{
    "generated_at": "2026-10-09T20:42:42+00:00",
    "count": 30,
    "articles": [
        {
            "id": 4759,
            "title": "AI Scramble Drives Cybersecurity M&A Boom",
            "url": "https://www.darkreading.com/cybersecurity-analytics/ai-scramble-cybersecurity-ma-boom",
            "author": "Robert Lemos",
            "summary": "Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What's different: Many of the buyers are not your typical cybersecurity firms.",
            "published_at": "2026-10-09 19:26:26",
            "discovered_at": "2026-10-09 20:00:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4758,
            "title": "Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention",
            "url": "https://securityaffairs.com/200695/uncategorized/germany-arrests-suspected-qilin-ransomware-leader-after-japan-detention.html",
            "author": "Pierluigi Paganini",
            "summary": "Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest. Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group, and Japan’s National Police Agency just put its own role in that arrest on the record. The […]",
            "published_at": "2026-10-09 18:45:43",
            "discovered_at": "2026-10-09 19:50:07",
            "updated_at": null,
            "priority_score": 15,
            "source": "Security Affairs",
            "source_group": "Other",
            "categories": [
                "Law Enforcement",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 4757,
            "title": "Japan confirms arrest of Russian Qilin operative, extradition to Germany",
            "url": "https://therecord.media/japan-germany-ransomware-arrest",
            "author": null,
            "summary": "Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.",
            "published_at": "2026-10-09 18:45:00",
            "discovered_at": "2026-10-09 19:05:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 402,
            "title": "CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-048-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 18:19:17",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-13762",
                "CVE-2026-13763"
            ]
        },
        {
            "id": 411,
            "title": "Issue with containerd CRI Plugin - CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-046-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 18:19:17",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-47262",
                "CVE-2026-50195",
                "CVE-2026-53488",
                "CVE-2026-53489",
                "CVE-2026-53492"
            ]
        },
        {
            "id": 454,
            "title": "CVE-2026-13769 – Insecure file permissions in AWS CLI",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-049-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 18:19:17",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-13769"
            ]
        },
        {
            "id": 455,
            "title": "CVE-2026-12957 and CVE-2026-12958 - Issues in Language Servers for AWS and Amazon Q Developer Plugins",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-047-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 18:19:17",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-12957",
                "CVE-2026-12958"
            ]
        },
        {
            "id": 476,
            "title": "CVE-2026-13760 - OS Command Injection in NodejsFunction Docker Bundling in aws-cdk-lib",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-050-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 18:19:17",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-13760"
            ]
        },
        {
            "id": 4755,
            "title": "CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-133-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-133-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 11:00 AM PDT Description: AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. Impacted versions: - @aws-amplify/graphql-index-transformer >=2.2.0, =1.4.0,",
            "published_at": "2026-10-09 18:13:24",
            "discovered_at": "2026-10-09 18:30:11",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-108096"
            ]
        },
        {
            "id": 4756,
            "title": "FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack",
            "url": "https://thehackernews.com/2026/10/fbi-arrests-another-shinyhunters.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI's jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and no charges have been made public. The",
            "published_at": "2026-10-09 17:45:26",
            "discovered_at": "2026-10-09 19:00:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement"
            ],
            "cves": []
        },
        {
            "id": 4754,
            "title": "What We Missed: FBI Strikes Back at ShinyHunters",
            "url": "https://www.darkreading.com/identity-access-management-security/fbi-shinyhunters-claims-hack",
            "author": "Rob Wright, Alexander Culafi",
            "summary": "In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.",
            "published_at": "2026-10-09 17:21:00",
            "discovered_at": "2026-10-09 17:35:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement"
            ],
            "cves": []
        },
        {
            "id": 4753,
            "title": "Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto",
            "url": "https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/",
            "author": "Bill Toulas",
            "summary": "Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]",
            "published_at": "2026-10-09 17:17:23",
            "discovered_at": "2026-10-09 17:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Cloud Security",
                "Threat Actors",
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4752,
            "title": "FBI arrests another suspected ShinyHunters hacker after agency breach",
            "url": "https://www.bleepingcomputer.com/news/security/fbi-arrests-another-suspected-shinyhunters-hacker-after-agency-breach/",
            "author": "Lawrence Abrams",
            "summary": "The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. [...]",
            "published_at": "2026-10-09 17:02:29",
            "discovered_at": "2026-10-09 17:15:01",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement"
            ],
            "cves": []
        },
        {
            "id": 4750,
            "title": "P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands",
            "url": "https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html",
            "author": "info@thehackernews.com (The Hacker News)",
            "summary": "Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. \"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure,\" iVerify said in a new report published Thursday. The name",
            "published_at": "2026-10-09 16:29:55",
            "discovered_at": "2026-10-09 16:50:10",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Hacker News",
            "source_group": "Security Journalism",
            "categories": [
                "Apple",
                "Security Research"
            ],
            "cves": []
        },
        {
            "id": 4751,
            "title": "Security Threats Don't Stop at the Office: Why Executives' Families Need Training, Too",
            "url": "https://www.darkreading.com/cyber-risk/security-threats-don-t-stop-at-the-office-why-executives-families-need-training-too",
            "author": "Arielle Waldman",
            "summary": "Those closest to executives must match their security postures because the weakest link in a family can become the entry point for attacks.",
            "published_at": "2026-10-09 16:25:05",
            "discovered_at": "2026-10-09 16:50:12",
            "updated_at": "2026-10-09 17:45:03",
            "priority_score": 0,
            "source": "Dark Reading",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 426,
            "title": "CVE-2026-12043 - Heap double-free in AWS Common Runtime aws-c-http",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-043-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 16:14:05",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-12043"
            ]
        },
        {
            "id": 440,
            "title": "CVE-2026-10740 - Excessive memory allocation in s2n-quic",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-041-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 16:14:05",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-10740"
            ]
        },
        {
            "id": 465,
            "title": "CVE-2026-11931 - Insecure Permissions on Authentication Token Cache File in Kiro IDE",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-045-aws/",
            "author": "aws@amazon.com",
            "summary": null,
            "published_at": "2026-10-09 16:14:05",
            "discovered_at": "2026-08-15 18:58:22",
            "updated_at": "2026-10-09 18:30:11",
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-11931"
            ]
        },
        {
            "id": 4747,
            "title": "Hundreds of thousands impacted by data breach at biosensor firm iRhythm",
            "url": "https://therecord.media/irhythm-data-breach-reports",
            "author": null,
            "summary": "A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer.",
            "published_at": "2026-10-09 16:06:00",
            "discovered_at": "2026-10-09 16:20:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [
                "Apple",
                "Data Breaches"
            ],
            "cves": []
        },
        {
            "id": 4748,
            "title": "Leader of vast money mule operation that laundered cybercriminal proceeds pleads guilty",
            "url": "https://therecord.media/leader-of-money-mule-operation-for-cybercriminals-pleads-guilty",
            "author": null,
            "summary": "Oleg Korniev, a 42-year-old dual citizen of Ukraine and Russia, was a principal of Your Mule Cashout, or “YMCO,” which from 2007 until 2014 set up a sophisticated network of mules in the U.S. and Europe.",
            "published_at": "2026-10-09 16:06:00",
            "discovered_at": "2026-10-09 16:20:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4749,
            "title": "CVE-2026-107783 - Insertion of sensitive information into log file in AWS Tools for PowerShell",
            "url": "https://aws.amazon.com/security/security-bulletins/rss/2026-132-aws/",
            "author": "aws@amazon.com",
            "summary": "Bulletin ID: 2026-132-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 08:30 AM PDT Description: AWS Tools for PowerShell V5 lets developers and administrators manage their AWS services from the PowerShell scripting environment. We identified CVE-2026-107783, where insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts. Impacted versions:",
            "published_at": "2026-10-09 15:56:44",
            "discovered_at": "2026-10-09 16:30:13",
            "updated_at": null,
            "priority_score": 5,
            "source": "AWS Security Bulletins",
            "source_group": "Vendor Research",
            "categories": [
                "Cloud Security",
                "Vulnerabilities"
            ],
            "cves": [
                "CVE-2026-107783"
            ]
        },
        {
            "id": 4746,
            "title": "FBI touts another ShinyHunters arrest in response to data breach",
            "url": "https://therecord.media/shinyhunters-arrest-fbi-data-breach-investigation",
            "author": null,
            "summary": "“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate,\" FBI Director Kash Patel said.",
            "published_at": "2026-10-09 15:41:00",
            "discovered_at": "2026-10-09 15:50:09",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [
                "Data Breaches",
                "Law Enforcement"
            ],
            "cves": []
        },
        {
            "id": 4745,
            "title": "Germany arrests alleged core Qilin ransomware member after extradition",
            "url": "https://www.bleepingcomputer.com/news/security/germany-arrests-alleged-core-qilin-ransomware-member-after-extradition/",
            "author": "Bill Toulas",
            "summary": "Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. [...]",
            "published_at": "2026-10-09 15:38:56",
            "discovered_at": "2026-10-09 15:45:03",
            "updated_at": null,
            "priority_score": 15,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "Law Enforcement",
                "Ransomware"
            ],
            "cves": []
        },
        {
            "id": 4740,
            "title": "Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion",
            "url": "https://www.tenable.com/security/research/tra-2026-65",
            "author": "Joshua Martinelle",
            "summary": "Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion Note: Another researcher identified the same vulnerability during the disclosure process with the Nous Researcher team.In Hermes Agent, the public GET /auth/native/authorize flow validates the redirect_uri with Python's urllib.parse.urlparse, then hands the raw, unnormalized value back to the browser after authentication.The two parsers treat backslashes differently. Python's parser and the browser's WHATWG parser therefore disagree on the URL's actual host. The server can accept a URL it classifies as loopback (127.0.0.1) while the browser navigates to a different, attacker-controlled origin. The attacker also chooses the PKCE challenge, so they can exchange the leaked authorization code for the victim account's tokens. This results in a full session takeover.The _validate_loopback_redirect_uri function is explicitly meant to allow only literal loopback addresses, since a remote origin would otherwise receive a live authorization code. However, it parses raw, checks parsed.hostname, and then returns raw unchanged. register_pending stores this raw string. After a valid sign-in, auth_password_login appends code and state to it, and the page script redirects with window.location.assign(data.next).The discrepancy reproduces with http://127.0.0.1:17777\\@127.0.0.1:27777/callback. urlparse reads 127.0.0.1:17777\\ as user information before the @ and reports the hostname as 127.0.0.1, with port 27777. The browser instead treats \\ as a path separator in an HTTP URL. It opens http://127.0.0.1:17777/@127.0.0.1:27777/callback, so the request goes to the origin on port 17777. In testing, the browser reached this second origin carrying the code and state parameters. A remote host placed before the backslash would receive the authorization code in the same way. Joshua Martinelle Fri, 10/09/2026 - 11:15",
            "published_at": "2026-10-09 15:15:46",
            "discovered_at": "2026-10-09 15:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Tenable Research Advisories",
            "source_group": "Vendor Research",
            "categories": [
                "Microsoft",
                "Vulnerabilities"
            ],
            "cves": []
        },
        {
            "id": 4741,
            "title": "Hermes Agent - Pre-Authentication Disk Consumption",
            "url": "https://www.tenable.com/security/research/tra-2026-64",
            "author": "Joshua Martinelle",
            "summary": "Hermes Agent - Pre-Authentication Disk Consumption In Hermes Agent the public POST /auth/password-login route copies the client-supplied provider value, with no size limit, into the audit log before rejecting an unknown provider.Because the middleware treats this route as public, an unauthenticated client with no account can cause arbitrarily large, attacker-controlled data to be written persistently to the server's disk.In hermes_cli/dashboard_auth/routes.py, _PasswordLoginBody.provider is declared as a str with no maximum length. The auth_password_login handler applies the attempt limit, fails to find the provider, and then passes body.provider to audit_log before returning 404. In hermes_cli/dashboard_auth/audit.py, the logger filters certain sensitive field names but never bounds value size. It serializes the full object as JSON and appends it to dashboard-auth.log.Testing confirmed the behavior. A request with a nonexistent provider and empty credentials returned the expected 404. Raising provider to about 4.19 million characters still returned 404, but the free disk space reported by /api/status dropped from 923 MB to 919 MB, and the value stayed in the log after the request ended.A single request with a total JSON size of exactly 100 MiB (104,857,600 bytes) also returned 404 and reduced free space from 919 MB to 819 MB. The persistent write therefore scales directly with the client-controlled payload size. Repeated requests could exhaust disk space and degrade the service's availability. Joshua Martinelle Fri, 10/09/2026 - 11:13",
            "published_at": "2026-10-09 15:13:14",
            "discovered_at": "2026-10-09 15:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Tenable Research Advisories",
            "source_group": "Vendor Research",
            "categories": [],
            "cves": []
        },
        {
            "id": 4742,
            "title": "Hermes Agent - Pre-Authentication Memory Exhaustion",
            "url": "https://www.tenable.com/security/research/tra-2026-63",
            "author": "Joshua Martinelle",
            "summary": "Hermes Agent - Pre-Authentication Memory Exhaustion In Hermes Agent the dashboard's public authentication routes (/auth/native/token, /auth/native/refresh, and /auth/password-login) read and parse the entire JSON request body before any authentication check, with no application-level size limit.The gated_auth_middleware in hermes_cli/dashboard_auth/middleware.py lets these paths through via _GATE_PUBLIC_PREFIXES before checking for a session. The handlers in routes.py rely on Pydantic models whose string fields have no size bound, and the pinned web stack (FastAPI 0.133.1, Starlette 1.3.1, Uvicorn 0.41.0) buffers the full body before the handler runs. Uvicorn's configuration in start_server (hermes_cli/web_server.py) caps WebSocket message size but sets no HTTP body limit.As a result, an unauthenticated client can send oversized payloads that are fully loaded into memory before being rejected. Testing confirmed that a ~1 MB body to /auth/native/refresh returned 401 instead of 413, and that chunked uploads of 32 MiB and 128 MiB, sent without Content-Length, still reached /auth/password-login's application-level rejection (404). Keeping eight concurrent 32 MiB uploads open for fifteen seconds raised the dashboard process's memory from 721 MiB to 1.08 GiB, while /api/status continued to report overall=ok.Although every request is ultimately rejected, an anonymous attacker can drive substantial memory consumption by holding several large uploads in progress, which creates a denial-of-service risk. Joshua Martinelle Fri, 10/09/2026 - 11:07",
            "published_at": "2026-10-09 15:07:30",
            "discovered_at": "2026-10-09 15:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Tenable Research Advisories",
            "source_group": "Vendor Research",
            "categories": [],
            "cves": []
        },
        {
            "id": 4743,
            "title": "WordPress - Post Author Second Order SQLi",
            "url": "https://www.tenable.com/security/research/tra-2026-62",
            "author": "Joshua Martinelle",
            "summary": "WordPress - Post Author Second Order SQLi A regression was introduced in version 4.0.0 of WP Post Author, the multi-authors module stores the co-author list in the wpma_author post meta and later interpolates each stored value directly into a SQL query. Neither end of that path is safe.On write, awpa_ma_save_metabox() takes $_POST['wpma_metabox_authors_list'], splits it on commas, and stores each element verbatim. The handler computes a sanitized copy and then stores the raw value instead:// includes/multi-authors/wpa-multi-authors.php:113 foreach ($data as $key => $user_id) { $userid = sanitize_text_field($user_id); // computed and never used add_post_meta($post_id, 'wpma_author', $user_id); // raw value storedThe handler has no nonce verification, no current_user_can('edit_post', $post_id) check, and no autosave guard, even though the metabox still emits a nonce field at line 91 that nothing ever validates.On read, awpa_ma_get_guest_author() concatenates the stored value into the query with no prepare() and no cast:// includes/multi-authors/wpa-multi-authors.php:299 public function awpa_ma_get_guest_author($guest_id) { global $wpdb; $table_name = $wpdb->prefix . \"wpa_guest_authors\"; $query = \"SELECT id, user_email, display_name, user_nicename FROM $table_name where id = $guest_id\"; $guest_author = $wpdb->get_results($query, OBJECT); return $guest_author ? $guest_author[0] : false; }Three of the returned columns are echoed back into the page as data-nice_name, data-user_email and data-display_name attributes, so a UNION SELECT returns the attacker's chosen data directly in the HTML response. Joshua Martinelle Fri, 10/09/2026 - 10:52",
            "published_at": "2026-10-09 14:52:51",
            "discovered_at": "2026-10-09 15:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Tenable Research Advisories",
            "source_group": "Vendor Research",
            "categories": [
                "Law Enforcement"
            ],
            "cves": []
        },
        {
            "id": 4744,
            "title": "WordPress - Post Author Authenticated SQLi",
            "url": "https://www.tenable.com/security/research/tra-2026-61",
            "author": "Joshua Martinelle",
            "summary": "WordPress - Post Author Authenticated SQLi Two REST handlers build SQL queries by concatenating client-supplied request parameters straight into the query string. There is no $wpdb->prepare(), no esc_like(), and no whitelisting. The only processing applied is sanitize_text_field(), which trims whitespace and strips tags and control characters. It does not escape quotes and offers no protection against SQL injection.// includes/api-request/free/multi-authors/class-multiauthors.php — awpa_list_guest_authors() $orderby = sanitize_text_field($request['order_by']); // not an SQL defense $order = sanitize_text_field($request['order']); $search_term = sanitize_text_field($request['search']); ... $query = \"SELECT * FROM $table_name WHERE 1=1 AND (user_email LIKE '%$search_term%' OR display_name LIKE '%$search_term%' OR ...) ORDER BY $orderby $order LIMIT $offset, $authors_per_page;\"; $posts = $wpdb->get_results($query, OBJECT); // no prepare()Every parameter is an injection point. search breaks out of the LIKE '%...%' string literal order_by and order inject into the identifier/keyword context after ORDER BY.per_page and page inject into the numeric LIMIT clause. The membership-listing handler in class-registered-users.php repeats the same pattern against a different table.This was reproduced end-to-end against WP Post Author 3.10.0. A boolean oracle and a time-based oracle both fire, and the administrator account's password hash was extracted blind through the endpoint. Joshua Martinelle Fri, 10/09/2026 - 10:40",
            "published_at": "2026-10-09 14:40:09",
            "discovered_at": "2026-10-09 15:25:02",
            "updated_at": null,
            "priority_score": 0,
            "source": "Tenable Research Advisories",
            "source_group": "Vendor Research",
            "categories": [],
            "cves": []
        },
        {
            "id": 4739,
            "title": "Belarusian hacktivists admit to 2023 breach of Russian state healthcare network",
            "url": "https://therecord.media/belarusian-cyber-partisans-claim-2023-russia-healthcare-hack",
            "author": null,
            "summary": "The Belarusian Cyber Partisans concurred with Russian research that they indeed spent months inside the network for the Moscow Department of Health.",
            "published_at": "2026-10-09 14:40:00",
            "discovered_at": "2026-10-09 14:50:09",
            "updated_at": null,
            "priority_score": 0,
            "source": "The Record",
            "source_group": "Security Journalism",
            "categories": [],
            "cves": []
        },
        {
            "id": 4733,
            "title": "How to keep AI agents within their permissions",
            "url": "https://www.bleepingcomputer.com/news/security/how-to-keep-ai-agents-within-their-permissions/",
            "author": "Sponsored by Token Security",
            "summary": "AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce agent-specific policies without sacrificing autonomy. [...]",
            "published_at": "2026-10-09 14:01:11",
            "discovered_at": "2026-10-09 14:15:03",
            "updated_at": null,
            "priority_score": 0,
            "source": "BleepingComputer",
            "source_group": "Security Journalism",
            "categories": [
                "AI Security"
            ],
            "cves": []
        }
    ]
}