Rosetta Daily · Aug 17, 2026
Scanned 33 sources, read 304 raw items (36-hour window), selected 18.
Critical Vulnerabilities
-
🔴 openssl_encrypt (PyPI crypto library) discloses 15 critical CVSS 9.3 vulnerabilities in one batch: sandbox escapes (AST analyzer bypassed via
__class__.__mro__.__subclasses__()chains for arbitrary command execution), auth bypass (verify_api_tokenaccepts any non-empty Bearer token), KEM decapsulation silently falling back to a predictable simulation mode that leaks plaintext, AES-GCM failures falling back to unauthenticated AES-CTR, and more. Fixed in 1.4.0. Examples: CVE-2026-74900, CVE-2026-74901, CVE-2026-74896. -
🔴 SiYuan note-taking app has 3 critical bugs before v3.7.4: path traversal in the MCP
database_cleantool allowing arbitrary file read/delete (CVE-2026-74798, CVSS 9.3); unauthenticated/debug/pprofendpoints outside prod mode leaking access codes and AI provider API keys (CVE-2026-74799, CVSS 9.2); stored XSS via missing Content-Disposition headers on served assets (CVE-2026-74800, CVSS 9.4). -
🔴 WordPress ProSolution WP Client plugin: two bugs chain to unauthenticated RCE: arbitrary file deletion (CVE-2026-14524, CVSS 9.1 — deleting wp-config.php can trigger code execution) and arbitrary file upload (CVE-2026-16098, CVSS 9.8); a publicly exposed frontend nonce lets unauthenticated attackers reach both.
-
🔴 WordPress Frontend Admin by DynamiApps plugin: privilege escalation to administrator (CVE-2026-18432, CVSS 9.8): an
is_numeric()check gates the authorization test on an unauthenticated AJAX endpoint, letting attackers coerce a non-numeric user ID into administrator (ID 1) and take over the account. -
Certighost: AD CS privilege escalation lets a standard domain user become equivalent to a Domain Controller (CVE-2026-54121). Underlines PKI's long-underestimated status as Tier 0 identity infrastructure. Source: Bleeping Computer.
-
WordPress login-page XSS2Shell flaw reportedly affects ~11,000 sites, reachable without an account. No CVE number or further technical detail given in the source — verify against the original. Source: 安全客 (AnQuanKe).
Actively Exploited / KEV
-
🔥 New CISA KEV addition: Ray-Project Ray code injection vulnerability (CVE-2025-62593). Confirmed present in
intel.kev_catalogvia SQL, added 2026-08-18. -
🔴⚠️ VMware vCenter directory traversal (CVE-2026-59310, CVSS 9.8) exploited by a suspected China-nexus APT to deploy Babuk-derived ransomware. Verified via SQL: NOT currently in the CISA KEV catalog. Source: The Hacker News.
-
⚠️ Microsoft Defender "ShieldBreak" zero-day (CVE-2026-69414) under active exploitation; patch in progress. Verified via SQL: not currently in KEV. Source: Bleeping Computer.
-
⚠️ Unisoc VoLTE video-call exploit chain gives full Android kernel access; chipset maker has not fixed it. This is stage two of an exploit chain first disclosed in March. Source: The Hacker News.
AI Security
-
⚠️ How MCP servers can expose enterprise secrets: plaintext configuration files, over-permissioned access, and prompt injection can leak secrets before security teams even know a server is running. Source: The Hacker News.
-
AI supply-chain incident: ~195TB of data reportedly stolen from 2,500 companies in 40 minutes. The source gives only headline figures, no vendor name or further technical detail — verify against the original before acting on it. Source: 安全客 (AnQuanKe).
Other
-
Philips and GE investigating Clop ransomware data-theft claims. Source: Bleeping Computer.
-
French tax authority (DGFiP) data breach affects 678,000 individuals. Source: Bleeping Computer.
-
SafePal hardware wallet breach exposes ~39,798 customers; stolen data for sale. Source: Bleeping Computer.
-
Evooo1Bot: new Mirai-derived Linux botnet turns edge devices into SOCKS5 proxies. Source: The Hacker News.
-
AmnesiaStealer: new macOS infostealer hijacks browser sessions via remote control (ClickFix delivery). Source: Bleeping Computer.
-
Threema secure messaging service disrupted by large-scale DDoS attacks this week. Source: Bleeping Computer.