Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-08-17
Daily Brief·2026-08-17·33 Sources·18 Items

Rosetta Daily · Aug 17, 2026

Scanned 33 sources, read 304 raw items (36-hour window), selected 18.

Critical Vulnerabilities

  • 🔴 openssl_encrypt (PyPI crypto library) discloses 15 critical CVSS 9.3 vulnerabilities in one batch: sandbox escapes (AST analyzer bypassed via __class__.__mro__.__subclasses__() chains for arbitrary command execution), auth bypass (verify_api_token accepts any non-empty Bearer token), KEM decapsulation silently falling back to a predictable simulation mode that leaks plaintext, AES-GCM failures falling back to unauthenticated AES-CTR, and more. Fixed in 1.4.0. Examples: CVE-2026-74900, CVE-2026-74901, CVE-2026-74896.

  • 🔴 SiYuan note-taking app has 3 critical bugs before v3.7.4: path traversal in the MCP database_clean tool allowing arbitrary file read/delete (CVE-2026-74798, CVSS 9.3); unauthenticated /debug/pprof endpoints outside prod mode leaking access codes and AI provider API keys (CVE-2026-74799, CVSS 9.2); stored XSS via missing Content-Disposition headers on served assets (CVE-2026-74800, CVSS 9.4).

  • 🔴 WordPress ProSolution WP Client plugin: two bugs chain to unauthenticated RCE: arbitrary file deletion (CVE-2026-14524, CVSS 9.1 — deleting wp-config.php can trigger code execution) and arbitrary file upload (CVE-2026-16098, CVSS 9.8); a publicly exposed frontend nonce lets unauthenticated attackers reach both.

  • 🔴 WordPress Frontend Admin by DynamiApps plugin: privilege escalation to administrator (CVE-2026-18432, CVSS 9.8): an is_numeric() check gates the authorization test on an unauthenticated AJAX endpoint, letting attackers coerce a non-numeric user ID into administrator (ID 1) and take over the account.

  • Certighost: AD CS privilege escalation lets a standard domain user become equivalent to a Domain Controller (CVE-2026-54121). Underlines PKI's long-underestimated status as Tier 0 identity infrastructure. Source: Bleeping Computer.

  • WordPress login-page XSS2Shell flaw reportedly affects ~11,000 sites, reachable without an account. No CVE number or further technical detail given in the source — verify against the original. Source: 安全客 (AnQuanKe).

Actively Exploited / KEV

  • 🔥 New CISA KEV addition: Ray-Project Ray code injection vulnerability (CVE-2025-62593). Confirmed present in intel.kev_catalog via SQL, added 2026-08-18.

  • 🔴⚠️ VMware vCenter directory traversal (CVE-2026-59310, CVSS 9.8) exploited by a suspected China-nexus APT to deploy Babuk-derived ransomware. Verified via SQL: NOT currently in the CISA KEV catalog. Source: The Hacker News.

  • ⚠️ Microsoft Defender "ShieldBreak" zero-day (CVE-2026-69414) under active exploitation; patch in progress. Verified via SQL: not currently in KEV. Source: Bleeping Computer.

  • ⚠️ Unisoc VoLTE video-call exploit chain gives full Android kernel access; chipset maker has not fixed it. This is stage two of an exploit chain first disclosed in March. Source: The Hacker News.

AI Security

  • ⚠️ How MCP servers can expose enterprise secrets: plaintext configuration files, over-permissioned access, and prompt injection can leak secrets before security teams even know a server is running. Source: The Hacker News.

  • AI supply-chain incident: ~195TB of data reportedly stolen from 2,500 companies in 40 minutes. The source gives only headline figures, no vendor name or further technical detail — verify against the original before acting on it. Source: 安全客 (AnQuanKe).

Other

  • Philips and GE investigating Clop ransomware data-theft claims. Source: Bleeping Computer.

  • French tax authority (DGFiP) data breach affects 678,000 individuals. Source: Bleeping Computer.

  • SafePal hardware wallet breach exposes ~39,798 customers; stolen data for sale. Source: Bleeping Computer.

  • Evooo1Bot: new Mirai-derived Linux botnet turns edge devices into SOCKS5 proxies. Source: The Hacker News.

  • AmnesiaStealer: new macOS infostealer hijacks browser sessions via remote control (ClickFix delivery). Source: Bleeping Computer.

  • Threema secure messaging service disrupted by large-scale DDoS attacks this week. Source: Bleeping Computer.

← Prev
Rosetta Daily · Aug 16, 2026
Next →
Rosetta Daily · Aug 18, 2026