<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/web-security/</link><description>Recent content in Web-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/web-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical Avada WordPress theme flaw enables zero-click RCE</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-critical-avada-wordpress-theme-flaw-enables-zero-click-rce/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-critical-avada-wordpress-theme-flaw-enables-zero-click-rce/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Avada is among the most widely deployed commercial WordPress themes, and unauthenticated PHP code execution is a maximum-severity primitive — update Avada to the patched release this sprint. No KEV listing or public PoC is confirmed yet, so this is urgent but not emergency-weekend work.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>BdThemes Supply Chain Attack Creates Rogue WordPress Admin Accounts</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-bdthemes-supply-chain-attack-poisons-json-to-create-rogue-wo/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-bdthemes-supply-chain-attack-poisons-json-to-create-rogue-wo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active supply chain compromise affecting BdThemes WordPress plugins meets the Act threshold even without formal enrichment signals — audit all WordPress installations for BdThemes plugins and check admin user lists for unauthorized accounts created during the compromise window.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> The attack surface is concrete: hunt for unexpected WordPress administrator account creation events across managed sites, correlating with BdThemes plugin presence to identify compromised instances.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Add WordPress plugin vendor risk to your third-party/supply chain review process; if BdThemes plugins are in use anywhere in the organization, confirm with responsible teams that no rogue admins were introduced.&lt;/li>
&lt;/ul></description></item><item><title>Web Security is Too Hard</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-web-security-is-too-hard/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-web-security-is-too-hard/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> A well-discussed opinion piece (224 HN points, 117 comments) on the inherent complexity of web security — worth skimming for design philosophy and to calibrate where to focus hardening effort, but no actionable change required today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Rails patches critical Active Storage flaw with RCE potential</title><link>https://curasec.metacog.co.kr/insights/2026-08-03-rails-patches-critical-active-storage-flaw-with-rce-potentia/</link><pubDate>Mon, 03 Aug 2026 13:48:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-03-rails-patches-critical-active-storage-flaw-with-rce-potentia/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Active Storage is a core Rails component widely used for file handling, so any Rails-backed app is likely exposed; no public PoC or KEV listing yet, but the critical severity and unauthenticated file-read-to-RCE path make this a patch-this-sprint priority — update Rails to the fixed version.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>