Suriq - Always on Watch
Practitioner cybersecurity analysis from the Suriq desk.
What to patch, what to detect, and why it matters, in plain English.
Managed security built on Wazuh. suriq.io
⚠️ PATCH NOW
Microsoft Exchange has an auth-bypass flaw (CVE-2026-62911) that relays a server's own account into a webshell running as SYSTEM.
A public exploit just dropped, and 21,899 servers are still exposed.
Patch, then turn on Extended Protection.
https://suriq.io/blog/exchange-cve-2026-62911-auth-bypass-webshell-poc
🔴 EXPLOITED
Chrome's V8 engine has its sixth zero-day of 2026 (CVE-2026-85046), exploited in the wild.
Chrome 152.0.7977.82 is only half the job. Edge, Brave, Opera and Electron apps run the same engine and patch separately.
WP Fastest Cache, a WordPress plugin on 1M+ sites, has a flaw that lets a stranger poison your cached pages and serve malicious code to every visitor.
Fix: update to 1.5.1 and clear your page cache.
A public exploit is due Sept 9. (CVE-2026-74916)
https://suriq.io/blog/wp-fastest-cache-cache-poisoning-cve-2026-74916
The Manchester Airports breach did not need a hacked server. An extortion group says it read a marketing API key straight out of the site's JavaScript and exported customer data. Your EDR would never see it.
https://suriq.io/blog/manchester-airports-client-side-api-key-breach
🔴 EXPLOITED
North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to take over defense and aerospace PCs.
Patched Aug 11, but exploited in the wild first; a kernel rootkit blinded security tools.
Run Windows? Update now and hunt.
https://suriq.io/blog/lazarus-operation-dream-job-windows-zero-day
Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it leaked to a private repo.
It is marked compromised, so past signatures no longer verify.
Verify by hand or ship Mozilla RPMs? Import the new key.
https://suriq.io/blog/mozilla-firefox-thunderbird-signing-key-revoked
🚨 BREAKING
Attackers did not breach Steam, ING or bol. They breached the shipping partner all three share, Ceva Logistics.
Customer names, addresses and order details across Europe are exposed. No passwords taken, but expect phishing that quotes your real orders.
https://suriq.io/blog/ceva-logistics-breach-customer-data-exposed
🔴 EXPLOITED
macOS Screen Sharing has an auth bypass (CVE-2026-65400) that gives a network attacker root with no password.
Apple patched it Aug 6; exposed Macs are already being hit to mine Monero.
Update now, or turn Screen Sharing off.
🔴 EXPLOITED
Gunra ransomware beat multi-factor authentication without phishing anyone. It rewrote a company's login server so one attacker-chosen code always passed.
MFA stayed on; every login looked clean.
It gets in via unpatched Fortinet flaws. Patching won't evict it.
🔴 EXPLOITED
LiteLLM, the open-source gateway fronting your LLM providers, has an auth bypass (CVE-2026-59822) CISA confirms is exploited.
Attackers reach its MCP tools and steal the provider keys it stores.
Fix: update to 1.84.0 and rotate keys.
https://suriq.io/blog/litellm-cve-2026-59822-mcp-auth-bypass
Close to 800 malicious npm packages ship a cross-platform stealer that runs on import, not at install.
Blocked web C2 falls back to DNS.
Pulled a new npm dependency this week? Hunt host and DNS logs.
Microsoft ties new StormEncryptor ransomware to China-linked Storm-1175, which breaks in via an N-able N-central auth bypass (CVE-2026-18577).
One management console breach reaches every downstream client.
Patch to 2026.3.1.7, then hunt.
https://suriq.io/blog/storm-1175-stormencryptor-rmm-ransomware
⚠️ PATCH NOW
SAP NetWeaver has a critical flaw (CVSS 9.8) that lets a stranger crash the server or leak its memory with no login, through the protocol SAP GUI speaks.
Affects SAP NetWeaver AS ABAP; no public exploit yet.
Fix: apply SAP's August kernel patch. (CVE-2026-34265)
https://suriq.io/blog/sap-netweaver-diag-unauth-memory-corruption
The Fabrik add-on for Joomla has a max-severity flaw (CVSS 10, CVE-2026-67282): a stranger can run code on the server with no login.
Every site on Fabrik below 4.6.8 is exposed.
Fix: update to 4.6.8 now, then check for stray PHP files.
https://suriq.io/blog/fabrik-joomla-unauth-rce-cve-2026-67282
The Unitree G1 humanoid robot has two flaws that give root with no login (CVE-2026-76639, CVE-2026-76640).
One works over Bluetooth from across a room, and a hacked robot can infect other G1 units nearby.
Unitree fixed the cloud part; isolate the rest.
Ivanti's Endpoint Manager has three new high-severity flaws, all fixed in the 2024 SU7 update.
One leaks stored database passwords, one lets a user rewrite session recordings, one crashes the agents.
Not exploited yet. Patch now. (CVE-2026-18129)
https://suriq.io/blog/ivanti-epm-august-2026-su7-management-plane-flaws
⚠️ PATCH NOW
Dell PowerStore storage arrays have a critical flaw (CVSS 9.8): reach the management interface with no login and you can read files that hold admin credentials.
Affects the PowerStore T line (500T to 9200T).
Patch, then rotate the array's credentials.
https://suriq.io/blog/dell-powerstore-unauth-credential-leak-cve-2026-58574
AmnesiaStealer, a new macOS stealer, doesn't stop at saved passwords. It clones your browser and drives it live, inside your logged-in sessions.
Spread via fake GitHub pages that tell you to paste a Terminal command.
Reset sessions, not just passwords.
https://suriq.io/blog/amnesiastealer-macos-live-browser-hijack
JFrog Artifactory has an unauthenticated bypass (CVE-2026-82329, CVSS 9.8) that lets a stranger forge admin tokens, exploited now.
Self-managed instances in default config are in scope.
Patch, then rotate tokens: the upgrade won't revoke a forged one.
https://suriq.io/blog/jfrog-artifactory-cve-2026-82329-admin-token-forge
A BGP route hijack redirected Softaculous traffic and pushed a malicious Virtualizor update that ran as root.
Encryption checked the connection, not the file. The updates were not signed.
Run Virtualizor? Patch to 3.2.9.9 and hunt for the rogue service.
https://suriq.io/blog/virtualizor-bgp-hijack-malicious-update
WHMCS CVE-2026-67399: if you cannot upgrade to 8.13.7 or 9.0.8 yet, we published a stopgap hook that blocks the payload types this bug most likely needs.
Not a fix. Copy it, test it, delete it after you patch.
Adobe patched a critical Magento and Adobe Commerce flaw (CVE-2026-71362, CVSS 9.1): a stranger can switch into any customer's account with no login.
Affects all stores through the July 2026 patch level.
Fix: apply Adobe bulletin APSB26-92 now.
https://suriq.io/blog/magento-adobe-commerce-account-takeover-cve-2026-71362
A public exploit, HardBreacher, turns Kaspersky's endpoint agent into a local privilege-escalation tool on fully patched Windows 11.
The flaw is in the agent, not Windows, so OS patching misses it.
Kaspersky says it is fixed. Check your agent version.
https://suriq.io/blog/kaspersky-endpoint-security-hardbreacher-privilege-escalation
🚨 BREAKING
Police, the FBI and CrowdStrike disrupted Sality, a botnet that has infected 15,000+ machines since 2003.
The catch: it breaks the operator's control, not the infections. Every hit machine is still infected.
Run old Windows hosts? Hunt for it now.
https://suriq.io/blog/sality-botnet-takedown-machines-still-infected
A Cisco firewall flaw (CVE-2026-20349) lets a stranger crash your ASA or FTD with one crafted request. No login, no workaround, already exploited.
When the box reloads, your VPN tunnels drop and its logs go dark.
Patch to the fixed build by August 14.
https://suriq.io/blog/cisco-asa-ftd-cve-2026-20349-dos-exploited
🔴 EXPLOITED
Sangoma Switchvox has a critical unauthenticated flaw (CVE-2026-9586, CVSS 9.3) that lets a stranger run code on the phone system.
Patched in July, mass-exploited since Aug 30. Around 4,000 consoles are exposed.
Fix: update to 8.4.0.2 and hunt the logs.
https://suriq.io/blog/switchvox-cve-2026-9586-unauth-rce-exploited
GeoServer, the open-source map server, has an unpatched zero-day: unauthenticated SQL injection that can reach remote code execution.
No fix yet; probing began within hours.
Restrict access and cut the database account's privileges now.
https://suriq.io/blog/geoserver-zero-day-sql-injection-rce-no-patch
AJCloud camera firmware (CVE-2026-56718) lets anyone on the network read the files as root, no login.
The dump leaks your Wi-Fi password and video-stream logins in the clear.
Fix: firmware 01.10715.11.37, then isolate the camera.
https://suriq.io/blog/ajcloud-ipc-camera-path-traversal-cve-2026-56718
Evooo1Bot is a new Linux botnet that exploits internet-facing devices, then turns them into proxies and credential thieves.
It targets Confluence, WSO2 and ingress-nginx, not just routers.
Watch for rogue services and odd outbound traffic.
https://suriq.io/blog/evooo1bot-linux-botnet-servers-socks-relay
Two of this week's five critical WordPress flaws (GiveWP, CVSS 10.0, and Avada) don't just take over the site, they run code on the hosting server. All five are unauthenticated. Patch now.
https://suriq.io/blog/wordpress-five-critical-plugin-theme-flaws-server-rce
Opening a booby-trapped code repository can run an attacker's commands in editors built on Eclipse Theia (the framework under Arduino IDE 2.x and other tools).
A crafted git config runs on folder open, no trust prompt. CVE-2026-19884, CVSS 8.4.
Fix: update to Theia 1.70.0.
https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884
⚠️ PATCH NOW
WHMCS, the billing platform many hosting firms run, has a critical flaw (CVE-2026-67399): a stranger with no login can run code on the server.
Affects 9.x before 9.0.8 and 8.x before 8.13.7. No workaround.
Patch now.
https://suriq.io/blog/whmcs-unauthenticated-rce-cve-2026-67399-patch
The "malicious LiteLLM packages" headlines miss it. The real breach was Trivy, the container scanner, poisoned in CI five days earlier.
CloudSEK maps 2,500+ orgs of potential exposure, not confirmed breaches.
Ran Trivy in March? Rotate your keys.
⚠️ PATCH NOW
Predis, a widely used PHP client for Redis, has a critical flaw (CVSS 9.8, CVE-2026-84372): attacker-controlled cache keys can smuggle extra Redis commands.
Hits versions 3.0 to 3.2 on cluster and replication setups.
Fix: upgrade to Predis 3.3.0.
https://suriq.io/blog/predis-crlf-command-injection-cve-2026-84372
Encrypted AI reasoning blocks from OpenAI, Anthropic, and Google can be decoded by a weaker model from the same provider.
Researchers pulled 182 credentials from 315,320 blocks in public repos. Stop sharing raw AI logs.
ClickFix trained people to paste into the Run box, and defenders learned to watch it. TerminalFix moved the paste into Windows Terminal, where old rules do not look. The fix did not change: watch the sequence.
https://suriq.io/blog/terminalfix-clickfix-windows-terminal-reverse-tunnel
Undertow, the web server inside Red Hat JBoss, has a pre-login flaw (CVE-2026-15565) that lets anyone crash the server by flooding a WebSocket until it runs out of memory.
Affects JBoss EAP 7/8 and Data Grid 8. No patch yet.
Fix: disable WebSockets where you can.
VulnCheck found two more factory backdoors in ZBT router firmware: SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233).
One calls out, one listens on an open port for anyone to reach as root.
No fix. Replace the hardware.
https://suriq.io/blog/zbt-speakingstone-darklantern-router-backdoors








