Ransomware Campaigns Exploit SharePoint Flaw to Run Server Code
CISA now links CVE-2026-45659 to ransomware. Check exact SharePoint builds, then investigate whether low-privilege access reached the farm before patching.
Reader edition
CISA now links CVE-2026-45659 to ransomware. Check exact SharePoint builds, then investigate whether low-privilege access reached the farm before patching.
Researchers chain signed Windows device installers into SYSTEM execution through emulated USB hardware or an ordinary RDP session.
A signed ClickOnce app delivered two stealers and an hVNC RAT after a fake Web3 interview. Hunt per-user ClickOnce records, then rotate every secret reachable from affected hosts.
Microsoft's August updates fix an AFD.sys race used in attacks; defenders must verify fixed builds and investigate pre-patch privilege escalation.
Unit 42 says stolen AI API keys can reach gray-market proxy services within minutes, turning one exposed credential into catastrophic usage charges.
Public research turns a patched NetScaler memory overflow into a root-code-execution risk for SAML deployments, making build verification urgent.
Customer contact data is public after a social-engineering breach; defenders should harden support and identity checks against targeted impersonation.
CVE-2026-65640 reaches Ghostscript on sites using Imagick; WordPress 7.0.4 and exact backports move content checks ahead of image processing.
August Windows updates fix a public registry-hive privilege escalation; defenders can hunt its staging files, virtual paths, and unusual DLL loads.
Exposed ASA and FTD remote-access services need release-specific hot fixes; Cisco offers no workaround for the exploited denial-of-service flaw.
Rapid7 joined a SharePoint identity bypass to unsafe .NET type creation. August's cumulative updates complete Microsoft's two-cycle fix.
Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.
CISA confirms exploitation of a pre-authentication LoadMaster command-injection flaw. API-enabled appliances need a fixed release and an exposure review.