“Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations,” Grafana
said
in a series of
Category Added in a WPeMatico Campaign
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
Funnel Builder
plugin for WordPress has come under active exploitation in the wild to
inject malicious JavaScript code
into WooCommerce checkout pages with the goal of stealing payment data.
Details of the activity were
published
by Sansec this week. The vulnerability currently does not have an official CVE identifier. It
Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access
Turla
has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that’s engineered for stealth and persistent access to compromised hosts.
Turla, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA), is assessed to be affiliated with Center 16 of Russia’s Federal Security Service (FSB)
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
The vulnerabilities, collectively dubbed
Claw Chain
by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below –
What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
“Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to
On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email
The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue.
“
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits
The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It’s
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0.
“A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly
Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets
According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious –
node-ipc@9.1.6
node-ipc@9.2.3
node-ipc@12.0.1
“Early analysis indicates that node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1
