Rose debug info
---------------

Human Factor Blog

how human behavior affects security

Programmer’s Digest #199

08/19/2026-08/26/2026 Critical isolated-vm Flaw, 4 npm Packages Abuse unpkg Mirrors, GitLab CVE-2026-19478 And More.

1. Critical isolated-vm Flaw Lets Untrusted JavaScript Escape Sandbox and Hijack Host Execution

A critical flaw in isolated-vm, a popular Node.js sandboxing library, could let untrusted JavaScript escape its V8 sandbox and potentially hijack the host process. Tracked as GHSA-864f-rcv7-6rh4 (CVE pending), it affects versions before 7.0.1 and 6.2.0, patched August 8, 2026.

The bug lies in ExternalCopy’s transferList handling, which moves ArrayBuffer memory across isolation boundaries. The native code validates entries in one pass but transfers them in a second without revalidating types — a TOCTOU/type-confusion flaw. Endor Labs researchers found an attacker can exploit this with a JavaScript getter that returns a valid ArrayBuffer on first read but a different value on second read, tricking the host into treating attacker-controlled data as a buffer.

Exploitable with just one exposed ivm.Reference, impact ranges from host process crashes to control-flow hijacking and potential arbitrary code execution outside the sandbox — serious for multi-tenant apps, AI agent platforms, and services running customer-supplied JavaScript.

Users should upgrade to 7.0.1 or 6.2.0 immediately and audit native binding layers.

2. Hackers Target WordPress Sites in MiniOrange Auth Bypass Attacks

Attackers are actively exploiting two chained authentication bypass flaws in the miniOrange SAML SSO plugin for WordPress, letting them forge SAML responses and log in as administrators. Tracked as CVE-2026-61979 and CVE-2026-15981, the bugs stem from the plugin accepting an attacker-chosen signature algorithm (allowing HMAC-SHA1 abuse of the IdP’s known public key) and mishandling an OpenSSL verification error as success.

Both were disclosed and patched in July, but the vendor’s advisory covered only the free edition — leaving six paid editions (used by ~30,000 customers) without notice, despite fixes existing for those too. Patchstack reports real exploitation: DigitalOcean blocked a suspicious admin session on August 16, traced to attackers chaining both flaws via the Standard edition. Scanning is underway from six IPs across Europe, Africa, and the US, and a public PoC targets the free edition.

Since WordPress won’t flag updates for paid versions, admins must manually upgrade to patched releases.

3. 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have uncovered a campaign using 24 npm packages as free phishing infrastructure for ClickFix-style fake CAPTCHA pages. The packages themselves aren’t designed to infect developers who install them. Instead, threat actors exploit npm and its mirrors as safe, validated storage for malware. The packages, many still downloadable, contain a single HTML page. Once mirrored on services like unpkg, these pages render as fake Cloudflare CAPTCHA prompts hosted on trusted domains.

Victims opening such links see a bogus verification page that redirects them to attacker-controlled infrastructure for ClickFix attacks or credential harvesting. The HTML embeds JavaScript sending requests to remote servers. Initially, requests went to a typosquatted Microsoft login domain. After Chrome’s Safe Browsing blocked it, attackers switched to KeyVal, a legitimate key-value store, using it as a dead drop resolver to decode redirect URLs. Currently redirects lead to ChatGPT, but researchers warn the infrastructure could deliver phishing domains anytime. 

4. GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed GitLab flaw, CVE-2026-19478 (CVSS 9.4), is already under active exploitation. The code injection vulnerability lets unauthenticated attackers modify or delete public GitLab projects without credentials or user interaction.

Affected versions include GitLab CE/EE 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab said the issue can be exploited via a GraphQL directive and released fixes in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. 
watchTowr reproduced the vulnerability within minutes and observed in-the-wild exploitation against its honeypots. AI-enabled attackers are able to compress the time from disclosure to exploitation. The impact extends beyond deletion—attackers can forge merge records and ban maintainers. Organizations should patch immediately or restrict unauthenticated access to “/api/graphql” and remove public repository access. 

5. Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo has patched a high-severity code injection flaw in its notebook software, tracked as CVE-2026-75149 (CVSS v3.1: 8.8, CVSS v4: 8.7). A specially crafted notebook could supply an attacker-controlled MCP server command through its configuration; when opened in edit mode, that command ran as a local subprocess before any notebook cell executed. No attacker authentication was required, though user interaction (opening the notebook) was.

The issue is fixed in version 0.23.15, released July 23. Marimo’s patch hardens handling of notebook metadata by treating it as attacker-controlled, stripping notebook-supplied configuration sections — including ai, mcp, completion, secrets, and server — through an allowlist. The current PyPI release is 0.24.0.

A related flaw, CVE-2026-67618 (CVSS 7.1), disclosed August 4, involved an attacker-controlled AI base_url in notebook metadata that could exfiltrate a user’s API key on their next AI request, also fixed in 0.23.15.

Users on affected versions should upgrade immediately.

6. Citrix Urges Admins to Patch New NetScaler Flaws 

Citrix is urging customers to patch two NetScaler flaws immediately. The more severe, CVE-2026-19490, lets unauthenticated remote attackers bypass authentication on appliances configured as AAA virtual servers or Gateways (SSL VPN, ICA Proxy, CVPN, RDP Proxy), depending on firmware version and SAML Action configuration. The second, CVE-2026-19489, is a high-severity memory overflow enabling DoS attacks when SIP ALG is enabled on large-scale NAT configurations.

Admins can check exposure by searching their config for SAML action/vserver strings (CVE-2026-19490) or the “sipalg” NAT group string (CVE-2026-19489). Citrix recommends upgrading to NetScaler ADC/Gateway 14.1-73.32, 13.1-63.21, or the relevant FIPS/NDcPP builds.

Neither flaw is currently known to be exploited, but Citrix previously disclosed two other NetScaler bugs in March that attackers began abusing within days, one later added to CISA’s KEV catalog. Over 22,000 NetScaler ADC and nearly 1,800 Gateway instances remain exposed online.

1 d   digest   programmers'

Programmer’s Digest #198

08/12/2026-08/19/2026 Attackers Exploit MLflow SSRF Flaw, 16 Typosquatted RubyGems Packages, Actively Exploited Ray Flaw  And More.

1. Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Two severe vulnerabilities in MLflow and FUXA are under active exploitation. CVE-2026-64849 (CVSS 9.3) is an unauthenticated SSRF flaw in MLflow affecting versions below 3.15.0, allowing attackers to reach cloud metadata endpoints and steal credentials. Exploitation began within hours of disclosure on August 17, 2026, with attackers indiscriminately scanning for exposed instances. The flaw bypasses prior fixes by exploiting web redirect handling.

CVE-2026-25895 (CVSS 9.5) is a missing authentication and path traversal vulnerability in FUXA versions ≤1.2.9, enabling unauthenticated remote code execution via arbitrary file writes. Scanning started August 18, 2026, from a single IP targeting roughly 60 exposed FUXA installations. Attackers are overwriting main.js with junk data, though no RCE payloads have been observed yet.

Organizations should patch immediately, review logs for compromise, and check for exposed credentials.

2. 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have uncovered a typosquatting campaign targeting RubyGems users with a Windows info-stealer dubbed StubMaker. Discovered on August 15, 2026, the campaign involved 16 malicious gems—including ubnuler, ri18nr, and brumdler—all clumsy typosquats of popular Ruby dependencies. The packages have since been yanked.

The malware harvests browser credentials, crypto wallets, seed phrases, and Telegram data. It exploits Ruby’s package name reuse and unvalidated author fields, allowing attackers to republish yanked gems under new accounts. The attack chain uses an “extconf.rb” hook to fetch a Rust-based loader from GitHub, which launches a Go-based stealer that bypasses Chrome’s app-bound encryption to extract data from Chromium browsers. Stolen information is uploaded to Gofile as a password-protected ZIP, with the link sent to the attacker over unencrypted HTTP.

The same actor also targeted npm with 37 typosquatted packages using postinstall hooks to deliver the identical payload. Researchers recommend isolating infected Windows hosts, rotating credentials, and removing malicious libraries.

3. CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

Ray, with 43,500 GitHub stars and over 7,900 forks, contains a critical vulnerability tracked as CVE-2025-62593 (CVSS 9.4) enabling remote code execution through DNS rebinding attacks in Firefox and Safari.

The flaw stems from Ray’s lack of authentication on critical endpoints, allowing attackers to execute arbitrary code against developers running Ray who visit malicious websites or view malicious ads. The attack can also target network-adjacent Ray instances inside private corporate networks, using the browser as an intermediary.

The vulnerability primarily affects development and testing environments. It was patched in version 2.52.0. Researchers Avi Lumelsky and Jonathan Leitschuh were credited with discovery.

Threat actors behind the RondoDox botnet incorporated the exploit two days before public disclosure on November 26, 2025. Unpatched instances have also been targeted in the ShadowRay 2.0 campaign, turning GPU clusters into cryptocurrency mining botnets. FCEB agencies must apply fixes by August 20, 2026.

4. SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts

A critical SAP Commerce Cloud vulnerability, CVE-2026-58231, is under active exploitation. Rated 10.0 on CVSS, it stems from insufficient authorization checks and input validation, allowing unauthenticated attackers to abuse a default authentication client and submit crafted input to vulnerable functions. Successful exploitation could enable arbitrary code execution and compromise internal components, severely impacting confidentiality, integrity, and availability.

Defused Cyber detected exploitation attempts on its honeypots just three days after the patch was released. KEVIntel independently confirmed two attempts on August 14 from a U.S.-based IP address.

Onapsis urges customers to patch immediately and rebuild/redeploy the fixed Commerce Cloud version. As a temporary measure, organizations can configure IP Filter Sets to restrict access to the vulnerable endpoint.

The attackers remain unidentified, though previous SAP flaws have been exploited by China-linked groups and ransomware actors.

8 d   digest   programmers'

Programmer’s Digest #197

08/07/2026-08/12/2026 SAP Commerce Cloud Flaw, BDThemes WordPress Supply Chain Attack, Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT And More.

1. SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

SAP has released patches for a maximum-severity flaw in Commerce Cloud (Data Hub Adapter) that could enable arbitrary code execution. The bug, CVE-2026-58231 (CVSS 10.0), stems from insufficient authorization checks and input validation. CVE.org notes it lets an unauthenticated attacker abuse a default authentication client to submit crafted input to under-validated functions, compromising confidentiality, integrity, and availability. Onapsis has urged customers to patch and redeploy, with an IP Filter Set as a temporary mitigation.

SAP’s August 2026 update also fixes three other critical flaws: CVE-2026-44772 (CVSS 9.9), a code injection bug in Manufacturing Integration and Intelligence letting a low-privileged attacker trigger command execution via a vulnerable servlet fetching external content; CVE-2026-34265 (CVSS 9.8), an out-of-bounds write in NetWeaver/ABAP Platform’s DIAG protocol parsing that can leak data or crash systems; and CVE-2026-44758 (CVSS 9.1), an SSTI/SSRF flaw enabling privileged attackers to run OS commands, fixed by removing the vulnerable servlet.

2. Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, sat on PyPI for roughly 40 minutes on March 24 carrying credential-stealing code that harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords. Threat intel firm CloudSEK says a dataset built from ~434,000 captured files maps potential exposure to over 2,500 organizations, though these are files the attackers stole, not victim-confirmed data, and CloudSEK stresses the totals aren’t a victim count. NVIDIA, Cisco, Deloitte, Volkswagen, FedEx, Siemens, and X Corp appear among matches; both CloudSEK and LiteLLM recommend rotating credentials rather than waiting for proof of misuse.

The incident is tied to a broader TeamPCP campaign (tracked as UNC6780) that also compromised Aqua Security’s Trivy scanner, force-pushing malicious commits across dozens of version tags. The FBI warned in a July advisory that stolen credentials may be weaponized long after initial compromise, urging rotation of CI/CD secrets, publishing tokens, and cloud credentials, plus checks for campaign-linked repos like tpcp-docs.

3. BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells

A supply chain compromise has hit WordPress plugin vendor BdThemes, letting attackers silently create rogue admin accounts and install webshells without altering any plugin code. Wordfence, alerted August 7, found threat actors poisoned a JSON banner feed (“Biggopti”) used across plugins like Element Pack, Prime Slider, and Ultimate Post Kit. The feed fetches from a DigitalOcean Spaces bucket; a stored XSS flaw in Prime Slider’s display_id field let attackers inject a payload that fires on admin page load, contacts a C2 server, creates a new admin account via the session’s REST API nonce, and uploads a disguised plugin containing a webshell. That webshell installs persistent Must-Use plugins, including a magic-login backdoor and an account-hiding module. A secondary payload generates deterministic bd_-prefixed credentials from each victim’s hostname. Wordfence links the infrastructure to prior Advanced Responsive Video Embedder and OptinMonster/TrustPulse incidents. Affected plugins were pulled; site owners should audit user lists and mu-plugins directories. 

4. Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 (now 1,033+) malicious npm packages, using AI-generated typo-squatted names, deliver cross-platform RAT/infostealer malware, per OpenSourceMalware and Sonatype (tracking it as “Flooding Dropper”). Instead of install hooks, READMEs instruct developers to load them via require(), triggering a downloader called WEL1DROPPER that detects the OS/architecture and fetches payloads from Cloudflare Workers or, as fallback, via DNS TXT records from “wel1[.]ru.” Windows payloads patch ETW/AMSI to evade monitoring; macOS uses LaunchAgent persistence; Linux deploys the Sliver C2 framework. A hidden “telemetry.js” file duplicates the downloader logic as camouflage. Domains suggest targeting of Russian financial institutions, and researchers link the campaign to April’s “Moika” dependency-confusion operation.

Separately, Unit 42 documented other npm/PyPI campaigns delivering crypto stealers, cloud credential theft, and CI/CD token exfiltration, plus Chrome extensions covertly turning browsers into residential proxy nodes via embedded bandwidth-sharing SDKs.

5. Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE

Microsoft’s August 2026 Patch Tuesday fixes 398 CVEs, 62 rated Critical, including one actively exploited zero-day. CVE-2026-68820, a use-after-free in the WinSock kernel driver (afd.sys), is under active exploitation and can grant SYSTEM privileges via a race condition. The most urgent fix is CVE-2026-62878, a critical, potentially wormable Windows DNS Server stack buffer overflow allowing unauthenticated remote code execution with no user interaction—serious given how widely DNS servers are exposed.

Three more RCE bugs stand out: CVE-2026-62893 in WDS’s unauthenticated TFTP service; CVE-2026-62815 in Microsoft’s QUIC/HTTP-3 implementation, affecting an estimated 13.5 million sites; and CVE-2026-59124, a CVSS 9.8 flaw in HPC Pack Microsoft flags as “exploitation more likely.” An Exchange authentication-bypass bug, CVE-2026-62911, was demonstrated with working exploit code at Pwn2Own Berlin and could let attackers compromise every mailbox on a server. Two publicly disclosed bugs and two TPM 2.0 flaws round out the release.

15 d   digest   programmers'
Earlier Ctrl + ↓