Hackers Exploit Modular DS WordPress Plugin Flaw for Admin Access
Critical
Executive Summary
Hackers are actively exploiting a critical vulnerability, CVE-2026-23550, in the Modular DS WordPress plugin, allowing unauthenticated attackers to bypass authentication and gain admin-level privileges. This flaw is actively exploited in the wild.
Vulnerability Details
Affected Product: Modular DS WordPress plugin, versions up to and including 2.5.1
Identifier: CVE-2026-23550
CVSS Score: 10.0 (Critical)
Exploitation Status: Actively Exploited
Risk & Impact
Triage: Immediate update is crucial to prevent site compromise.
Attack Vector: By setting the specific parameter [origin equals mo] and any ‘type’ parameter, attackers bypass authentication via a flawed isDirectRequest() check, gaining access to sensitive routes.
Ease of Exploit: Trivial, requiring only a simple modification of the request to bypass authentication.
Action Plan
Immediate Action: Upgrade to Version 2.5.2 AND immediately regenerate WordPress salts in wp-config.php. Patching alone does not evict attackers who have already generated valid admin session cookies.
Workaround: Mitigation rules can be applied to block exploitation before patching.
Detection: Monitor for HTTP GET calls to the 'modular-connector' login endpoint (API route ending in /login/) and attempts to create new admin users. Check for suspicious admin accounts like "PoC Admin".
Relevant professional terms
Privilege Escalation
A type of security vulnerability where an attacker is able to obtain a higher level of access to a system than they are authorized for.
Authentication Bypass
A security flaw that allows an attacker to circumvent normal authentication mechanisms and gain unauthorized access to a system or application.
Cisco Patches AsyncOS Zero-Day Exploited Since November 2025
Critical
Executive Summary
Cisco has released a patch for a maximum severity zero-day vulnerability, CVE-2025-20393, in AsyncOS that has been actively exploited since November 2025, affecting Secure Email Gateway (SEG) appliances. The vulnerability allows for remote command execution with root privileges and has been exploited by a China-linked APT group.
Vulnerability Details
Affected Product: Cisco Secure Email Gateway (SEG) and Email and Web Manager running Cisco AsyncOS Software. Affected AsyncOS versions include 14.2 and earlier, 15.0, 15.5, and 16.0.
Identifier: CVE-2025-20393.
CVSS Score: 10.0 (Critical).
Exploitation Status: Actively Exploited.
Risk & Impact
Triage: Critical. Immediate patching or mitigation is required due to active exploitation and the potential for complete system compromise.
Attack Vector: The vulnerability stems from insufficient HTTP request validation in the Spam Quarantine feature, allowing attackers to send crafted requests to execute commands with root privileges.
Ease of Exploit: Exploitation is considered easy if the Spam Quarantine feature is enabled and exposed to the internet.
Action Plan
Immediate Action: Upgrade to fixed software releases: 15.0.5-016, 15.5.4-012, and 16.0.4-016 for Email Security Gateway; 15.0.2-007, 15.5.4-007, and 16.0.4-010 for Email and Web Manager.
Workaround: If patching is not immediately possible, disable the Spam Quarantine feature and restrict access to the appliance. Ensure the appliances are secured behind a firewall and monitor web log traffic for any unexpected activity.
Detection: Monitor for indicators of compromise (IOCs) related to the APT group UAT-9686, including the deployment of tools like AquaShell, AquaTunnel, and AquaPurge. Review logs for unauthorized access or tampering.
Relevant professional terms
Zero-Day Vulnerability
A software vulnerability that is known to the vendor but does not yet have a patch available, making it actively exploitable.
Secure Email Gateway (SEG)
A security solution that monitors email traffic to prevent malicious content from reaching user inboxes, acting as a barrier between an organization's email environment and the outside world.
Wiz Research discovered a critical supply chain vulnerability, dubbed CodeBreach, that abuses a CodeBuild misconfiguration to potentially take over key AWS GitHub repositories, including the JavaScript SDK powering the AWS Console. The vulnerability's CVE-ID and status are currently unknown.
Identifier: AWS Security Bulletin 2026-002-AWS (No CVE).
CVSS Score: N/A (Architecture Flaw)
Exploitation Status: Proof of Concept (Internal)
Risk & Impact
Triage: High Urgency
Attack Vector: Abuse of CodeBuild misconfiguration to hijack AWS GitHub repositories.
Ease of Exploit: Assessment required based on specific misconfiguration details.
Action Plan
Immediate Action: Review and rectify CodeBuild configurations to prevent unauthorized repository access.
Workaround: Implement strict access controls and monitoring for CodeBuild projects.
Detection: Monitor CodeBuild activity for suspicious behavior and unauthorized access attempts.
Relevant professional terms
Supply Chain Vulnerability
A weakness in any element of the supply chain (software, hardware, or processes) that could be exploited to compromise the security of the final product or service.
CodeBuild
A fully managed continuous integration service that compiles source code, runs tests, and produces software packages that are ready to deploy.
WhisperPair Exposes Bluetooth Earbuds and Headphones to Tracking and Eavesdropping
High
Executive Summary
The WhisperPair vulnerability (CVE-2025-36911) allows attackers to take control of Bluetooth earbuds and headphones without user interaction, potentially enabling eavesdropping and location tracking. This critical flaw affects devices using Google Fast Pair from various manufacturers.
Vulnerability Details
Affected Product: Bluetooth earbuds, headphones, and speakers using Google Fast Pair from vendors including Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, and Google
Identifier: CVE-2025-36911
CVSS Score: 7.1 (High)
Exploitation Status: No evidence of exploitation outside of lab settings
Risk & Impact
Triage: Critical. Immediate action is required due to the potential for unauthorized access and control of devices.
Attack Vector: An attacker within Bluetooth range (up to 14 meters) can force pairing with vulnerable devices, even without the device being in pairing mode. If the attacker is the first to pair the accessory, they can track the device's location via Google's Find Hub network.
Ease of Exploit: Easy. The attack can be performed using readily available hardware like a laptop or phone, requiring no user interaction.
Action Plan
Immediate Action: Android OS updates are insufficient. You must download the vendor-specific companion app (e.g., Sony Headphones Connect, JBL App) to manually push the firmware update to your accessory.
Workaround: While not a complete fix, avoid using vulnerable accessories in sensitive environments. Disabling Fast Pair scanning prompts on Android devices does not remove Fast Pair support from the accessory.
Detection: Monitor for unusual Bluetooth pairing activity and review tracking alerts.
Relevant professional terms
Bluetooth Eavesdropping
The unauthorized access and monitoring of Bluetooth communications, potentially leading to the interception of sensitive information or control of devices.
Bluetooth Tracker
A small electronic device that uses Bluetooth to help find misplaced items by connecting wirelessly to a mobile device.
UAT-8837, a China-nexus APT, is targeting North American critical infrastructure to gain initial access to high-value organizations. The group exploits both n-day and zero-day vulnerabilities, including CVE-2025-53690 in Sitecore.
Key TTPs
Initial Access: Exploitation of Sitecore zero-day vulnerability (CVE-2025-53690) and compromised credentials.
Execution: Deploys open-source tools like Earthworm, SharpHound, and GoTokenTheft.
Defense Evasion: Disables RestrictedAdmin for RDP and cycles through tool variants to evade detection.
Campaign Analysis
UAT-8837 has been active since at least 2025, focusing on critical infrastructure in North America. The group exfiltrates DLL-based shared libraries, potentially leading to supply chain compromises.
Targeting & Infrastructure
Target Profile: High-value organizations within critical infrastructure sectors in North America.
Infrastructure: Utilizes attacker-owned remote infrastructure and internal endpoints.
Relevant Terms
APT: Advanced Persistent Threat, a sophisticated, long-term cyberattack campaign.
Zero-Day: A vulnerability that is unknown to the vendor and for which no patch is available.
Gootloader, a malware used for initial access, now employs malformed ZIP archives with up to 1,000 parts to evade detection. This technique aims to bypass security measures by concatenating numerous archives.
Key TTPs
Initial Access: SEO poisoning leads users to compromised websites hosting malicious ZIP archives.
Execution: Tricking users into executing a malicious script file contained within the ZIP archive.
Defense Evasion: Using malformed ZIP archives with up to 1,000 parts to evade detection.
Campaign Analysis
Gootloader's evolution involves adapting obfuscation techniques to bypass security measures. Unremoved infections can lead to data theft or ransomware.
Targeting & Infrastructure
Target Profile: Targets include users searching for business-related documents such as agreements, contracts, and templates.
Infrastructure: Compromised websites, often WordPress sites, are used to host malicious documents.
Relevant Terms
SEO Poisoning: A technique used to manipulate search engine results to direct users to malicious websites.
Cobalt Strike: A commercial, full-featured penetration testing and red team tool often used by attackers for command and control.
AI-driven "vibe coding" tools excel at basic coding practices but often fail to implement adequate security controls, leading to potential vulnerabilities. Tenzai's tests revealed that AI agents struggled with authorization and were prone to Server-Side Request Forgery (SSRF) vulnerabilities.
Key Findings
AI coding agents are generally proficient at avoiding issues where good coding practices are well-established, such as preventing SQL injection (SQLi) and Cross-Site Scripting (XSS).
Tenzai's testing of five AI coding agents found a total of 69 vulnerabilities in 15 generated apps, ranging from critical to low severity.
All five AI agents introduced an SSRF vulnerability in tests, allowing attackers to invoke requests to arbitrary URLs.
The Bottom Line
The increasing adoption of AI-assisted coding necessitates a shift towards "vibe testing" to identify and mitigate vulnerabilities introduced by AI-generated code. While AI can accelerate development and reduce costs, organizations must prioritize security by implementing robust validation processes and security-focused helper models. Addressing the security risks associated with vibe coding is crucial to prevent potential breaches and ensure the integrity of applications developed with AI assistance.
Relevant Terms
Vibe Coding: An AI-assisted software development technique where developers use natural language prompts to generate code.
SQL Injection (SQLi): A code injection technique used to attack data-driven applications by inserting malicious SQL statements into an entry field.