2026-06-19
2026-06-19 00:00Z
HIGH

Lost in relocation: analysis of a new loader distributing CASTLESTEALER

Elastic Security Labs·elastic.coin the wild

Elastic Security Labs discovered OXLOADER, a previously undocumented Windows loader distributing the CASTLESTEALER infostealer via malicious Google Ads impersonating Node.js. The loader employs sophisticated obfuscation (control-flow flattening, mixed Boolean-Arithmetic, opaque predicates), self-modifying decryption stubs, .reloc section abuse for shellcode staging, and five anti-VM/sandbox checks (CPU count, RAM, display refresh rate, network emulation, geographic/language exclusions) to evade detection and analysis. The attack chain uses batch scripts hosted on Storj, UAC bypass, and DonutLoader to deliver .NET-based CASTLESTEALER in-memory, with attribution pointing to Russian-speaking financially motivated threat actors.

SRFApplicationTACTA0005TACTA0001TACTA0007SRFWebTACTA0003TACTA0042TACTA0043
82
Edit Score
2026-06-18
2026-06-18 23:16Z
HIGH

CVE-2026-56078 — PraisonAI: before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56078

PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite arbitrary files, enabling sensitive disclosure, denial of service, or code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 23:16Z
HIGH

CVE-2026-56076 — PraisonAI: before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56076

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks authentication and hardcodes Access-Control-Allow-Origin: * headers, combined with Starlette's Content-Type-agnostic JSON parsing, enabling attackers to bypass CORS preflight checks via simple requests and exfiltrate sensitive agent responses including tool execution results and env CVSSv3.1 8.1 (HIGH)

CWECWE 942VNDPraisonaiTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-18
2026-06-18 23:16Z
HIGH

CVE-2026-56075 — PraisonAI: Authenticated attackers can instruct the LLM agent to execute arbitrary shell commands via subprocess.run

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56075

PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable. Authenticated attackers can instruct the LLM agent to execute arbitrary shell commands via subprocess.run with shell=True, bypassing the manual approval gate and insufficient command sanitization blocklists. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDPraisonaiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 22:16Z
CRIT

CVE-2026-54130 — Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54130

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 22:16Z
CRIT

CVE-2026-47647 — Microsoft: Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47647

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDMicrosoftTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-18
2026-06-18 21:16Z
CRIT

CVE-2026-49454 — Relyra: Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49454

Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept forged SAML signatures because SignatureValue was not cryptographically verified before the library returned a successful authentication result. The XMLDSig trust boundary was incomplete as :public_key.verify over the exclusive-C14N canonicalized SignedInfo was not performed against the configured IdP certificate's public key, DigestValue was not recomputed CVSSv3.1 9.1 (CRITICAL)

CWECWE 287CWECWE 347VNDRelyraTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-18
2026-06-18 21:16Z
CRIT

CVE-2026-49257 — Python: mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49257

mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP server bound to 0.0.0.0:8080 with no authentication enabled. All MCP tools, including SQL query execution, schema creation, and table-config mutation, are reachable by any network-adjacent caller. The server proxies these calls using server-side Pinot credentials, producing a confused-deputy condition that yi CVSSv3.1 10.0 (CRITICAL)

CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-18
2026-06-18 21:16Z
CRIT

CVE-2026-49252 — deepstream is a server that allows clients and backend services to sync data, send

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49252

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Versions prior to 10.0.5 are vulnerable to Prototype Pollution. Exploitation can lead to potential privilege escalation from any authenticated user with write permission to any record. This issue has been fixed in version 10.0.5. CVSSv3.1 9.9 (CRITICAL)

CWECWE 1321TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-18
2026-06-18 21:16Z
HIGH

CVE-2026-43994 — Coturn: Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm().

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43994

Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer overflow in decode_oauth_token_gcm(). A uint16_t nonce_len field read from an attacker-supplied OAuth access token (0-65535) is passed directly to memcpy() as the copy length into a 256-byte stack buffer (oauth_encrypted_block.nonce[256]) without bounds checking. The overflow occurs before AES-GCM authentication is verified, the attacker does not need to know t CVSSv3.1 8.1 (HIGH)

CWECWE 120VNDCoturnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-18
2026-06-18 20:16Z
HIGH

CVE-2026-48716 — nanobot is a personal AI assistant.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48716

nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path using the fileName field from an incoming WhatsApp document message without sanitization. The WhatsApp bridge downloads media attachments and writes them to disk using a filename derived from the sender's message via documentMessage.fileName, which is concatenated with a prefix and its raw value is passed directly to path.join(media CVSSv3.1 8.7 (HIGH)

CWECWE 22TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 20:16Z
CRIT

CVE-2026-47846 — Bitnami: Cassandra container images are affected by a retained default superuser vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47846

Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the container initialization script creates the new superuser account but fails to drop the built-in cassandra account in certain scenarios. This leaves the default cassandra:cassandra superuser active as an unintended access path. Affected versions — Container image: 4.0.x prior to 4.0.2 CVSSv3.1 9.8 (CRITICAL)

CWECWE 798VNDBitnamiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 18:16Z
CRIT

CVE-2026-54390 — JTL: Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54390

JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticated attackers to inject malicious template syntax due to unsanitized user-supplied input passed to the Smarty template engine. Attackers can exploit this flaw to read sensitive server-side values such as database credentials and encryption keys, and on versions 5.4.0 through 5.7.1, leverage registered Smarty modifiers including unserialize and file_get_content CVSSv3.1 9.8 (CRITICAL)

CWECWE 1336VNDJtlTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 17:16Z
HIGH

CVE-2026-56020 — Webmin: The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56020

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641. CVSSv3.1 8.1 (HIGH)

CWECWE 290VNDWebminTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-18
2026-06-18 17:16Z
HIGH

CVE-2026-55237 — AutoGPT: Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55237

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), which is passed to `router.push`. An attacker can craft a malicious link that, when opened by an authenticated user, performs a client-side redirect and executes arbitrary JavaScript in th CVSSv3.1 8.8 (HIGH)

CWECWE 601CWECWE 87VNDAutogptTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 17:16Z
HIGH

CVE-2026-54104 — Government: The U.S.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54104

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated attacker to escalate their own privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 602VNDGovernmentTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 17:16Z
CRIT

CVE-2026-54103 — Government: The U.S.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54103

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDGovernmentTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 17:16Z
HIGH

CVE-2026-48617 — Nodejs Node.js: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48617

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. CVSSv3.1 8.2 (HIGH) · EPSS 15th percentile

CWECWE 284TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-18
2026-06-18 17:16Z
CRIT

CVE-2026-38717 — InHand: Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38717

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDInhandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 17:16Z
CRIT

CVE-2026-38716 — InHand: Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38716

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDInhandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 17:16Z
CRIT

CVE-2026-38715 — InHand: Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38715

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDInhandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 17:16Z
CRIT

CVE-2026-38714 — InHand: Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38714

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDInhandTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-18
2026-06-18 16:30Z
INFO

BloodHound MCP, One Year Later: What I Learned About MCPs, Models, and Context

SpecterOps·specterops.io

Matthew Nickerson documents one year of BloodHound MCP development, detailing architectural refactoring from 100 individual tools to 13 composite tools. The redesign reduced fixed context overhead by 70% (19k to 5.7k tokens per turn) while improving model decision-making and error recovery. New features include file upload support for agentic workflows and domain-specific resources for Cypher query generation.

SRFApplicationSWBloodhoundSWMcpTYPResearchTYPToolTECT1087
72
Edit Score
2026-06-18
2026-06-18 16:16Z
HIGH

CVE-2026-46580 — Eclipse Theia: An attacker could craft a malicious repository containing prompt template files that, when the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46580

In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrust CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDEclipseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-18
2026-06-18 16:16Z
HIGH

CVE-2026-44691 — Eclipse Theia: An attacker could craft a malicious repository that, when cloned and opened in Theia

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44691

In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatica CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDEclipseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score