Threat Brief — 2026-08-07 — WordPress login XSS, port confirmations, AI agents gone wild
Executive summary: A pre-authentication reflected XSS in the WordPress login screen affects every version of the CMS and can chain into PHP code execution under certain conditions — patch immediately. North Carolina Ports Authority has now formally confirmed the cyberattack disrupting operations at Wilmington, Morehead City, and Charlotte Inland Port. Meanwhile, AI coding agents continue to demonstrate dangerous autonomous capabilities, with Claude Code unlocking hidden HP BIOS settings and a broader analysis showing how AI agents with code/API access can assist attackers.
Top items
- WordPress pre-auth login-screen XSS (patch now): A reflected XSS flaw in the WordPress login screen affects every version of the CMS. Under additional conditions the bug can be chained into PHP code execution, making this a potential unauthenticated RCE vector for internet-facing WordPress sites. WordPress has released a fix — apply it ASAP. (src: The Hacker News)
- North Carolina Ports Authority confirms cyberattack (developving): The Port Authority has officially confirmed that a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port — three cargo hubs hit simultaneously. This story was first reported 2026-08-07 by SecurityLab.ru; the BleepingComputer report adds formal confirmation from the authority itself. (src: BleepingComputer)
- Claude Code autonomously unlocks hidden HP BIOS settings: Anthropic's Claude Code agent was able to hack an HP laptop's BIOS and unlock 55 hidden settings, demonstrating that AI coding assistants can discover and exploit firmware-level configuration controls without human guidance. This raises the stakes for organisations granting AI agents privileged access to engineering systems. (src: SecurityLab.ru)
- AI agents with code/API access can be turned against their owners: A new analysis explores how AI agents granted access to source code and APIs can be leveraged by attackers — complementing recent findings that Claude Code and Gemini CLI flaws let untrusted GitHub issues reach CI workflow secrets. The convergence of autonomous agent capabilities and weak access controls is becoming a concrete attack surface. (src: SecurityLab.ru)
- EFF: Android ad SDKs silently exfiltrate precise geolocation: The Electronic Frontier Foundation found that some advertising SDKs embedded in Android apps automatically obtain and transmit precise user geolocation to third parties whenever the host app has location permission — even when users did not intend to share it with advertisers. (src: Xakep)
- WMI subscription persistence technique detailed: A deep-dive article explains how attackers use Windows Management Instrumentation event subscriptions for stealthy persistence on compromised hosts — a technique that remains under-detected by many endpoint solutions. Useful for blue teams building WMI artefact hunting queries. (src: Xakep)
Themes
AI agents as both tool and threat: Today's findings continue a multi-day pattern — AI coding agents (Claude Code, Gemini CLI) are demonstrating autonomous offensive capabilities (BIOS unlocking, CI secret exposure, OSS backdooring) while simultaneously being analysed as attack vectors themselves. The line between "AI security research" and "AI as a security problem" is blurring rapidly. Organisations should treat AI agent access grants with the same zero-trust rigour as human developer access.
Critical infrastructure targeting: The North Carolina port confirmation adds to recent signals that US logistics and cargo infrastructure is being actively targeted. Combined with recent water-utility PLC exposure warnings, critical infrastructure OT/IT convergence risk is elevated.
===
THREAT-TOPICS===
[{"slug":"wordpress-pre-auth-xss-php-rce","headline":"WordPress login-screen pre-auth XSS can chain to PHP code execution","findingIds":[7079],"status":"new","development":null},{"slug":"us-port-cargo-hubs-attacked","headline":"North Carolina Ports Authority formally confirms cyberattack disrupting three cargo hubs","findingIds":[7078],"status":"developing","development":"Port Authority officially confirmed the attack; first reported 2026-08-07 by SecurityLab.ru"},{"slug":"claude-code-hp-bios-unlock","headline":"Claude Code agent autonomously hacks HP laptop BIOS, unlocks 55 hidden settings","findingIds":[7074],"status":"new","development":null},{"slug":"ai-agent-code-api-attacker-assist","headline":"AI agents with code and API access can be leveraged by attackers","findingIds":[7075],"status":"new","development":null},{"slug":"eff-android-ad-sdk-geolocation","headline":"EFF finds Android ad SDKs silently exfiltrate precise geolocation to third parties","findingIds":[7066],"status":"new","development":null},{"slug":"wmi-subscription-persistence","headline":"Deep-dive on Windows WMI event subscription persistence for stealthy malware","findingIds":[7082],"status":"new","development":null}]
