CuraSec

tag: Auth-Bypass · 3 items

2026-08-25 · BleepingComputer · source ↗ #wordpress#saml#auth-bypass
  • Engineer — Act: If you run the miniOrange SAML 2.0 SSO plugin on any WordPress site, update it immediately — active exploitation attempts are underway and successful attacks yield unauthenticated admin access via forged SAML responses. Audit recent admin accounts and session logs for signs of unauthorized logins.
  • SOC/IR — Act: Active exploitation is in progress; hunt for anomalous SAML authentication events and unexpected admin account creation or logins on any WordPress instances in your estate, and tune detections for unusual authentication source patterns against WordPress admin endpoints.
  • Leader — Plan: If your organization operates WordPress sites with the miniOrange SAML SSO plugin, direct teams to patch this week — a successful exploit grants full admin takeover, which could expose customer data or be used as a pivot point. Verify your WordPress plugin inventory and patch cadence.
2026-08-04 · BleepingComputer · source ↗ #cve#auth-bypass#active-exploitation
  • Engineer — Act: CVE-2026-18577 is CISA KEV-listed with a public PoC and confirmed active exploitation — patch N-central immediately to the vendor-specified fixed version, and audit logs for unauthorized access since the vulnerability affects both hosted and on-premises deployments.
  • SOC/IR — Act: Active exploitation of N-central means assume-breach posture for any org running it — sweep for anomalous authentication events on N-central servers and hunt for lateral movement originating from managed endpoints, as compromise of an RMM tool gives attackers broad access to managed devices.
  • Leader — Act: N-central is an RMM platform used by MSPs; if your organization or any MSP managing your environment runs it, request an immediate attestation of patch status and review whether threat actors could have used it as a pivot into your estate — this is the type of systemic MSP-chain risk worth a brief to leadership this week.
  • Signals: CVE-2026-18577 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
2026-07-11 · BleepingComputer · source ↗ #gitea#auth-bypass#supply-chain
  • Engineer — Act: If you run Gitea via the official Docker image, update to the patched image immediately — the flaw allows full admin impersonation and is being actively exploited. Audit recent repository access and check for unauthorized commits or access token creation.
  • SOC/IR — Act: Active exploitation of an admin-impersonation bug in a self-hosted code repository warrants an assume-breach sweep: review Gitea audit logs for anomalous authentication events or unexpected admin-level actions since the vulnerability became public, and hunt for signs of unauthorized repository access or code changes.
  • Leader — Act: If your organization self-hosts Gitea via Docker, confirm with engineering this week whether the vulnerable image is in use and verify patching status — unauthorized admin access to source code repositories is a direct supply chain and IP risk.