https://www.exploit-db.com/exploits/52632)
- *🏢 Apache HTTP Server kritískar RCE og þjónustuneitunarveikleikar** Fjölmargir kritískir veikleikar með CVSS stig upp á 10.0 leyfa fjarkeyrslu kóða og þjónustuneitun.
- *CVE:** Fjölmargir (t.d. CVE-2026-48913, CVE-2026-44631) (CVSS: Upp á 10.0)
- *Staða:** Birt
- *Veikar útgáfur:** Útgáfur fyrir 2.4.58
- *Lagfært í:** Útgáfa 2.4.58
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Gentoo GLSA: GLSA 202608-05: Apache HTTPD: Fjölmargir veikleikar](https://security.gentoo.org/glsa/202608-05)
- *WordPress Core wp2shell óauðkennd fjarkeyrsla kóða** Kritískur óauðkennd fjarkeyrslu kóða veikleikur í WordPress kóðanum, nefndur "wp2shell", er breitt nýtt með vandlega aðferð á REST API batch tengilið samhliða með SQL-innsetningu.
- *CVE:** CVE-2026-63030 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** WordPress 6.9.0-6.9.4 og 7.0.0-7.0.1
- *Lagfært í:** WordPress 6.9.5 og 7.0.2
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
- *🏢 NGINX kritísk heap biðminnisskrun (CVE-2026-42945)** Kritísk heap biðminnisskrun í NGINX's `ngx_http_rewrite_module` leyfir óauðkennd fjarkeyrslu kóða eða þjónustuneitun og er í virkri nýtingu.
- *CVE:** CVE-2026-42945 (CVSS: 8.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** NGINX Open Source 1.0.0 til 1.24.x
- *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Kritísk NGINX veikleiki getur skemmt aðferðir og getur leyft fjarkeyrslu kóða](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html)
- *🏢 Adobe ColdFusion margar kritískar RCE uppfærslur** Adobe hefur uppfært yfir 55 kritískar veikleikar í ColdFusion, með fjölmargum CVSS 10.0 stigum RCE veikleikum sem eru í virkri nýtingu.
- *CVE:** Fjölmargir (t.d. CVE-2026-48282, CVE-2026-48316) (CVSS: Upp á 10.0)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** ColdFusion 2023 og 2025 fyrir spesífaðar uppfærslur
- *Lagfært í:** Notaðu síðustu Adobe öryggisuppfærslur
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Adobe uppfærir þrjá CVSS 10.0 ColdFusion og Campaign Classic veikleikar](https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html) ## 🔍 Þjónustu aðgerð
- *Lazarus Group notar Windows núll-daga veikleika (CVE-2026-68820):** APT grúpa frá Norður-Kóreu notar núll-daga veikleika í Windows (CVE-2026-68820) með trojanuðum PDF skjölum sem eru nefndir sem ósöfnuðar starfsmannsáætlanir, ákveðin á vörnarmáli. CISA hefur beðið um uppfærslur.
- *Kali365 netveiðar kerfi býr til MFA framhjáhlaup:** Þetta netveiðar- og aðferð (phishing-as-a-service) halda áfram að ákveða Microsoft 365 með að sækja OAuth lykilum með aðferðum sem byggja á aðgerðum á aðgerðarþjónustu, sem gefur aðgang að notanda án þess að þurfa lykilorð.
- *Gunra gíslatökuhugbúnað notar Fortinet og Schneider veikleikar:** Gunra gíslatökuhugbúnað notar þekktar veikleikar í **Fortinet** (FortiOS, FortiProxy) og Schneider Electric PowerLogic P5 tæki til fyrstu aðgangs og til að framhjá MFA, ákveðin á kritískum aðgangi.
- *LiteLLM PyPI aðfangakeðja hætta breiddast:** Þessi óþýðandi Python pakkinn, sem hefur upphaflega verið skemmdur í skemmdum CI/CD aðgangi (Trivy skannari), hefur nú ákveðið yfir 2.100 fyrirtæki, sækjandi út auðkenni útvegar og leyfir hliðarfærslu. ## 📋 Uppfærslur og uppfærslur
- *🏢 Microsoft Defender 'RoguePlanet' núll-daga veikleiki (CVE-2026-50656):** Microsoft hefur uppfært núll-daga veikleika í Defender fyrir Windows 10/11. Uppfærslan var útgefin á júlí 9, 2026.
- *🏢 Fortinet og Schneider veikleikar notuð af Gunra:** Uppfærslur eru tiltækar fyrir Fortinet (CVE-2024-55591) og Schneider Electric veikleikar sem notuð eru. Það er kritískt að uppfæra núna til að banna þessa gíslatöku aðferð.
- *Zoom núll-sjálfstæða RCE ('Zoomsday'):** Zoom hefur útgefið uppfærslur fyrir kritískar núll-sjálfstæða RCE veikleikar (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) í aðgerðaratriðum. Uppfæra Zoom kliða núna.
- *Exim tölvuþjónn kritísk RCE:** Fjölmargir kritískir RCE veikleikar geta áhrif á Exim útgáfur 4.97 til 4.99.2. Uppfærslur eru tiltækar í Exim 4.99.3 og nýrra.
- *MongoDB, Rsync, ClamAV, MOVEit:** Kritískar uppfærslur eru tiltækar fyrir fjölmargar veikleikar í **MongoDB**, **Rsync**, **ClamAV** (áhrif á nágrannarvörur eins og Cisco) og **Progress MOVEit**. Það er áhugavert að velja út frá inntakshjólum. ## Daglegar árangurir 1. **Uppfæra netþjónn sem er í heimilisbúningi:** Uppfæra allar **Apache HTTP Server**, **NGINX** og **WordPress** útgáfur í síðustu uppfærslu útgáfum vegna virkra RCE nýtinga. 2. **Stjóra uppfærslur í vafrum:** Þýða uppfærslu á **Microsoft Edge** í heildarvinnu í útgáfu 146.0.7680.153 eða nýrra til að minnka ávæntingar. 3. **Athuga Python útviklingarumhverfi:** Leita að og fjarlægðu óþýðandi útgáfum (1.82.7, 1.82.8) af **LiteLLM** PyPI pakkanum og skoðaðu fyrir tekin auðkenni úr útviklara kerfum. 4. **Athuga MFA og skilyrðisbundnar aðgangsreglur:** Í ljósi Kali365 og Gunra aðgerða, athugaðu innskráningar logg í Microsoft 365 fyrir aðgerðir á aðgerðarþjónustu og tryggðu að MFA framhjáhlaup verði aðgengilegt. ## 🔗 Heimildir - [Exploit-DB: [local] Microsoft Edge 150.0.4078.48 - RCE](https://www.exploit-db.com/exploits/52632) - [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce) - [The Hacker News: Kritísk NGINX veikleiki getur skemmt aðferðir og getur leyft fjarkeyrslu kóða](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html) - [The Hacker News: Óþýðandi LiteLLM útgáfur tengdar Trivy hætta geta ákveðið yfir 2.100+ fyrirtæki](https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html) - [The Hacker News: Lazarus notar Windows núll-daga veikleika til að fá SYSTEM aðgang og setja inn baksýn](https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html)
## Executive Summary The threat landscape on August 14, 2026, is characterized by **widespread active exploitation of critical vulnerabilities across core enterprise infrastructure**. Immediate patching is required for **Microsoft Edge**, **Apache HTTP Server**, and **WordPress**, where exploits are in the wild. The **LiteLLM PyPI supply chain attack** has escalated, with over 2,100 organizations impacted. Additionally, sophisticated threat actors like **Lazarus** are exploiting Windows zero-days, and phishing-as-a-service platforms like **Kali365** continue to bypass MFA, posing a persistent credential theft risk.
## ⚠️ Immediate Action Required
* **🏢 Microsoft Edge Multiple Critical Vulnerabilities** Multiple critical flaws allow remote code execution, information disclosure, and security policy bypass. CERT-FR notes active exploitation of CVE-2026-3909. * **CVE:** CVE-2026-3909 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 146.0.7680.153 * **Fixed:** Latest versions (update to 146.0.7680.153 or later) * **Workaround:** None mentioned in source * **Reference:** [Exploit-DB: [local] Microsoft Edge 150.0.4078.48 - RCE](https://www.exploit-db.com/exploits/52632)
* **🏢 Apache HTTP Server Critical RCE and DoS Flaws** Multiple critical vulnerabilities with CVSS scores up to 10.0 allow remote code execution and denial of service. * **CVE:** Multiple (e.g., CVE-2026-48913, CVE-2026-44631) (CVSS: Up to 10.0) * **Status:** Disclosed * **Vulnerable:** Versions prior to 2.4.58 * **Fixed:** Version 2.4.58 * **Workaround:** None mentioned in source * **Reference:** [Gentoo GLSA: GLSA 202608-05: Apache HTTPD: Multiple Vulnerabilities](https://security.gentoo.org/glsa/202608-05)
* **WordPress Core wp2shell Unauthenticated RCE** A critical, unauthenticated RCE vulnerability in WordPress core, dubbed "wp2shell," is being widely exploited via a REST API batch endpoint flaw combined with SQL injection. * **CVE:** CVE-2026-63030 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1 * **Fixed:** WordPress 6.9.5 and 7.0.2 * **Workaround:** None mentioned in source * **Reference:** [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
* **🏢 NGINX Critical Heap Buffer Overflow (CVE-2026-42945)** A critical heap buffer overflow in NGINX's `ngx_http_rewrite_module` allows unauthenticated remote code execution or denial of service and is actively exploited. * **CVE:** CVE-2026-42945 (CVSS: 8.1) * **Status:** Active exploitation detected * **Vulnerable:** NGINX Open Source 1.0.0 through 1.24.x * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html)
* **🏢 Adobe ColdFusion Multiple Critical RCE Patches** Adobe has patched over 55 critical vulnerabilities in ColdFusion, including multiple CVSS 10.0-rated RCE flaws that are actively exploited. * **CVE:** Multiple (e.g., CVE-2026-48282, CVE-2026-48316) (CVSS: Up to 10.0) * **Status:** Active exploitation detected * **Vulnerable:** ColdFusion 2023 and 2025 prior to specific updates * **Fixed:** Apply latest Adobe security updates * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws](https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html)
## 🔍 Threat Activity
* **Lazarus Group Exploits Windows Zero-Day (CVE-2026-68820):** The North Korean APT group is exploiting a Windows privilege escalation zero-day (CVE-2026-68820) via trojanized PDFs disguised as fake job offers, targeting the defense sector. CISA has mandated patching. * **Kali365 Phishing Kit Bypasses MFA:** This phishing-as-a-service platform continues to target Microsoft 365 by stealing OAuth tokens via device code phishing, granting persistent account access without needing passwords. * **Gunra Ransomware Leverages Fortinet & Schneider Flaws:** The Gunra ransomware operation is exploiting known vulnerabilities in **Fortinet** (FortiOS, FortiProxy) and Schneider Electric PowerLogic P5 devices for initial access and to bypass MFA, targeting critical infrastructure. * **LiteLLM PyPI Supply Chain Attack Expands:** The malicious Python package compromise, originating from a poisoned CI/CD pipeline (Trivy scanner), has now impacted over 2,100 organizations, harvesting developer credentials and enabling lateral movement.
## 📋 Patches & Updates
* **🏢 Microsoft Defender 'RoguePlanet' Zero-Day (CVE-2026-50656):** Microsoft has patched a local privilege escalation zero-day in Defender for Windows 10/11. The patch was released on July 9, 2026. * **🏢 Fortinet & Schneider Vulnerabilities Exploited by Gunra:** Patches are available for the Fortinet (CVE-2024-55591) and Schneider Electric vulnerabilities being exploited. Immediate patching is critical to block this ransomware vector. * **Zoom Zero-Click RCE ('Zoomsday'):** Zoom has released patches for critical zero-click RCE vulnerabilities (CVE-2026-53413, CVE-2026-53414, CVE-2026-53415) in its annotation feature. Update Zoom clients immediately. * **Exim Mail Server Critical RCE:** Multiple critical RCE vulnerabilities affect Exim versions 4.97 through 4.99.2. Patches are available in Exim 4.99.3 and later. * **MongoDB, Rsync, ClamAV, MOVEit:** Critical patches are available for multiple vulnerabilities in **MongoDB**, **Rsync**, **ClamAV** (affecting downstream products like Cisco), and **Progress MOVEit** Automation/Transfer. Prioritize based on internal deployment.
## Today's Priorities 1. **Patch Public-Facing Web Infrastructure:** Immediately update all **Apache HTTP Server**, **NGINX**, and **WordPress** instances to their latest patched versions due to active RCE exploitation. 2. **Enforce Browser Updates:** Force an enterprise-wide update of **Microsoft Edge** to version 146.0.7680.153 or later to mitigate actively exploited vulnerabilities. 3. **Audit Python Development Environments:** Scan for and remove malicious versions (1.82.7, 1.82.8) of the **LiteLLM** PyPI package and investigate for signs of credential theft from developer systems. 4. **Review MFA & Conditional Access Policies:** In light of the Kali365 and Gunra campaigns, audit Microsoft 365 sign-in logs for device code authentication anomalies and ensure MFA bypass protections are in place.
## 🔗 References
- [Exploit-DB: [local] Microsoft Edge 150.0.4078.48 - RCE](https://www.exploit-db.com/exploits/52632)
- [FortiGuard Outbreak Alerts: WP2Shell RCE](https://fortiguard.fortinet.com/outbreak-alert/wp2shell-rce)
- [The Hacker News: Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html)
- [The Hacker News: Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations](https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html)
- [The Hacker News: Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor](https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html)