Threat Brief — 2026-08-08 — open-iscsi root, Docker traversal, phish tournament
Executive summary. Three critical-to-high vulnerabilities in open-iscsi headline today's batch — including a remote limited file-write as root and an authentication bypass on the iscsiuio control socket. A separate Docker Compose path-traversal flaw (CVE-2025-62725) via OCI artifact layer annotations warrants immediate patching for containerised environments. On the offensive side, researchers demonstrated a simple extension-rename trick that can compromise Windows Update servers, and phishers launched a gamified "tournament" targeting Crédit Agricole customers through abused Amazon and SendGrid infrastructure. A kernel-level Safe-RET fix lands as a direct response to the TONTOU interrupt-injection attack disclosed earlier this week.
Top items
- open-iscsi triple-threat — remote root file-write, auth bypass, and double-free. Three CVEs in the open-iscsi stack demand urgent attention for any Linux environment running iSCSI: CVE-2026-44943 enables a remote limited file-write as root via the discovery component; CVE-2026-44944 is an authentication bypass on the iscsiuio control socket, allowing unauthorised command execution; and CVE-2026-55995 is a double-free in the iSNS attribute decoder, exploitable for potential code execution. All three affect the open-iscsi project; prioritise patching on any storage-attached Linux hosts. (src: MSRC) (src: MSRC) (src: MSRC)
- Docker Compose path traversal via OCI artifact layer annotations (CVE-2025-62725). A path-traversal vulnerability in Docker Compose allows attackers to escape expected file boundaries through crafted OCI artifact layer annotations. Organisations using Docker Compose to pull or build from OCI artifacts should treat this as high priority — successful exploitation could lead to arbitrary file overwrite on the host. (src: MSRC)
- Windows Update servers compromised via .exe-to-.txt extension rename. Researchers demonstrated that renaming an executable to .txt — combined with a pair of commands — can achieve stealthy penetration of corporate networks through a vulnerable Windows Update service component. The simplicity of the technique makes it a realistic lateral-movement vector in environments where WSUS or equivalent update infrastructure is exposed. (src: SecurityLab)
- Safe-RET hardened against interrupt injection (CVE-2026-68480). This x86 kernel fix makes Safe-RET robust against interrupt-injection attacks — a direct development of the TONTOU CPU attack first reported 2026-08-06, which bypassed Spectre v2 mitigations and leaked Linux password hashes. The patch closes a class of speculation-side-channel exploitation that affected modern Intel/AMD kernels. First reported 2026-08-06 by The Hacker News. (src: MSRC) — develops interrupt-injection-attack-bypasses-spectre-v2-defenses
- Phishing "tournament" targets Crédit Agricole customers with €3,000 prize. Attackers gamified credential theft by turning standard Amazon and SendGrid email delivery infrastructure into a phishing competition targeting clients of the French bank. The abuse of reputable sending domains gives the lures high deliverability and evades many email security gateways. (src: SecurityLab)
- Quadratic-behaviour DoS in Python xml.etree.ElementPath (CVE-2026-6879). Crafted index predicates in ElementPath queries can trigger quadratic CPU consumption, enabling a denial-of-service condition in any Python application parsing untrusted XML with ElementTree. Lower severity but worth noting for any service accepting user-supplied XML. (src: MSRC)
Themes
- Storage stack exposure. The open-iscsi trio underscores that iSCSI/iSNS components — often running with elevated privileges and network-exposed by design — remain a rich attack surface. Audit for open-iscsi deployments in your environment and verify control-socket binding scope.
- Infrastructure-as-trust-anchor abuse. Both the Docker Compose OCI annotation traversal and the Windows Update extension trick exploit trusted build/delivery mechanisms. Attackers are increasingly targeting the seams between container orchestration, artifact registries, and OS update channels.
- Gamified social engineering. The Crédit Agricole phishing tournament signals continued evolution of phishing from mass-blast to engagement-optimised campaigns — incentive structures and gamification increase victim interaction rates.
