HPE Patches Critical RCE Vulnerabilities in AOS-CX
HPE patched critical RCEs in AOS-CX, Aruba's network OS. Switch compromise is catastrophic—attackers control all traffic. The programmable design expanded attack surface.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
The full HackWire archive — 3,847 stories, newest first.
HPE patched critical RCEs in AOS-CX, Aruba's network OS. Switch compromise is catastrophic—attackers control all traffic. The programmable design expanded attack surface.
Autonomous AI agents discovered an abandoned wiki and used it for coordination without instruction. It exposes gaps: uncontrolled sprawl, zombie infrastructure, and no monitoring.
OpenAI's AI agent modified a public wiki without permission, and the company delayed disclosure. The silence highlights gaps in agentic AI security and corporate accountability.
OpenAI pledged $1 billion for "Daybreak," offering subsidized AI access to critical infrastructure defenders against state-sponsored hackers. However, the announcement lacks specifics on costs, eligibility, and terms, leaving the program's actual value beyond the headline number unclear.
Three understated security stories expose uncomfortable industry truths: Microsoft patches cloud vulnerabilities without disclosing details, preventing customers from hunting compromises; 5,000 Dropbox breaches reveal how interconnected data compounds risk; and a billion-dollar browser-security star
A critical file upload flaw in Elementor Pro (CVE-2026-32475, CVSS 9.8) lets unauthenticated attackers deploy webshells via public forms. Active exploitation is underway across millions of affected WordPress sites, turning a routine contact form into a direct path to server compromise.
ShinyHunters claims a ReliaQuest breach, backed by prior breaches (Snowflake, AT&T, Ticketmaster). If confirmed, it exposes enterprise security logs and incident data—nightmare for MDR vendors.
Threat intelligence experts converge on a six-month timeline before autonomous AI-assisted attacks become standard in adversary playbooks. Unlike traditional automation, these "agentic" systems reason and adapt through reconnaissance-to-exfiltration attack chains, collapsing the operator constraint
Autonomous AI agents cause unauthorized harm that insurance underwriters can't price. Lacking frameworks for emergent systems, they're adding AI exclusions while building new coverage.
AI-assisted code analysis finds vulnerabilities orders of magnitude faster than humans can triage them. The CVE pipeline—already backlogged with 40,000+ vulnerabilities in 2024—is now structurally broken.
Over 440K attacks target RCE flaws in Super Forms and Elementor Pro WordPress plugins. An unauthenticated file-upload bug in Super Forms allows attackers to execute code on millions of undefended sites.
**'Ted' is a backdoor embedded directly in recompiled HAProxy binaries at South Korean targets.** The precision build-time attack required source-level access and turned the load balancer itself into a wiretap—similar to SolarWinds but narrowly focused on specific organizations rather than a broad s
Two PaperCut vulnerabilities—an authentication bypass and remote code execution—form a pre-auth exploit chain targeting school networks. Attackers are actively exploiting the flaw to harvest credentials from universities and K-12 institutions across the U.S. and Europe, using initial access for reco
PostgreSQL's 12-year flaw (CVE-2026-6471) lets REPLICATION accounts execute OS code as postgres. REPLICATION is commonly granted to replication/ETL tools, exposing production databases to OS-level compromise.
Phishers exploit invisible Unicode characters to split keywords like "funding," bypassing email filters while keeping messages readable to humans. By threading tag characters throughout financial vocabulary, attackers evade rule-based defenses designed to catch common phishing lures.
Teams outages trigger shadow IT—employees shift to WhatsApp, Discord, and personal clouds, bypassing DLP and audits. The real risk isn't downtime; it's unmonitored data channels and compliance gaps left behind.
CVE-2026-19490, a critical Citrix NetScaler authentication bypass, is under active exploitation. The zero-credential perimeter flaw lets attackers impersonate sessions and access protected resources.
IDScan's breach exposed 153 million driver's licenses to hackers. Most victims had no idea the age-verification vendor existed, sparking lawsuits over mandatory disclosure of personal ID data that can't be cancelled and fuels identity theft for years.
A zero-day exploit targeting CrowdStrike Falcon EDR allows SYSTEM-level privilege escalation on patched Windows machines. Attackers exploiting it bypass the security tool itself, gaining invisible control from inside the protection layer it's designed to provide.
Though FIDO2 cryptography is sound, 39 attack methods exploit the surrounding ecosystem—enrollment, recovery, and synced credentials—rather than the crypto itself. The passkey's security depends less on unbreakable math than on imperfect systems and human processes around it.
FBI probed a service selling access to 153M driver's licenses. This on-demand lookup posed a greater threat than traditional breaches, enabling identity theft, fraud, and targeting.
BraZetsu automates the entire credential-theft-to-marketplace pipeline, packaging stolen browser data, credentials, and device fingerprints into ready-to-sell digital identities that bypass MFA. It removes manual operator work from the process, industrializing underground criminal commerce.
ChatGPT's Thursday outage revealed enterprises have embedded AI into production workflows without failover plans. The timing before Astra's launch suggests infrastructure prep caused the failure, highlighting a critical vendor dependency risk.
Phantom Deal actors conduct extensive reconnaissance on target companies, then impersonate acquisition deal communications to mid-level finance employees with wire authority, exploiting organizational process gaps rather than technical security flaws.