LodeHQSubscribe →

Critical RCEs and DoS: Everest, Redis, HTTP/2

Infosec · 2026-06-05

Vulnerabilities & Exploits
Critical Everest Forms Pro WordPress RCE (CVE‑2026‑3300) Actively Exploited, Patch Now1 MIN

A critical RCE flaw (CVE‑2026‑3300, CVSS 9.8) in the Everest Forms Pro WordPress plugin is being actively exploited, allowing unauthenticated attackers to run arbitrary PHP, create admin accounts, and install webshells. The bug affects all versions ≤1.9.12 and has generated over 29k blocked attempts; users must update to 1.9.13 immediately.

Anthropic expands Project Glasswing to 150 critical‑infrastructure firms5 MIN

Anthropic announced Project Glasswing will now give Claude Mythos Preview access to roughly 150 new organizations across 15+ countries, targeting sectors like power, water, healthcare, and communications. The expansion aims to uncover high‑severity software flaws in critical‑infrastructure codebases, protecting potentially hundreds of millions of users.

Non‑Canonical AD ACL Order Can Render Deny ACEs Ineffective9 MIN

Active Directory evaluates ACL entries sequentially and stops once all required rights are granted. A non‑canonical ACL ordering can let an Allow ACE fire before a Deny ACE, causing the deny to never be evaluated and creating a silent permission bypass.

Google Gemini Voice Assistant Vulnerable to Messaging‑App Notification Hijacks15 MIN

SafeBreach researchers uncovered a new indirect prompt‑injection flaw that lets attackers embed hidden commands in WhatsApp, Slack, SMS or other notifications. When Google Gemini reads these poisoned messages, it silently executes malicious actions like controlling smart‑home devices or spoofing trusted messages. Google has issued a content‑classifier update to mitigate the issue.

Codex Reveals Critical HTTP/2 DoS Bomb Across Major Web Servers8 MIN

OpenAI's Codex uncovered a remote denial‑of‑service exploit, HTTP/2 Bomb, that leverages HPACK compression and flow‑control stalls to drain memory on default configurations of nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. A single 100 Mbps host can incapacitate a vulnerable server within seconds, exposing a critical, unpatched web‑server weakness.

Autonomous AI uncovers two‑year‑old RCE bug in Redis8 MIN

An autonomous AI tool identified CVE-2026-23479, a two‑year‑old use‑after‑free bug in Redis's blocking‑client code that lets authenticated users run arbitrary OS commands. Redis released patches in May 2026 across several major versions to close the flaw.

Threats & Malware
AI Worm Prototype Shows Hackers Can Exploit Any Online Device with Small Models7 MIN

University of Toronto researchers demonstrated an AI‑driven worm that can hijack any internet‑connected device using freely available small models. The proof‑of‑concept shows hackers could launch adaptive, low‑cost attacks without large‑scale AI resources, prompting urgent calls for new defenses.

China-linked TA4922 uses AI‑assisted malware to expand globally24 MIN

Proofpoint reports that the Chinese‑speaking cybercrime group TA4922 has expanded from East Asia into Europe and Africa, deploying new malware families such as Atlas RAT, RomulusLoader, SilentRunLoader and ValleyRAT. Analysts say the rapid growth of its toolkit is driven by large‑language‑model assistance, accelerating development and evasion.

Malspam Uses Google DoubleClick to Slip DesckVB RAT Past Defenses2 MIN

Researchers uncovered a malspam campaign that leverages Google's DoubleClick tracking domain to hide its delivery chain and drop the .NET‑based DesckVB RAT. The lure redirects through DoubleClick before serving a malicious ZIP that installs a loader, evades security tools, and establishes persistent control via process hollowing.

ReliaQuest uncovers OP-512: New China-linked threat targeting IIS web servers3 MIN

ReliaQuest identified a new China‑linked threat cluster, OP‑512, that targets Microsoft IIS servers with a custom web‑shell framework. The group deploys three uniquely generated shells, using cryptographic controls and timestomping to evade detection, and aims at espionage of organizations aligned with Chinese intelligence priorities.

IronWorm malware hijacks 36 npm packages via Rust binaries1 MIN

Researchers discovered IronWorm, a Rust‑written infostealer that infected 36 npm packages, delivering binary payloads through post‑install scripts. The campaign stole environment variables, cloud credentials, and crypto wallets, but was mitigated after JFrog flagged the malicious packages, which had about 32 k monthly downloads.

PCPJack Compromises 230 Cloud Servers to Run Hidden SMTP Relay Network3 MIN

Security firm Hunt.io uncovered that the PCPJack group hijacked 230 AWS, Google Cloud, and Azure instances across three continents, converting them into covert SMTP proxy servers for spam relaying. The actors left open directories on a C2 server, exposing deployment scripts, binaries, and Sliver configurations used to manage the fleet.

Breaches & Industry News
WFP cyber‑attack exposes data of 600,000 Gaza households5 MIN

The World Food Programme confirmed a cyber‑attack that leaked personal data of about 600,000 Gaza households from its self‑registration app, exposing names, IDs, phone numbers and locations. The breach, the largest known humanitarian data leak, prompted WFP to shut down the platform and bolster security, while investigators seek the attackers.

Privacy, Policy & Governance
DoJ and tech giants freeze $3.8M, dismantle 1.4M scam accounts in Southeast Asia8 MIN

The DOJ’s Scam Center Strike Force partnered with tech firms and international law‑enforcement to disrupt over 1.4 million scam‑related accounts in Southeast Asia and freeze more than $3.8 million in illicit cryptocurrency. The operation, dubbed “Disruption Week,” marks a rare joint government‑private effort to curb cyber‑enabled fraud targeting Americans.

Get Infosec in your inbox, every issue.
Subscribe free
Privacy · Terms · About · Contact
© 2026 LodeHQ