WordPress, OpenSSL, Fortinet zero-days: patches shipped and KEV escalations
ID: 03ae7509-42e4-585f-9c00-df94b505b938
STIX ID: report--03ae7509-42e4-585f-9c00-df94b505b938
Feed Name: defend.network
This briefing reports multiple high-severity, actively-exploited issues and compromises: WordPress core deserialization RCE (versions 6.9/7.0) patched via forced updates; an OpenSSL 'HollowByte' memory-exhaustion DoS; two Fortinet FortiSandbox command-injection CVEs added to CISA KEV with active exploitation and an urgent remediation deadline; NadMesh botnet actively harvesting AWS keys and Kubernetes tokens from exposed AI services; and a DigiCert breach tied to an APT subgroup resulting in stolen code-signing certificates — defenders are advised to apply patches, inventory affected assets, rotate exposed credentials, and monitor for IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
