Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-08-09
Daily Brief·2026-08-09·33 Sources·15 Items

Rosetta Daily · Aug 9, 2026

Scanned 33 enabled sources; 209 raw items collected in the last 36 hours (115 CVE, 58 vendor advisories, 30 ransomware, 6 industry news); 15 selected.

Critical Vulnerabilities

WordPress AI Copilot – Content Generator Plugin Authorization Bypass (CVE-2026-14526, CVSS 9.8) 🔴
Versions up to and including 1.5.6 fail to properly verify user authorization. Unauthenticated attackers can create an administrator account via a malicious workflow containing a wp_create_user node (role=administrator), achieving full site takeover. Any site rendering the [aiwu-form] shortcode or a public chatbot is exposed, since the nonce value is emitted into public-facing JS, making the check non-functional.
Source: NVD

MSI Radix AXE6600 Router Command Injection Cluster (11 CVEs, all CVSS 9.3) 🔴
Firmware v781521 contains unauthenticated command injection across openvpn, macfilter, Telnet/SSH configuration, port forwarding, URL filtering, access control, and WPS endpoints, letting remote attackers execute arbitrary commands as root.
Source: NVD (CVE-2026-71983 through 71993)

D-Link DWR-M961 Command Injection / Buffer Overflow Cluster (15 CVEs, all CVSS 9.3) 🔴
Hardware version C1 devices are affected by command injection and buffer overflow flaws across quicksetup.cgi, app.cgi, and multiple /boafrm/ form interfaces (NTP, PIN management, IMEI, SMS management, USSD, diagnostics, LTE FOTA upgrade), allowing remote root command execution or device crash.
Source: NVD (CVE-2026-71944 through 71958)

Shenzhen Aitemi M300 Wi-Fi Repeater Command Injection (CVE-2026-19348, CVSS 8.9) 🔴
The smacfilter_conf function in /protocol.csp allows remote command injection via the enable/name/mac parameters. A public exploit is already available.
Source: NVD

Actively Exploited / KEV

Progress Kemp LoadMaster Command Injection Added to CISA KEV After 792 Reported Exploit Attempts (CVE-2026-8037, CVSS 9.6) 🔥⚠️
CISA added the flaw to its Known Exploited Vulnerabilities catalog last Friday following active exploitation reports; the command injection bug can be weaponized for arbitrary code execution.
Source: The Hacker News

N-able N-central Auth Bypass Still Under Active Exploitation, Vendor Ships Second Hotfix Round (CVE-2026-18556 / CVE-2026-18577, both in KEV) 🔥⚠️
N-able released a fresh round of N-central hotfixes, saying it continues monitoring threat actors as they evolve techniques to reach and persist on managed systems; both associated CVEs were added to CISA's KEV catalog on Aug 4 and Aug 3.
Source: The Hacker News

Metabase Zero-Day Exploited in the Wild, Grants Admin Access Without Authentication (CVSS 10.0, no CVE assigned yet) ⚠️
Metabase warned that a maximum-severity flaw in its BI software has been exploited as a zero-day, allowing unauthenticated attackers to inject arbitrary SQL into the application database and gain access.
Source: The Hacker News

Vendor Advisories

Kata Containers Guest-to-Host Escape (CVE-2026-47243)
A flaw in the runtime-rs component's virtiofs implementation allows guest-root to host-root escape.
Source: MSRC

Kata Containers Confidential Guest Memory Tampering (CVE-2026-64676)
Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory.
Source: MSRC

open-iscsi iscsiuio Control-Socket Authentication Bypass (CVE-2026-44944)
Source: MSRC

HAProxy Flaws Affect Community, Enterprise, and ALOHA (CVE-2026-26080, CVE-2026-26081)
Versions before 3.3.3 mishandle varint (loop/crash, CVE-2026-26080) and lack a length check for the NEW_TOKEN format (CVE-2026-26081).
Source: MSRC

Docker Compose Path Traversal via OCI Artifact Layer Annotations (CVE-2025-62725)
Source: MSRC

Web Security Research

New CSS Attacks Break Webmail Defenses to Steal Passwords and Tokens
Research shows email content can escape its message boundary and interfere with webmail UI. Attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail can capture passwords, hijack third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. Disclosed by PortSwigger researcher Gareth.
Source: The Hacker News

AI Security

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers ⚠️
Two security firms independently found this behavior via different routes: attacker-controlled instructions can make Rovo collect Jira/Confluence data the signed-in user can access and exfiltrate it to an outside server. PromptArmor hid instructions inside content Rovo reads (an uploaded file); only one of the two routes is confirmed fixed.
Source: The Hacker News

Other

Hackers Breach TrueConf to Trojanize Client Installers With Backdoors
The Head Mare hacktivist group exploited vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with backdoored versions.
Source: Bleeping Computer

← Prev
Rosetta Daily · Jul 31, 2026
Next →
Rosetta Daily · Aug 10, 2026