Rosetta Daily · Aug 31, 2026
Scanned 285 items from 6 sources over the last 36 hours; selected 12.
Critical Vulnerabilities
Five critical flaws across popular WordPress plugins and themes enable site takeover (CVE-2026-76581, CVSS 9.8, and others)
Wordfence and Patchstack disclosed critical flaws in WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. The lead issue, CVE-2026-76581, is an authentication bypass in WPMU DEV Dashboard letting unauthenticated attackers take over affected sites; the set together spans authentication bypass, account takeover, and arbitrary code execution.
Sources: The Hacker News
Rodauth authentication bypass lets any logged-in user impersonate another account (CVE-2026-82466, CVSS 9.4)
Rodauth before 2.46.0 mishandles account resolution in its webauthn_login route, falling back to session account identifiers instead of validating credentials — any authenticated user can become any other account.
Sources: NVD
AI Security
argocd-mcp exposes Argo CD's full tool surface with no authentication (CVE-2026-82456, CVSS 10.0)
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without caller credentials when ARGOCD_API_TOKEN is set. Anyone who can reach the listener inherits the operator's stored token and can create applications, trigger syncs, and modify Argo CD resources.
Sources: NVD
Six CVSS 8+ disclosures land in one day across AI agent and LLM tooling
Alongside argocd-mcp, NVD published a cluster of high-severity flaws in AI infrastructure software within hours of each other: keploy's agent control-plane HTTP server binds to all interfaces with no auth, exposing an endpoint that streams TLS session keys (CVE-2026-82641, CVSS 8.8); NextChat's proxy endpoint leaks the server's OpenAI API key because its x-base-url header check uses substring matching instead of hostname parsing (CVE-2026-82639, CVSS 8.7); jina-ai reader disables its private-address guard outside Google Cloud, opening it to SSRF against cloud metadata (CVE-2026-82638, CVSS 8.7); iFlytek's astron-agent fails to validate workflow ownership in its copyFlow endpoint, letting attackers read or overwrite other tenants' workflows (CVE-2026-82475, CVSS 8.6); and Skyvern's TextPromptBlock renders prompts through a sandboxed Jinja environment and then an unsandboxed one, letting injected template syntax escape the sandbox for code execution (CVE-2026-82447, CVSS 8.7). None are yet in the KEV catalog.
Sources: NVD — keploy · NVD — NextChat · NVD — jina-ai reader · NVD — astron-agent · NVD — Skyvern
Infostealer malware is hijacking Claude sessions to drain usage, Anthropic warns
Anthropic is warning some users that infostealer malware on their machines has stolen active Claude login sessions, letting attackers access accounts and consume the victim's usage allowance.
Sources: Bleeping Computer
Other Threat Activity
TerminalFix variant of ClickFix deploys a reverse-tunnel backdoor via fake Cloudflare CAPTCHAs
Microsoft disclosed TerminalFix, a ClickFix variant that directs victims to Windows Terminal or PowerShell instead of the Run dialog, increasing the odds that a complex malicious command executes successfully.
Sources: The Hacker News
Chrome and Edge extensions caught stealing crypto and browser data
Multiple browser extensions delivered a malware framework with modules that stole cryptocurrency, sensitive data, and browser history, and injected ClickFix lures into pages.
Sources: Bleeping Computer
FulcrumSec claims theft of 86 GB of data from Manchester Airports Group
FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record; leaked samples show customer, booking, and travel information beyond what MAG initially disclosed.
Sources: Bleeping Computer