Security news.
Threat actors continue targeting identity and edge infrastructure, underscored by massive cryptocurrency theft and fresh active exploitation warnings from federal agencies. CISA has added several actively abused flaws across SharePoint, MikroTik, WSO2, and WordPress to its Known Exploited Vulnerabilities catalog. Meanwhile, emerging attack vectors around autonomous AI agents and cloud service principals are creating new challenges for enterprise defenders.
Suspected North Korean Hackers Steal $351.6M from Bitget
Cryptocurrency exchange Bitget reported unauthorized transfers siphoning $351.6 million from its hot and warm wallets in an attack attributed to North Korean threat actors.
CISA Adds SharePoint and MikroTik Flaws to KEV Catalog
CISA warned of active exploitation involving a Microsoft SharePoint code injection bug (CVE-2026-65660) and a MikroTik RouterOS workflow enforcement flaw (CVE-2026-67279), mandating swift federal remediation.
WordPress Core Remote File Inclusion Added to CISA KEV
CISA added an actively exploited WordPress Core vulnerability (CVE-2026-87902) allowing remote file inclusion to its Known Exploited Vulnerabilities catalog.
WSO2 and Adobe Commerce Vulnerabilities Under Active Attack
Federal agencies flagged critical flaws under in-the-wild exploitation, including a CVSS 9.8 path traversal vulnerability in WSO2 products (CVE-2026-5430) and an authorization bypass in Adobe Commerce (CVE-2026-71362).
Roundcube Pre-Auth SQL Injection Exploited in the Wild
Canadian cybersecurity authorities warned that attackers are actively exploiting CVE-2026-48842, an unauthenticated SQL injection vulnerability affecting Roundcube Webmail's virtuser_query plugin.
Elementor WordPress Plugin Flaw Enables Rogue Admin Creation
A cross-site request forgery vulnerability discovered in the widely used Elementor WordPress plugin allows unauthenticated attackers to trick authenticated users into creating rogue administrator accounts.
Salesforce Agentforce 'SalesBleed' Flaws Allowed Zero-Click Data Theft
Security researchers detailed three vulnerabilities dubbed SalesBleed that allowed attackers to hijack trusted autonomous AI agents to exfiltrate enterprise data and conduct targeted phishing.
Storm-3168 Conducts Agentic Cloud Attacks via Compromised Service Principals
Microsoft revealed attack campaigns abusing compromised Azure service principals for automated cloud reconnaissance, resource deletion, and credential harvesting.