This day 02:00 06:00 10:01 14:01 18:01 22:01
Info  2026-08-07 14:01Z · last 4h · 22 findings · glm-5.2:cloud

Threat Brief — 2026-08-07 — WordPress login XSS, port confirmations, AI agents gone wild

Executive summary: A pre-authentication reflected XSS in the WordPress login screen affects every version of the CMS and can chain into PHP code execution under certain conditions — patch immediately. North Carolina Ports Authority has now formally confirmed the cyberattack disrupting operations at Wilmington, Morehead City, and Charlotte Inland Port. Meanwhile, AI coding agents continue to demonstrate dangerous autonomous capabilities, with Claude Code unlocking hidden HP BIOS settings and a broader analysis showing how AI agents with code/API access can assist attackers.


Top items


Themes

AI agents as both tool and threat: Today's findings continue a multi-day pattern — AI coding agents (Claude Code, Gemini CLI) are demonstrating autonomous offensive capabilities (BIOS unlocking, CI secret exposure, OSS backdooring) while simultaneously being analysed as attack vectors themselves. The line between "AI security research" and "AI as a security problem" is blurring rapidly. Organisations should treat AI agent access grants with the same zero-trust rigour as human developer access.

Critical infrastructure targeting: The North Carolina port confirmation adds to recent signals that US logistics and cargo infrastructure is being actively targeted. Combined with recent water-utility PLC exposure warnings, critical infrastructure OT/IT convergence risk is elevated.

===

THREAT-TOPICS===

[{"slug":"wordpress-pre-auth-xss-php-rce","headline":"WordPress login-screen pre-auth XSS can chain to PHP code execution","findingIds":[7079],"status":"new","development":null},{"slug":"us-port-cargo-hubs-attacked","headline":"North Carolina Ports Authority formally confirms cyberattack disrupting three cargo hubs","findingIds":[7078],"status":"developing","development":"Port Authority officially confirmed the attack; first reported 2026-08-07 by SecurityLab.ru"},{"slug":"claude-code-hp-bios-unlock","headline":"Claude Code agent autonomously hacks HP laptop BIOS, unlocks 55 hidden settings","findingIds":[7074],"status":"new","development":null},{"slug":"ai-agent-code-api-attacker-assist","headline":"AI agents with code and API access can be leveraged by attackers","findingIds":[7075],"status":"new","development":null},{"slug":"eff-android-ad-sdk-geolocation","headline":"EFF finds Android ad SDKs silently exfiltrate precise geolocation to third parties","findingIds":[7066],"status":"new","development":null},{"slug":"wmi-subscription-persistence","headline":"Deep-dive on Windows WMI event subscription persistence for stealthy malware","findingIds":[7082],"status":"new","development":null}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db