CVE-2026-42945, CVE-2026-44283, CVE-2026-46483, CVE-2026-8328, CVE-2026-8368
Domains:
protect-wss[.]com
IP Addresses:
3.15.0.3
Get tomorrow's brief in your inbox
Today: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin. Microsoft quietly fixed a critical Azure Kubernetes privilege escalation but refuses to issue a CVE. NGINX patches 16-year-old heap overflow with public exploit code now available.
Funnel Builder Plugin Skimming Campaign (Active Exploitation)
WordPress sites running Funnel Builder versions before 3.15.0.3 face active exploitation. Attackers inject malicious JavaScript into WooCommerce checkout pages via an unauthenticated endpoint that allows calling internal methods without permission checks. The vulnerability affects over 40,000 stores. Attackers plant fake Google Tag Manager scripts that load payment skimmers stealing credit card numbers, CVVs, and billing addresses via WebSocket connections to wss://protect-wss[.]com/ws.
NGINX Heap Overflow (CVE-2026-42945)
Critical heap buffer overflow in NGINX's ngx_http_rewrite_module enables denial-of-service and remote code execution if ASLR is disabled. CVSS 9.2, introduced 16 years ago. PoC exploit code is now public. The flaw affects servers using rewrite and set directives when replacement strings contain question marks. Exploitation involves cross-request heap manipulation to corrupt memory pool cleanup pointers.
Azure Kubernetes Privilege Escalation (Silent Fix)
Security researcher Justin O'Leary reports Microsoft silently patched a critical Azure Backup for AKS privilege escalation after rejecting his vulnerability report and blocking CVE assignment. The flaw allowed users with only "Backup Contributor" role on a backup vault to gain cluster-admin access without existing Kubernetes permissions. Microsoft claims the issue required pre-existing administrative access, which O'Leary disputes. CERT/CC validated the vulnerability (VU#284781) but closed the case under CNA hierarchy rules. Following disclosure, the original attack path no longer works and Azure now requires manual Trusted Access configuration before backup enablement.
BlackFile Vishing Extortion Campaign (UNC6671)
Google Threat Intelligence Group tracks an ongoing extortion campaign by UNC6671 operating under the "BlackFile" brand. The group targets organizations via voice phishing and single sign-on compromise using adversary-in-the-middle techniques to bypass MFA. Campaign demonstrates sophisticated social engineering combined with technical SSO compromise capabilities.
1 claim tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Stormous | www.kai.id | Transportation | Indonesia |
Note: PT Kereta Api Indonesia is the national railway company operating train services throughout Indonesia.
Grafana GitHub Token Compromise and Extortion
Grafana disclosed an unauthorized party obtained a token granting access to the company's GitHub environment and downloaded its codebase. The attacker attempted to blackmail and extort Grafana, demanding payment to prevent publishing the stolen database. Grafana refused to pay the ransom per FBI guidance. No customer data or personal information was accessed. CoinbaseCartel claimed responsibility. The group is an offshoot of ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems, focusing on data theft and extortion without encryption. CoinbaseCartel has amassed 170 victims across healthcare, technology, transportation, manufacturing, and business services since emerging in September 2025.
Instructure-ShinyHunters Payment Debate
Media outlets continue investigating whether Instructure paid ShinyHunters after the extortion group's second attack on May 7. Despite pledging transparency, Instructure has not directly addressed the payment question in recent updates. The incident highlights ongoing debate in the security community about ransom payments to extortion groups.
Illuminate Education Data Breach Lawsuit
California Supreme Court ruled in J.M. v. Illuminate Education, Inc., a case closely watched by edtech vendors regarding liability for data breaches. Illuminate suffered a December 2021 breach affecting 1.7 million students in New York and 434,000 students in other states. The ruling provides precedent for holding educational technology vendors accountable for security failures.
Russian Kazuar Backdoor Evolves to P2P Botnet
Russian intelligence group Secret Blizzard (Turla, FSB-linked) transformed its Kazuar backdoor into a modular peer-to-peer botnet with enhanced stealth capabilities. The malware now operates using three modules: kernel (central coordinator), bridge (external communications proxy), and worker (espionage operations). The architecture uses leader election where one infected system communicates with C2 while others remain silent, reducing detection surface. Internal communications use IPC protocols including Windows Messaging, Mailslots, and named pipes with AES encryption and Protobuf serialization. The worker module performs keylogging, screenshots, filesystem harvesting, system reconnaissance, MAPI email collection, and window monitoring. Kazuar now supports 150 configuration options including AMSI bypass, ETW bypass, and WLDP bypass. The malware's code lineage dates back to 2005, with documented activity since 2017 targeting government, diplomatic, and defense organizations across Europe, Asia, and Ukraine.
Medicare Fraud Using Stolen Patient Records
Federal jury convicted Ruby Scott, 55, of Farmington Hills, Michigan, for operating a $1.6 million Medicare fraud scheme. Scott owned Delta Home Health Care LLC and used stolen patient records to defraud Medicare from 2018 through 2021. The case demonstrates intersection of healthcare data breaches and financial fraud.
CVE-2026-46483 (Vim Command Injection)
Command injection in Vim's tar#Vimuntar function via missing shellescape {special} flag. EPSS score 0.002 (38th percentile). Microsoft Security Response Center published information on this vulnerability.
CVE-2026-44283 (etcd RBAC Bypass)
Read access via PrevKv in etcd transactions may bypass RBAC authorization checks. EPSS score 0.000 (9th percentile). Affects etcd deployments using RBAC for access control.
CVE-2026-8368 (Perl LWP::UserAgent Header Leak)
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. EPSS score 0.000 (4th percentile). Affects Perl applications handling HTTP redirects with authentication credentials.
CVE-2026-8328 (Perl FTP PASV SSRF)
FTP PASV SSRF vulnerability where ftpcp() does not use actual peer address and trusts server-supplied PASV host address. EPSS score 0.000 (12th percentile). Affects Perl FTP clients vulnerable to server-side request forgery.
Active exploitation campaigns target e-commerce infrastructure and payment processing chains, with attackers disguising malicious code as legitimate analytics tools. The Microsoft Azure privilege escalation case highlights tension between security researchers and vendors over disclosure practices and CVE assignment authority. Russian state-sponsored groups continue long-term evolution of espionage infrastructure, adapting traditional backdoors into distributed architectures designed for persistence and stealth.