Severity Daily

IT and AI security incidents, checked against the primary source

Tag: session hijacking

  • In six of today’s ten stories, the authoritative record has nothing to say at all

    In six of today’s ten stories, the authoritative record has nothing to say at all

    The most consequential item on the site today is cPanel’s parked-domain flaw. The vendor’s own advisory says an authenticated account holder who can add a parked or addon domain “can create arbitrary files on the server,” and that “successful exploitation leads to code execution as the root user, giving an attacker full control of the server and every account, website, and database on it.” Fixed builds are named across five branches, so this is a task you can finish tonight. It outranks the bigger-sounding story — Boston Scientific told the SEC that a cybersecurity incident caused a global disruption to its operations, and the clinical detail is worse than the filing, but almost nobody reading this can act on it. What decides the ranking is the second half of the cPanel item: three days after the advisory, CVE-2026-65643 has no record at NVD or the CVE Program, so nothing in your scanner or your ticket queue will raise it on its own. Tonight’s one fixable catastrophic flaw is the one your tooling is guaranteed to miss.

    The day had a thread, and it is yesterday’s failure mode inverted. Yesterday the authoritative record said the wrong thing; today, in six of ten stories, it says nothing at all. cPanel’s CVE has no record. AjaxPro’s record, now on a federal clock, still says no fixed version exists, though the maintainer shipped deserialization controls in November 2021. Two CVE records describe unauthenticated root code execution on the Unitree G1 EDU humanoid, one of them from Bluetooth range with no pairing, and neither the records, the CNA, nor Unitree names a firmware version that fixes it. The argocd-mcp flaw scored 10.0 on Saturday had a public GitHub advisory, and a fix, eighteen days before any CVE was attached to it. libuser’s only modern score says the bug cannot touch confidentiality or integrity, and NVD has published no primary v3 score of its own to arbitrate. And Anthropic’s warning to Claude users exists only as an email, with nothing on the newsroom or the status page.

    Order of business after cPanel. WPMU DEV Dashboard’s second unauthenticated admin bypass this month, CVSS 9.8, fixed in version 5.0.2 on August 24 and hitting exactly the Hub-connected sites the first one missed. Then MCP servers: VulnCheck published thirteen CVEs against thirteen separate projects inside a thirteen-second window on August 27, and the recurring defect — bind to every interface, accept sessions without credentials — is the one that earned argocd-mcp its 10.0. Then the two KEV additions that share a September 9, 2026 federal deadline, libuser and AjaxPro; ten days out rather than this week, and in both cases what an agency has to work around is the record, not the code. Unitree G1 operators have no patch to apply and should treat network and radio range as the only control they have.

    Four items moved without handing anyone a task, though one is worth an hour on your endpoints. Anthropic says commodity infostealers — Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, Atomic Stealer on macOS — are lifting Claude sessions off users’ machines, which makes it a workstation problem rather than a vendor one. An extortion group calling itself FulcrumSec put 86 GB, a sample, and a claimed access path behind the Manchester Airports breach. Socket found nineteen wallet-draining Chrome and Edge extensions, five of them bought from the developers who built them. And at Boston Scientific, every patient implanted since August 25 is storing data instead of sending it.

    Still open. CVE-2026-65643 still has no record, and nobody has said which CNA holds it. MAG’s statement, dated August 27 and not updated since, lists four field types; FulcrumSec’s sample shows itineraries and payment amounts, which are not among them. Anthropic has neither confirmed nor disputed the email, and nobody outside the company knows how many accounts received it. No one has named fixed firmware for the Unitree G1. Boston Scientific says the timeline for a full restoration is not yet known. And the September 9 deadline falls a week from Wednesday.