Today's report Older
Source: Security Rabbits
The Rabbit's Foot (TLDR)
WordPress Plugins and Themes Under Active Attack
Multiple WordPress plugins (Advanced Responsive Video Embedder, Cost Calculator Builder PRO) and the Streamit theme have critical vulnerabilities allowing full site takeover. Update or remove these components immediately.
Rails Active Storage Critical Flaw Allows File Read and RCE
CVE-2025-24293 in Active Storage lets unauthenticated attackers read arbitrary files and potentially execute code. Patch your Rails applications immediately.
CISA Urges Removal of Internet-Exposed PLCs After Water System Attacks
Following attacks on 30+ Minnesota water systems, CISA advises utilities to disconnect PLCs from the internet and harden OT security. Take action to protect critical infrastructure.
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Storm-2945 campaign 'CaptiveCrunch' compromises hotel Wi-Fi portals to deliver malware and steal Microsoft 365 tokens from travelers. Be cautious when using hotel networks and enable phishing-resistant MFA.
Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft
A firmware vulnerability in Coldcard wallets enabled a massive theft of 1,082.65 BTC. If you use Coldcard, update firmware immediately and monitor for any suspicious activity.
Source: CVE Trend
Trending vulnerability
CVE-2025-24293
Active Storage
    Published: 2026-01-30
    Updated: 2026-07-14




🥕 🥕
(23%)
# Active Storage allowed transformation methods potentially unsafe.Active Storage attempts to prevent the use of potentially unsafe image.transformation methods and parameters by default..The default allowed list contains three methods allow for the circumvention.of the ..
Source: NIST
NIST CVE
A hardcoded backdoor in the plugin allows unauthenticated attackers to authenticate as any admin user by supplying a publicly known token. Immediately update the plugin or remove it if no update is available.
An unauthenticated AJAX route allows arbitrary PHP function execution, enabling attackers to create admin accounts and take over the site. Update the theme to a patched version immediately.
Unauthenticated remote code execution via unsanitized input passed to PHP eval(). The required nonce is publicly accessible, making exploitation trivial. Update the plugin immediately.
The Azure AD OAuth login defaults to not verifying ID token signatures, allowing attackers to forge tokens and log in as any user, including admins. Upgrade to apache-airflow-providers-fab 3.7.3.
A pre-authentication heap buffer overflow allows remote unauthenticated attackers to crash the server or execute arbitrary code via a malformed SSH client string. Update to version 3.9.5 or later.
An unauthenticated attacker can bypass authentication and authorization on certain API endpoints via a crafted HTTP request, exposing sensitive data. Apply the vendor patch or upgrade to a fixed version.
Hardcoded credentials in the bundled WildFly management interface allow unauthenticated remote attackers to gain admin access and deploy malicious code. This EOL product should be replaced or isolated immediately.
Other software at risk
News
CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than [...] (Security Affairs)
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, [...] (The Hacker News)
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of [...] (Security Affairs)
Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic
Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign [...] (Security Affairs)
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by [...] (The Hacker News)
Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...] (BleepingComputer)
Source: Ransomware.live
Ransomware attacks
🛑 thegentlemen
Philippine Savings Bank
👻 qilin
Ceragres  \\ Commercial Furniture Interiors  \\ Dienst Pack Systems  \\ The Saturday Evening Post  \\ Pointe Property Group  \\ Schreiner Trockenbau GmbH
💀 play
Cambridge Management  \\ Sigma Plastics Group  \\ The Butcher Brothers
⚠️ incransom
quantinuum.com
🧠 Global Secret Group
Vernon & Waldrep
🦠 Gammax
MTCO (Mahmoud Altaheni & Partners Trading Co)
🧠 coinbasecartel
Xs Cad  \\ MIM Fertility  \\ M. B. Kahn Construction Co.  \\ CEN and Cenelec
Source: Hybrid Analysis
Top malicious URL
Source: Hybrid Analysis
Top malicious files