🟠 High | Source: The Hacker News
This weekly roundup covers multiple active threats including a WordPress remote code execution flaw, SonicWall zero-days, SharePoint zero-day exploitation, and attacks targeting AI services. Several vulnerabilities were being exploited in the wild before patches were available, with attack paths ranging from exposed systems to malicious use of legitimate public code.
Security Architect’s Take: Prioritise patching internet-facing assets immediately — SonicWall appliances, SharePoint servers, and WordPress instances should be audited for the specific flaws referenced. Review AI service API key exposure and ensure edge security appliances are not running outdated firmware, as zero-days in perimeter devices directly undermine cloud environment access controls.
Original advisory: ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More