<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Unauthenticated on CuraSec</title><link>https://curasec.metacog.co.kr/tags/unauthenticated/</link><description>Recent content in Unauthenticated on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 18 Jul 2026 11:51:11 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/unauthenticated/index.xml" rel="self" type="application/rss+xml"/><item><title>HollowByte: 11-byte payload triggers OpenSSL memory DoS</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-by/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-hollowbyte-ddos-flaw-bloats-openssl-server-memory-with-11-by/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> OpenSSL is universally deployed across Linux servers, TLS termination points, and containers, so exposure is near-universal; however, no KEV listing, EPSS score, or public PoC is present, meaning no active exploitation pressure. Track the OpenSSL patch release and schedule deployment within your normal critical-patch window.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>WordPress Core wp2shell Flaw Enables Unauthenticated RCE</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-new-wp2shell-wordpress-core-flaw-lets-unauthenticated-attack/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-new-wp2shell-wordpress-core-flaw-lets-unauthenticated-attack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public PoC is available for an unauthenticated RCE in WordPress core affecting 6.9 and 7.0 with no plugins required — patch every WordPress instance to the fixed version immediately and audit web server file systems for newly dropped shells or unexpected PHP files.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> A public PoC for unauthenticated RCE in WordPress core means active exploitation is likely underway; sweep web access logs for anomalous POST patterns against wp-admin and wp-includes endpoints, and hunt for new or modified PHP files and unexpected child processes spawned by the web server process since the disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Unauthenticated RCE in WordPress core with a working public exploit is a systemic exposure for any org running WordPress-powered properties; confirm inventory of WordPress versions across customer-facing and internal sites, verify engineering has prioritized emergency patching, and assess whether key SaaS or media vendors in your supply chain are exposed.&lt;/li>
&lt;/ul></description></item></channel></rss>