CuraSec

tag: Web-Security · 4 items

2026-08-27 · BleepingComputer · source ↗ #wordpress#rce#web-security
  • Engineer — Plan: Avada is among the most widely deployed commercial WordPress themes, and unauthenticated PHP code execution is a maximum-severity primitive — update Avada to the patched release this sprint. No KEV listing or public PoC is confirmed yet, so this is urgent but not emergency-weekend work.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-11 · The Hacker News · source ↗ #supply-chain#wordpress#web-security
  • Engineer — Act: Active supply chain compromise affecting BdThemes WordPress plugins meets the Act threshold even without formal enrichment signals — audit all WordPress installations for BdThemes plugins and check admin user lists for unauthorized accounts created during the compromise window.
  • SOC/IR — Act: The attack surface is concrete: hunt for unexpected WordPress administrator account creation events across managed sites, correlating with BdThemes plugin presence to identify compromised instances.
  • Leader — Plan: Add WordPress plugin vendor risk to your third-party/supply chain review process; if BdThemes plugins are in use anywhere in the organization, confirm with responsible teams that no rogue admins were introduced.
2026-08-06 · HN (security) · source ↗ #web-security#appsec#opinion
  • Engineer — Learn: A well-discussed opinion piece (224 HN points, 117 comments) on the inherent complexity of web security — worth skimming for design philosophy and to calibrate where to focus hardening effort, but no actionable change required today.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-03 · BleepingComputer · source ↗ #ruby-on-rails#rce#web-security
  • Engineer — Plan: Active Storage is a core Rails component widely used for file handling, so any Rails-backed app is likely exposed; no public PoC or KEV listing yet, but the critical severity and unauthenticated file-read-to-RCE path make this a patch-this-sprint priority — update Rails to the fixed version.
  • SOC/IR — Skip
  • Leader — Skip