<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Beazley Security Labs Advisories</title>
  <link href="https://labs.beazley.security/advisories" rel="alternate"/>
  <id>https://labs.beazley.security/advisories</id>
  <updated>Fri, 10 Jul 2026 05:00:00 GMT</updated>

  <entry><title>Emerging Threat: Progress Customers Instructed to Shut Down Storage Zone Controllers</title><link href="https://labs.beazley.security/advisories/BSL-A1188" rel="alternate"/><updated>2026-07-10T05:00:00.000Z</updated><published>2026-07-10T05:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1188</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>Beazley Security has been made aware of an emerging threat targeting Progress Software ShareFile. Progress Software issued an emergency communication via email to customers, urging immediate server shutdown citing a “<b>credible external security threat targeting Progress Software’s ShareFile Storage Zone Controllers.</b>” Progress Software have also reportedly temporarily disabled Storage Zone Controller (SZC) based accounts while the investigation is underway.</p><p>At the time of writing, Progress Software have not released any technical details about the threat, or whether a zero-day vulnerability is involved. This warning follows the public April 2026 <a href="https://labs.beazley.security/advisories/BSL-A1165">disclosure</a> of two critical vulnerabilities tracked as CVE-2026-2699 and CVE-2026-2701 which when chained allowed unauthenticated remote code execution on exposed SZC servers.</p><p>Progress Software further warns “You must <b>manually shut down the server hosting your Storage Zone Controllers</b>. This is a critical additional step to ensure the safety of your data,” indicating that cloud-side management capabilities or mitigation options are not currently available to protect on-premises SZC deployments.</p><p>Given the sensitive nature of data hosted on these systems and confirmed credible threat from Progress Software, Beazley Security recommends following vendor guidance to disable controllers and reduce risk. This is an evolving situation, and Beazley Security will update this advisory as additional details become available.</p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><p>The notification from Progress indicates that only the ShareFile Storage Zone Controller product is affected. It appears to affect all versions, as Progress have temporarily disabled all access to the system and instructed clients to shut down the associated on-premises file servers integrated with the ShareFile system.</p></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>Progress stated that as a precaution, they have temporarily disabled access to ShareFile accounts using SZCs. However, Progress is instructing customers to <b>manually shut down Windows servers hosting SZCs as a required additional mitigation step</b>.</p><p>There have been no additional mitigations provided by the vendor at the time of writing.</p></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>Progress Software have not confirmed whether this threat is related to a specific vulnerability or a zero-day, and no patches have been publicly released at this time.</p></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>The ShareFile Storage Zone Controller is an application that allows a client to host files on their own infrastructure but share them with the Progress ShareFile interface.</p><p>The email sent to clients indicates they believe the controllers are being targeted in a cyber attack, and that they have disabled ShareFile account access to these controllers in response. Because the system involves file servers hosted by clients, Progress has instructed clients to shut down their associated on-premises file servers as well.</p><p>The nature of the underlying weakness or emerging threat has not been publicly disclosed by Progress ShareFile at the time of writing. However, based on the messaging and previous vulnerability <a href="https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/">research</a>, the attack surface of concern likely centers on on-premises, internet facing SZC deployments.</p><p>This is an evolving situation, and Beazley Security will update this advisory as additional details become available.</p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.</p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.</p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach">contact our Incident Response team</a>.</p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><p><a href="https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/">https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/</a></p><p><a href="https://status.sharefile.com/">https://status.sharefile.com/</a></p><p><a href="https://support.sharefile.com/s/question/0D5QP00002NfwDD0AZ/is-anyone-else-experiencing-sharefile-issues-we-cant-login-and-chat-bot-isnt-working-on-the-site">https://support.sharefile.com/s/question/0D5QP00002NfwDD0AZ/is-anyone-else-experiencing-sharefile-issues-we-cant-login-and-chat-bot-isnt-working-on-the-site</a></p><p><a href="https://labs.beazley.security/advisories/BSL-A1165">https://labs.beazley.security/advisories/BSL-A1165</a></p><p><a href="https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/">https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/</a></p></div>]]></content><summary type="html">Progress Software issued an emergency communication via email to customers, urging immediate server shutdown citing a “credible external security threat targeting Progress Software’s ShareFile Storage Zone Controllers.” </summary></entry><entry><title>Vulnerabilities Found in Page Builder CK (CVE-2026-48908) and SP Page Builder (CVE-2026-56290)</title><link href="https://labs.beazley.security/advisories/BSL-A1187" rel="alternate"/><updated>2026-07-08T04:00:00.000Z</updated><published>2026-07-08T04:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1187</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On July 7th, 2026, CISA added two Joomla extension vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation in the wild. Tracked as CVE-2026-48908 and CVE-2026-56290, both vulnerabilities have CVSS base scores of 10, and both exploit unauthenticated arbitrary file uploads that can result in remote code execution (RCE) on affected Joomla servers.</p><p>Page Builder CK (CVE-2026-48908) and SP Page Builder (CVE-2026-56290) are both drag-and-drop page-building extensions for Joomla, a widely deployed open-source content management system that underpins a large number of small business, nonprofit, and community websites. Because the vulnerable upload functionality requires no authentication and writes directly to a location where they can be executed by the web server, a single crafted request is enough to compromise a site. Attackers exploiting these flaws have been observed planting hidden administrator accounts and deploying PHP file manager backdoors on compromised Joomla sites, giving them durable, high-privilege access that can persist well after the initial compromise is discovered. Both vendors have released fixed versions.</p><p>Given active exploitation of both vulnerabilities has been confirmed and listed within CISA’s KEV catalog, Beazley Security recommends affected organizations apply available fixes immediately and conduct a thorough review for any signs of compromise.</p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><table><tbody><tr><th><p>Product</p></th><th><p>Affected Versions</p></th></tr><tr><td><p>JoomShaper SP Page Builder (Joomla extension)</p></td><td><p>1.0.0 through 6.6.1</p></td></tr><tr><td><p>Page Builder CK (Joomla extension, Joomlack)</p></td><td><p>1.0 through 3.5.10</p></td></tr></tbody></table></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>Where immediate patching isn't possible, the vulnerable upload handlers in both extensions are reachable without authentication, so the only reliable interim step is to remove the exposure:</p><p>Temporarily disable or uninstall the vulnerable extension (Page Builder CK and/or SP Page Builder) until the update can be applied.</p><p>If the extension cannot be disabled, block public access to its component endpoints (index.php?option=com_pagebuilderck and index.php?option=com_sppagebuilder) at the web server or WAF layer.</p></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>Joomlack released Page Builder CK 3.6.0 on June 27, 2026, fixing CVE-2026-56290; the update is available through the Joomlack forum and the GitHub security advisory.</p><p>JoomShaper released SP Page Builder 6.6.2, fixing CVE-2026-48908, documented in its GitHub security advisory. Site owners should confirm they are running these versions or later.</p></div><div class="rtf"><h3 class="rtf-title">Indicators of Compromise (IoCs)</h3><p>For CVE-2026-56290, researchers observed attackers uploading web shells within hours of the patch being released, using the extension's font-upload handler option=com_pagebuilderck&amp;task=fonts.save to write PHP files into media/com_pagebuilderck/gfonts/. Site owners should check that directory, and Joomla's media and upload folders generally, for unexpected .php files and review web server access logs for unsolicited POST requests to index.php containing option=com_pagebuilderck from external hosts.</p><p>For CVE-2026-48908, attackers have used the plugin's custom icon upload feature to write a PHP file manager backdoor into the web root and create hidden administrator accounts. Site owners should review the Joomla Users list (Users > Manage in the admin backend) for administrator accounts they did not create and check upload and media directories for unrecognized PHP files.</p></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>SP Page Builder ships with a custom icon upload feature that is reachable without authentication. The handler behind it does not properly restrict the types of files it accepts before writing the upload into the site’s web root, pairing an unrestricted-upload weakness with the extension’s broader access control weakness. Because the web server will execute a PHP file wherever it sits under the web root, an attacker can disguise a PHP web shell as an icon upload and then request it directly to run arbitrary code with the privileges of the web server process. This creates a single-request path to RCE that requires no credentials and no user interaction, resulting in fast, automated exploitation now that public details are available.</p><p>Page Builder CK is exploited through a similar mechanism. It includes a feature that lets site administrators fetch and cache Google Fonts locally, handled by the extension’s fonts.save task. The handler accepts a remote URL and saves the fetched content into a web-accessible folder under the site’s media directory. The vulnerability combines two flaws: the endpoint fails to properly verify that the request comes from an authenticated, privileged Joomla admin, and it fails to validate that the fetched content is actually a font file before writing it to disk. An unauthenticated attacker can point the handler to PHP code, causing the extension to save it into the public media folder, where it can then be executed directly by requesting its URL.</p><p>A public proof-of-concept is available and automates this end-to-end: it retrieves a CSRF token from the site’s homepage, submits the crafted upload request, and confirms code execution by requesting the resulting shell. Given the low complexity of the exploit and the absence of any authentication requirement, Joomla sites running vulnerable versions of this widely used extension remain an attractive and easy target for opportunistic, automated attacks.</p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.</p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.</p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach">contact our Incident Response team</a>.</p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-56290">https://nvd.nist.gov/vuln/detail/CVE-2026-56290</a></p></li><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48908">https://nvd.nist.gov/vuln/detail/CVE-2026-48908</a></p></li><li><p><a href="https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3">https://forum.joomlack.fr/index.php/page-builder-ck/21627-nouvelle-version-de-pbck-et-joomla-3</a></p></li><li><p><a href="https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/">https://mysites.guru/blog/pagebuilderck-unauthenticated-file-upload-rce/</a></p></li><li><p><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-56290">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-56290</a></p></li><li><p><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-48908">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-48908</a></p></li></ul></div>]]></content><summary type="html">Critical vulnerabilities have been found in two Joomla plugins, leading to maximum severity CVE-2026-56290 and CVE-2026-48908, both already added to CISA's KEV catalog.</summary></entry><entry><title>Critical Vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access (CVE-2026-40138, CVE-2026-40139) </title><link href="https://labs.beazley.security/advisories/BSL-A1186" rel="alternate"/><updated>2026-07-07T15:51:00.000Z</updated><published>2026-07-07T15:51:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1186</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On July 6th, 2026, BeyondTrust disclosed two critical authentication bypass vulnerabilities in its Remote Support and Privileged Remote Access products. Tracked as CVE-2026-40138 and CVE-2026-40139, the flaws let a network-positioned, unauthenticated attacker defeat access controls and reach accounts with elevated privileges, provided a specific authentication configuration is enabled. The two are independent flaws in the same authentication subsystem that share a disclosure rather than chaining together, and BeyondTrust has released fixes for both.</p><p>Remote Support and Privileged Remote Access are appliances organizations use to manage remote sessions and control privileged access into sensitive internal environments. The exploitation of this vulnerability grants them an account with elevated privileges, making a pre-authentication bypass on an internet-reachable management appliance a high value target.  This access can be used to pivot into the systems the appliance was built to protect. BeyondTrust identified both issues internally and shipped patches before any public disclosure.</p><p>Neither vulnerability has been observed under active exploitation, and no public proof-of-concept code exists at the time of writing. However, pre-authentication bypasses in internet-facing management appliances are routinely weaponized soon after disclosure. Beazley Security recommends affected organizations apply available fixes as soon as possible.</p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><table><tbody><tr><th><p><b>Product</b></p></th><th><p><b>Affected Versions</b></p></th></tr><tr><td><p>BeyondTrust Privileged Remote Access</p></td><td><p>25.3.2 and earlier</p></td></tr><tr><td><p>BeyondTrust Remote Support</p></td><td><p>25.3.2 and earlier</p></td></tr></tbody></table></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>A single upgrade remediates both vulnerabilities. Upgrade Remote Support and Privileged Remote Access beyond the affected versions above. Self-hosted customers should apply the April 2026 Security Rollup patch for their version, or upgrade to a fixed release. Cloud-hosted instances were updated automatically by BeyondTrust and require no customer action.</p><p>Until the update can be applied, self-hosted operators can reduce exposure by limiting access to internet-facing appliances so that they are reachable only from trusted and administrative networks.</p></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>BeyondTrust has released fixes for both vulnerabilities. Cloud-hosted customers were patched automatically on April 21st, 2026. Self-hosted customers must act manually by applying the April 2026 Security Rollup or upgrading to version 25.3.3, available through BeyondTrust's security advisory.</p></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>Both vulnerabilities are improper authentication issues (CWE-287) in the authentication subsystem shared by Remote Support and Privileged Remote Access tools. CVE-2026-40138 stems from improper validation of authentication data, while CVE-2026-40139 stems from improper processing of authentication requests. In each case, the appliance mishandles a malformed authentication request over the network. This can grant access without valid credentials to accounts with elevated privileges. Both require a specific authentication configuration to be enabled before they can be triggered, which narrows the exposed devices to the ones running that configuration. Unfortunately, the specific configuration details have not been disclosed from BeyondTrust in their advisory at the time of publication.</p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.</p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.</p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach">contact our Incident Response team</a>.</p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://www.beyondtrust.com/trust-center/security-advisories/bt26-03">https://www.beyondtrust.com/trust-center/security-advisories/bt26-03</a></p></li><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40138">https://nvd.nist.gov/vuln/detail/CVE-2026-40138</a></p></li><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40139">https://nvd.nist.gov/vuln/detail/CVE-2026-40139</a></p></li></ul></div>]]></content><summary type="html">Two pre-authentication flaws CVE-2026-40138 and CVE-2026-40139 disclosed in BeyondTrust Remote Support and Privileged Remote Access let attackers bypass authentication and reach the appliance, including privileged accounts, when a specific authentication configuration is enabled.</summary></entry><entry><title>Multiple High-Severity Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-8451)</title><link href="https://labs.beazley.security/advisories/BSL-A1185" rel="alternate"/><updated>2026-06-30T07:00:00.000Z</updated><published>2026-06-30T07:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1185</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On June 30th, 2026, Citrix disclosed a high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products. Tracked as CVE-2026-8451, the flaw lets an unauthenticated, remote attacker leak fragments of appliance memory from a NetScaler configured as a SAML identity provider, placing it in the same class of memory disclosure flaws collectively known as &quot;CitrixBleed.&quot; </p><p>NetScaler ADC and NetScaler Gateway are internet facing application delivery and VPN appliances that provide load balancing, authentication, and remote access services. Past “CitrixBleed” vulnerabilities have been exploited to leak sensitive data such as account details and credentials that could provide an attacker initial access to affected organizations.</p><p>Although active exploitation has not been reported at the time of writing, vulnerabilities in the “CitrixBleed” category have historically been weaponized following disclosure. Beazley Security recommends affected organizations apply available fixes as soon as possible. </p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><table><tbody><tr><td><p>Product</p></td><td><p>Affected Versions</p></td></tr><tr><td><p>NetScaler ADC and NetScaler Gateway 14.1</p></td><td><p>before 14.1-72.61</p></td></tr><tr><td><p>NetScaler ADC and NetScaler Gateway 13.1</p></td><td><p>before 13.1-63.18</p></td></tr><tr><td><p>NetScaler ADC FIPS 14.1</p></td><td><p>before 14.1-72.61 FIPS</p></td></tr><tr><td><p>NetScaler ADC FIPS and NDcPP 13.1</p></td><td><p>before 13.1-37.272</p></td></tr></tbody></table></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>Given rapid weaponization of previous “CitrixBleed” vulnerabilities and potential for memory disclosure to expose sensitive information, Beazley Security strongly recommends patches be applied. </p><p>If organizations are unable to apply available fixes, the following steps may help to temporarily reduce risk:</p><ul><li><p>Temporarily disable SAML IdP functionality until updates can be applied.</p></li><li><p>Limit access of internet-facing NetScaler devices to trusted and administrative networks where possible.</p></li></ul></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>Cloud-managed NetScaler services have already received updates from the vendor. Citrix has released fixes for customer-managed devices, and additional information can be found in the official Citrix <a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604">advisory</a>. </p></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>CVE-2026-8451 is a pre-authentication memory overread in the SAML identity provider functionality of NetScaler, reachable only when the appliance is configured as a SAML IdP. </p><p>SAML authentication starts with a client-supplied base64-encoded XML document to /saml/login, and NetScaler parses that document with a custom XML parser rather than a vetted library. This custom attribute parser has a bug where for unquoted attribute values, it stops reading data only when it reads a null byte, a closing “greater than” symbol, or a matching quote, and it does not treat whitespace or newlines as terminators. </p><p>Watchtowr researchers <a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/">found</a> that the AssertionConsumerServiceURL attribute could be left blank, unterminated, and reordered in the input XML to cause a significant memory overread. More importantly, the exposed memory is sent back to the attacker in the response traffic. Data leaked via this exploit will be returned in the appliance's NSC_TASS response cookie. </p><p>This CVE is also somewhat limited compared with previous similar “Citrixbleed” attacks, in that the CVE-2026-8451 overread stops when it finds a control character such as a null byte, resulting in only a few bytes returned per request rather than the kilobytes seen in earlier “CitrixBleed” bugs. Even so, the leaked data can include process pointers, which could be chained with other vulnerabilities to achieve RCE. Additionally, a minimal malformed request to the same endpoint also reliably crashes the appliance, making denial of service trivial. Proof of concept details have been published by WatchTowr.</p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.</p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.</p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach">contact our Incident Response team.</a></p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8451">https://nvd.nist.gov/vuln/detail/CVE-2026-8451</a></p></li><li><p><a href="https://github.com/advisories/GHSA-6659-v5cc-894x">https://github.com/advisories/GHSA-6659-v5cc-894x</a> </p></li><li><p><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604</a> </p></li><li><p><a href="https://www.cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-645">https://www.cyber.gc.ca/en/alerts-advisories/citrix-security-advisory-av26-645</a></p></li><li><p><a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/">https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/</a></p></li></ul></div>]]></content><summary type="html">On June 30th, 2026, Citrix disclosed a high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products. Tracked as CVE-2026-8451, the flaw lets an unauthenticated, remote attacker leak fragments of appliance memory from a NetScaler configured as a SAML identity provider, placing it in the same class of memory disclosure flaws collectively known as &quot;CitrixBleed.&quot; </summary></entry><entry><title>Critical Vulnerability in Ubiquiti Network Application Under Active Exploitation (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910)</title><link href="https://labs.beazley.security/advisories/BSL-A1184" rel="alternate"/><updated>2026-06-24T22:00:00.000Z</updated><published>2026-06-24T22:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1184</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On June 23<sup>rd</sup>, 2026 CISA added three critical vulnerabilities affecting Ubiquiti UniFI to its known exploited vulnerabilities (KEV) catalog following confirmed active exploitation in the wild. Reported activity includes a Mirai/Gaafgyt botnet campaign, making immediate patching and post-compromise investigation and remediation critical for all affected organizations. </p><p>On May 21, 2026, Ubiquiti published Security Advisory Bulletin 064 (SAB-064) for Ubiquiti UniFi OS servers which identified three vulnerabilities CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, each rated CVSS base score of 10.0. These vulnerabilities can be chained together to allow an attacker unauthenticated remote code execution with full root privileges. Ubiquti has released updates that address these vulnerabilities at the time of their initial publication. </p><p>Given these attacks grant root level privileges to an attacker with a single request, Beazley Security recommends organizations running vulnerable UniFi OS instances assume compromise, immediately patch to prevent future exploitation, pull existing OS configuration backups, and rebuild from a known-good image. </p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><table><tbody><tr><th><p><b>Product</b> </p></th><th><p><b>Affected Versions</b> </p></th><th><p><b>Fixed Versions</b> </p></th></tr><tr><td><p>UniFi OS Server </p></td><td><p>&lt;5.0.6 </p></td><td><p>5.0.8 </p></td></tr></tbody></table></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>Ubiquiti and Beazley Security advise updating any Network instances in your UniFi console. The exploit is possible wherever a UniFi OS web interface is accessible. The default interface listens on TCP 11443. Blocking external access to it can prevent initial access to the system. </p><p>
It’s advisable to not allow external network access to your UniFi Management console and rather leverage <a href="https://help.ui.com/hc/en-us/articles/20680072882967-UniFi-Remote-Management-via-Site-Manager"><u>Ubiquiti’s Remote Site Management</u></a> service. </p></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>Updating a Ubiquti UniFi Network Application is performed through the UniFi Portal within the Control Plane Settings. </p><ol><li><p>Click the settings cog in on the left-most pane. </p></li><li><p>Access the “Control Plane” settings. </p></li><li><p>Within the loaded pane, ensure you select “Updates” </p></li><li><p>Click the “Update to X.X.X” button within the Network Application Row.</p></li></ol><img src="//images.ctfassets.net/2nw9zhl2ydi6/q1sAX9fwIoFnEHE12JXUb/a1a9050ef32a3d067245117b60bcbace/unifi_network_update.png" alt="UniFi Netowork Update Instructions" style="max-width:100%;"/><p class="figure-reference italic-paragraph"><i>Figure 1 Update mechanism within the UniFi UI</i></p><p>Beazley Security also advises organizations running UniFi Management Systems enable automatic updates on their machines. This is accessible by clicking the Application row within the UI and selecting a Release Channel and an update cadence from within the UI. </p><p>Organizations which were running vulnerable instances should assume root-level compromise of the device and are recommended to perform a clean install and restoration from a known backup if possible. Given root can read UniFi’s secret store which contains signing keys, TLS keys, cloud tokens, login database entries, and network configuration materials; a rotation of all secrets on the host is required. This includes running force-logout on all sessions and resetting database credentials. </p><p>Once backups of Unifi OS are restored on a clean install, organizations must rotate the signing key for the <code>unifi-core</code> service as restoring updates will not automatically rotate the potentially exfiled signing key. To do so you must update the <code>secret:</code> value in <code>/data/unifi-core/config/jwt.yaml</code> with a new value which can be produced with <code>openssl rand –hex 32 </code></p></div><div class="rtf"><h3 class="rtf-title">Indicators of Compromise (IoCs)</h3><p>Ubiquiti has not released any IoCs or indicators of attack related to this vulnerability at the time of disclosure. However, given the exploit grants the attacker root-level privileges to the underlying data presented in the UI, logs and traces of compromise can be altered or removed, preventing organizations from collecting indicators. Telemetry for this attack can be linked to known threat actors (Mirai/Gaafgyt) identified from IP information and are not likely to be discoverable on a compromised host post-exploitation. </p></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>UniFi OS fronts its web portal with nginx and enforces authentication with <code>auth_requests</code> to an underlying <code>unifi-core</code> service. This authentication check matches the request’s raw <code>x-original-uri</code> in nginx but does not normalize an encoded value after routing the traffic. This allows for divergent behavior where the request is sent from nginx when a normalized value is compared to an encoded value. </p><p>An attacker can send a request to <code>/api/aith/validate-sso/</code> which is exempt from the authorization flow, with a crafted payload that nginx redirects to an authorized internal route. </p><p><code>GET /api/auth/validate-sso/..%2f..%2f..%2fproxy/users/api/v2/ucs/update/latest_package </code></p><p>Once an attacker has bypassed the authorization, a <code>package-update</code> route is accessible which runs unsensitized input through an <code>sh –c</code> shell wrapper. This allows an attacker run arbitrary commands on the host OS trivially. Furthermore, Unifi OS 5.0.8 runs these commands on a service account, which has passwordless sudo on <code>/usr/bin/uos</code>, <code>/usr/bin/systemctl</code>, <code>/bin/chmod</code>, and critically <code>/usr/bin/dpkg/</code>. Attackers can install arbitrary packages on the system which run as root, and can maintain persistence by enabling and running packages on the init system of the host with <code>systemd</code>. </p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found. </p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients. </p><p>If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team. </p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b">https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b</a> </p></li><li><p><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"><u>https://www.cisa.gov/known-exploited-vulnerabilities-catalog</u></a> </p></li><li><p><a href="https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis"><u>https://bishopfox.com/blog/popping-root-on-unifi-os-server-unauthenticated-rce-chain-detection-analysis</u></a> </p></li><li><p><a href="https://github.com/BishopFox/CVE-2026-34908-check"><u>https://github.com/BishopFox/CVE-2026-34908-check</u></a> </p></li></ul></div>]]></content><summary type="html">Three CVEs released for Ubiquiti's UniFi OS allow attackers unauthenticated remote root level access</summary></entry><entry><title>Supply Chain Attack of Klue Market Intelligence Platform</title><link href="https://labs.beazley.security/advisories/BSL-A1183" rel="alternate"/><updated>2026-06-22T22:00:00.000Z</updated><published>2026-06-22T22:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1183</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On June 12<sup>th</sup>, Klue identified unauthorized activity affecting their integration infrastructure with Salesforce, resulting in data being exfiltrated from Salesforce instances of multiple Klue customers. Klue confirmed that attackers used a compromised legacy credential tied to an integration service account to access its systems. Using that access, the attacker proceeded to harvest OAuth tokens that Klue uses to connect with third-party platforms, including Salesforce. </p><p>As part of their containment and response to the incident, Klue revoked affected credentials and disabled integrations across multiple connected platforms including HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, Slack, and Salesforce. </p><p>The incident affected several Klue customers, including high-profile cybersecurity firms, which have begun notifying affected organizations based on the exposed Salesforce data. Compromised Salesforce data typically consists of sensitive information such as contact names, email addresses, job titles, phone numbers, business addresses, pricing quotes, and sales account data. </p><p>While the attacker has demonstrated the ability to pivot across connected customer environments via OAuth tokens, there have been no public reports at the time of writing that lateral movement extended beyond initial Salesforce environments. Klue has revoked the affected credentials and tokens, and engaged CrowdStrike for ongoing incident response and forensic investigation. </p><p><b>Beazley Security does not utilize Klue within its environment, and analysis of authentication logs, integrations, and third-party access show no indication that Beazley Security systems were impacted by Klue related breach activity.</b> Beazley Security Labs is continuing to monitor the situation and will update this advisory as additional details become available. </p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><p>Any organizations with an active or historical Klue integration connected to Salesforce or other supported platforms should assume their Salesforce environments to be breached. </p><p>Organizations whose vendors or partners rely on Klue for competitive intelligence functions may also be indirectly affected and should monitor security notification channels for any required actions.</p></div><div class="rtf"><h3 class="rtf-title">Indicators of Compromise (IoCs)</h3><p>Organizations who are Klue clients should assume breach and immediately revoke and rotate service-account passwords, refresh tokens, client secrets, and OAuth grants associated with any Klue integrations. Once access is revoked, Beazley Security recommends that administrators enable IP allowlisting on third-party integration accounts to their known addresses wherever possible to reduce the risk of data exfiltration for other Salesforce integrations. </p><p>In addition, Klue Clients should review third-party OAuth integrations for any unknown or unauthorized connections established after June 12<sup>th</sup>. For organizations with a Salesforce integration activated in Klue, review API query logs against the <code>/services/data/v59.0/</code> endpoint for unusual activity and audit any Salesforce OAuth integrations for any unknown or unauthorized accounts created since that date. </p><p><a href="https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft"><u>ReliaQuest identified the following IP addresses</u></a> as destinations for exfiltration in their findings: </p><ul><li><p><code>138.226.246[.]94 </code></p></li><li><p><code>212.86.125[.]24 </code></p></li><li><p><code>213.111.148[.]90 </code></p></li><li><p><code>94.154.32[.]160</code></p></li></ul></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>The compromise of Klue originated from a legacy credential created for an integration prototype that remained active after the project ended. A threat actor discovered the credential and used it to gain access to Klue’s environment to pivot into customer integrations. Once in, the attacker deployed code designed to harvest OAuth tokens used by Klue to connect to Salesforce customer platforms. Using the stolen OAuth tokens, the attacker was able to authenticate to affected Salesforce environments and access CRM data directly. </p><p>Attribution for the attack remains unclear. On the 17<sup>th</sup>, ReliaQuest published information identifying the specific post-access script behavior and tentatively identified ShinyHunters as the attacker. A few days later on the 21<sup>st</sup>, ShinyHunters posted on their Telegram channel claiming ownership of the Klue attack, highlighting their exfiltrated Salesforce data. In contrast, <a href="http://www.huntress.com/blog/klue-breach-investigation"><u>Huntress independently attributed</u></a> the attack to the newly emerged Icarus extortion group with high confidence, based on indicators within their own compromised environment. Since then, Icarus has added Klue to its Tor-based leak site, claiming responsibility for the attack and soliciting victims to contact them directly to prevent posting the stolen data. </p><img src="//images.ctfassets.net/2nw9zhl2ydi6/vw47lM2Mz8lJqzDXBJe9X/2f26faf52e53c5b5bffd08cc556046b2/icarus_klue_post.png" alt="Icarus-Klue-Attribution" style="max-width:100%;"/><p class="figure-reference italic-paragraph"><i>Figure 1. Screenshot of Icarus site</i></p><p>Beazley Security Labs will continue to monitor the situation and update this advisory as relevant details become available. </p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is actively monitoring the evolving situation and assessing potential impact across our vendor ecosystem. </p><p>For clients with SaaS platforms logging to our MXDR solution, we are reviewing available telemetry for indicators of compromise associated with this incident. </p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach"><u>contact our Incident Response team.</u></a></p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://klue.com/blog/an-update-on-recent-klue-security-incident"><u>https://klue.com/blog/an-update-on-recent-klue-security-incident</u></a> </p></li><li><p><a href="https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft"><u>https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft</u></a> </p></li><li><p><a href="https://status.salesforce.com/generalmessages/20000257"><u>https://status.salesforce.com/generalmessages/20000257</u></a></p></li><li><p><a href="https://&quot;"><u>www.huntress.com/blog/klue-breach-investigation</u></a></p></li></ul></div>]]></content><summary type="html">A compromise of Klue's market intelligence platform resulted in an attacker accessing multiple Salesforce instances, affecting multiple downstream clients.</summary></entry><entry><title>&quot;FortiBleed&quot; Data Disclosure</title><link href="https://labs.beazley.security/advisories/BSL-A1182" rel="alternate"/><updated>2026-06-17T05:00:00.000Z</updated><published>2026-06-17T05:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1182</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>A cyber espionage campaign dubbed “FortiBleed” has been uncovered by security researchers purportedly involving the compromise of over 73,000 Fortinet devices. The recovered dataset indicates that the attacker’s operation targeted FortiGate devices and related SSL VPN gateways. According to researchers, data uncovered appears to contain valid SSL VPN and administrative credentials including usernames, email addresses, and plaintext passwords.</p><p>Unlike a traditional breach and data leak, FortiBleed was not disclosed through a dark web forum post or vendor disclosure but was discovered by researchers on an exposed server believed to belong to threat actors. The actors reportedly left a directory open, which contained attacker tooling and a cache of the harvested credentials.</p><p>At the time of writing, the method by which threat actors obtained the firewall data remains unconfirmed. Community research has tentatively attributed the attack to a Russian-speaking cybercriminal group, though this is not yet verified.</p><p>Researchers at HudsonRock have released this <a href="https://www.hudsonrock.com/fortinet">exposure lookup</a> tool to search for impacted domains and verify exposure within the obtained dataset.</p><p>This is an evolving situation and Beazley Security will update this advisory as more information becomes available.</p></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>Affected organizations should assume that credentials or configuration data on FortiGate devices may have been exposed and take the following preventative actions:</p><ul><li><p>Rotate admin credentials, including local administrator accounts, API tokens, certificates, and other credentials integrated with the firewall.</p></li><li><p>Review historical administrator and authentication logs for signs of suspicious activity, including logins from unexpected IP addresses, geolocations, or account activity outside of normal business hours.</p></li><li><p>Upgrade devices to the latest FortiOS release if not already applied. Following any upgrades, rotate admin credentials to invalidate credentials that may have been exposed prior.</p></li><li><p>Restrict or eliminate direct internet access to the firewall management interface. Lock down administrative access to trusted and expected internal networks.</p></li><li><p>Implement multi-factor authentication for all accounts where possible to reduce risk of compromised credentials being used.</p></li></ul></div><div class="rtf"><h3 class="rtf-title">Indicators of Compromise (IoCs)</h3><p>At the time of writing, no indicators of compromise (IoCs) have been publicly attributed to FortiBleed, as the dataset was reportedly recovered from the actor’s own exposed server rather than discovered through a campaign with classic IoCs.</p><p>Defenders should focus on evidence of unauthorized access using compromised credentials, including:</p><ul><li><p>Successful administrative or SSL VPN logins from unexpected geographies, ranges, or unexpected times.</p></li><li><p>New or unexpected administrator account creations, or unexpected changes to administrative users.</p></li><li><p>Unexpected configuration backups or exports from untrusted sources.</p></li><li><p>Evidence of lateral movement into internal environments, especially activity pivoting from firewall access into Active Directory environments or SQL servers.</p></li></ul></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>The FortiBleed dataset was originally discovered by security researcher <a href="https://www.linkedin.com/posts/vdyachenko_massive-fortinetfortigate-bruteforceactive-activity-7471222472193830913-YBDi/">Bob Diachenko</a> and is reported to contain credential records, including firewall URLs, IPs and hostnames, usernames, and plaintext passwords, along with organizational context. It is believed that some authentication hashes were intercepted and potentially cracked to access and move laterally into environments. Post-access activity reportedly includes attempts to access Active Directory and SQL server environments.</p><p>As the dataset was discovered by researchers on exposed threat actor infrastructure, the exact method through which the configuration data was stolen or obtained by the attackers is unconfirmed at this time, and there is no corresponding vulnerability advisory from Fortinet.</p><p>Beazley Security recommends organizations rotate credentials on affected FortiGate devices immediately. We will continue to monitor for additional developments and provide updates as information becomes available.</p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.</p><p>Beazley Security has obtained the full list of potentially compromised devices and harvested credentials. Beazley Security has notified clients whose device IP addresses or email domains appeared in the &quot;Fortibleed&quot; list.</p><p>In addition, we have also conducted threat hunts across our MDR environment to detect potential access attempts against our clients.</p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach">contact our Incident Response team</a>.</p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://www.hudsonrock.com/fortinet">HudsonRock: FortiBleed</a></p></li><li><p><a href="https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8">DoublePulsar: FortiBleed — 75k Fortinet firewalls have admin passwords cracked</a></p></li></ul></div>]]></content><summary type="html">A cyber espionage campaign dubbed “FortiBleed” has been uncovered by security researchers purportedly involving the compromise of over 73,000 Fortinet devices. The recovered dataset indicates that the attacker’s operation targeted FortiGate devices and related SSL VPN gateways.</summary></entry><entry><title>Critical Vulnerability in Content Editor Extension for Joomla (CVE-2026-48907)</title><link href="https://labs.beazley.security/advisories/BSL-A1181" rel="alternate"/><updated>2026-06-16T22:00:00.000Z</updated><published>2026-06-16T22:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1181</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On the 12<sup>th</sup> of June, The Joomla Content Editor (JCE) maintainers released an advisory regarding their recent security updates. Namely, CVE-2026-48907 describes a maximum-severity (CVSS 10.0) unauthenticated remote code execution vulnerability in the JCE extension, affecting all versions from 1.0.0 through 2.9.99.4. The flaw allows any unauthenticated attacker to upload arbitrary PHP files and execute code on the target server. 

CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 16, 2026, confirming active exploitation in the wild, with automated scanning campaigns already targeting the approximately 2.5 million active Joomla sites worldwide. </p><p>Given the release of the patches, we advise affected individuals to update Joomla plugins immediately. Information regarding updating can be found in the Patches section below. </p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><table><tbody><tr><th><p>Product </p></th><th><p>Affected Version </p></th><th><p>Fixed Version </p></th></tr><tr><td><p>Joomla Content Editor (JCE) extension for Joomla </p></td><td><p>1.0.0 to 2.9.99.4 </p></td><td><p>2.9.99.5, 2.9.99.6 </p></td></tr></tbody></table><p>For clarification, a fix was provided in version 2.9.99.5, and additional hardening was added in 2.9.99.6. Widget Factory recommends affected clients upgrade to 2.9.99.6. </p></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>The June 6 patch (version 2.9.99.6) is the current fully hardened release and should be applied if possible. If that cannot be done, there are some general mitigation steps that can be applied: </p><ul><li><p><b>Disable PHP execution in upload directories:</b> </p><ul><li><p>On Apache, place a .htaccess file inside every upload directory blocking <code>.php</code>, <code>.phtml</code>, <code>.phar</code>, and <code>.php5</code> extensions. </p></li><li><p>On NGINX, use a location block to deny PHP execution within images, media, tmp, and uploads directories. </p></li></ul></li><li><p><b>PHP configuration hardening:</b> In php.ini, disable dangerous functions: <code>exec, passthru, shell_exec, system, proc_open, popen, curl_exec, curl_multi_exec, parse_ini_file, show_source</code>. </p></li><li><p><b>Administrative interface restriction:</b> Enable IP allowlisting for administrative interfaces (e.g., restrict /administrator to VPN or office IP ranges) and enforce MFA on all admin accounts. </p></li></ul></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>Patches and instructions were provided by the component developer in their <a href="https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites"><u>advisory</u></a>. As mentioned above, version 2.9.99.5 includes baseline fixes for the root issues related to the profile import endpoint. Version 2.9.99.6 added further hardening around the processing of user-supplied XML data to that endpoint. Widget Factory strongly recommends affected users update to the 2.9.99.6 patch. </p></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>Technical details of the vulnerability along with proof-of-concept (PoC) code were published by researchers at <a href="https://www.yeswehack.com/news/rce-joomla-content-editor-extension"><u>YesWeHack</u></a> on the same day as the official advisory from JCE. The CVE is comprised of multiple issues, all related to the following Widget Factory JCE component API endpoint: </p><p><code>/index.php?option=com_jce&amp;task=profiles.import </code></p><p>This endpoint is accessible without authorization and does not restrict uploads to only process profiles, allowing attackers to connect to the endpoint and upload arbitrary data that will get processed by the JCE component. </p><p>While the endpoint is meant to ingest and process XML file data, insufficient filtering in the vulnerable releases allows threat actors to upload arbitrary PHP files to be processed and stored. As a result, the underlying <code>File::upload</code> function is invoked with an <code>$allow_unsafe = true</code> parameter, which effectively bypasses Joomla's extension safety mechanisms. Together, these issues allow attackers to directly upload reverse shells and execute malicious code on a target machine. </p><p>Affected organizations can monitor and hunt for suspicious requests to the above-mentioned endpoint as an indicator of attack. Malicious requests to that endpoint will contain non-XML file content. </p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found. </p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients. </p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach"><u>contact our Incident Response team</u></a>. </p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites"><u>https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites</u></a> </p></li><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48907"><u>https://nvd.nist.gov/vuln/detail/CVE-2026-48907</u></a></p></li><li><p><a href="https://www.cisa.gov/news-events/alerts/2026/06/16/cisa-adds-one-known-exploited-vulnerability-catalog"><u>https://www.cisa.gov/news-events/alerts/2026/06/16/cisa-adds-one-known-exploited-vulnerability-catalog</u></a></p></li><li><p><a href="https://www.yeswehack.com/news/rce-joomla-content-editor-extension"><u>https://www.yeswehack.com/news/rce-joomla-content-editor-extension</u></a> </p></li><li><p><a href="https://deafnews.it/en/news/vulnerabilities/cisa-adds-joomla-jce-to-kev-pre-auth-rce-cvss-100"><u>https://deafnews.it/en/news/vulnerabilities/cisa-adds-joomla-jce-to-kev-pre-auth-rce-cvss-100</u></a> </p></li></ul></div>]]></content><summary type="html">An Remote Code Execution vulnerability was published that affects a well-known and widely used Joomla Extension &quot;Joomla Content Editor&quot; that is being exploited in the wild.</summary></entry><entry><title>Critical Authentication Bypass in SimpleHelp (CVE-2026-48558) </title><link href="https://labs.beazley.security/advisories/BSL-A1180" rel="alternate"/><updated>2026-06-16T22:00:00.000Z</updated><published>2026-06-16T22:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1180</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On June 29th, 2026 CISA added the critical vulnerability CVE-2026-48558 affecting SimpleHelp RMM to its known exploited vulnerabilities (KEV) catalog following confirmed active exploitation in the wild.</p><p>On June 12<sup>th</sup>, a critical vulnerability in SimpleHelp RMM was disclosed by Zach Hanley on behalf of offensive security firm Horizon3.ai. Tracked as CVE-2026-48558, the flaw lets an unauthenticated, remote attacker create and access privileged “Technician” accounts on Simplehelp servers configured to use OpenID Connect (OIDC) authentication. </p><p>SimpleHelp is commonly used for remote support, remote access, and monitoring within enterprise environments. Technician accounts within the SimpleHelp RMM solution are highly privileged, and by default can remote into managed endpoints, execute scripts, and perform other privileged actions. SimpleHelp has released fixes for the underlying vulnerability, which can be found below. </p><p>Given the administrative access typically granted to SimpleHelp RMM deployments and broad reach they provide within enterprise environments, as well as their history of being targeted by initial access brokers and ransomware operators, Beazley Security recommends affected organizations apply available fixes immediately and conduct a thorough review for any signs of compromise. </p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><table><tbody><tr><th><p>Product </p></th><th><p>Affected Versions </p></th></tr><tr><td><p>SimpleHelp </p></td><td><p>&lt; v5.5.16 </p></td></tr><tr><td><p>SimpleHelp </p></td><td><p>&lt; v6.0 RC 2 </p></td></tr></tbody></table></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>Given the vendor-released patches, we advise customers running vulnerable software upgrade to non-vulnerable versions of SimpleHelp. If affected administrators are unable to immediately apply fixes, disabling OIDC may temporarily help to reduce risk. However, doing so will limit login availability to local accounts. 

Disabling OIDC in SimpleHelp can be performed by logging into the SimpleHelp service with a local administrator account and performing the steps below: </p><ol><li><p>Navigate into each Technician Group that uses OIDC. </p></li><li><p>Switch to the Authentication tab. </p></li><li><p>Disable or switch the group's authentication back to local/password authentication. </p></li></ol></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>Official security fixes have veen made available by SimpleHelp and can be accessed via their Upgrade Guide <a href="https://guides.simple-help.com/updating-guide#updating-simplehelp"><u>here</u></a>.</p></div><div class="rtf"><h3 class="rtf-title">Indicators of Compromise (IoCs)</h3><p>Active exploitation of this vulnerability has not been confirmed as of publication of this advisory. However, given prior targeting of SimpleHelp by prolific threat actors in previous campaigns, public disclosure of technical details may accelerate exploitation attempts in the upcoming days. </p><p>To log in as a Technician, an attacker must connect from an IP address permitted by Technician login IP restrictions. If IP restrictions were not previously configured, logins from unexpected geolocations or ASNs are indicative of a compromised host. Defenders can watch for the following signs of compromise: </p><ul><li><p>New or unexpected Technician accounts </p></li><li><p>Unexpected Technician account logins, sessions, or tool runs initiated from unrecognized IP addresses </p></li><li><p>Unexpected configuration changes performed by recently created accounts 
</p></li></ul><p>You can access these logs from the SimpleHelp portal via Administration > Server Log > Access to review, as well as Administration > History, which records historical authenticated sessions. </p><p>We can therefore assume that POST requests to the /technician path, or an OAuth callback URL that originates from IPs that are not your configured IdP, are indicative of bypass attempts. Searching for Configuration save requested in the configuration/serverconfig.xml path can identify instances of these requests. </p></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>At the time of writing, SimpleHelp and the disclosing researchers have provided limited technical details regarding the vulnerability, and no public proof-of-concept exploits are known to be available. CVE-2026-48558 is an authentication bypass vulnerability affecting SimpleHelp deployments that are configured to use OpenID Connect (OIDC). </p><p>The vulnerability stems from a flaw within SimpleHelp’s OIDC authentication workflow that allows an attacker to submit forged tokens with arbitrary claims to bypass authentication. When OIDC authentication is enabled, the flaw allows an unauthenticated attacker to create and log in as a new Technician user even if MFA is enabled. </p><p>SimpleHelp is widely used by IT support desks and managed service providers, which makes a compromised server a potential pivot into many downstream client environments. Given prior targeting by well-known ransomware operators, Beazley Security recommends affected organizations patch immediately.</p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found. </p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients. </p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach"><u>contact our Incident Response team</u></a>.</p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48558"><u>https://nvd.nist.gov/vuln/detail/CVE-2026-48558</u></a> </p></li><li><p><a href="https://simple-help.com/security/simplehelp-security-update-2026-05"><u>https://simple-help.com/security/simplehelp-security-update-2026-05</u></a> </p></li><li><p><a href="https://guides.simple-help.com/updating-guide#updating-simplehelp"><u>https://guides.simple-help.com/updating-guide#updating-simplehelp</u></a></p></li></ul></div>]]></content><summary type="html">A critical SimpleHelp RMM remote authentication bypass was released June 12th which allows attackers to create privileged Technician accounts and grant control of SimpleHelp instance</summary></entry><entry><title>Critical Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Under Active Exploitation  (CVE-2026-35273)</title><link href="https://labs.beazley.security/advisories/BSL-A1179" rel="alternate"/><updated>2026-06-11T07:00:00.000Z</updated><published>2026-06-11T07:00:00.000Z</published><id>https://labs.beazley.security/advisories/BSL-A1179</id><content type="html"><![CDATA[<div class="rtf"><h3 class="rtf-title">Executive Summary</h3><p>On June 10<sup>th</sup> Oracle released a security advisory impacting the Environment Management component within Oracle’s PeopleSoft application. The vulnerability, now publicly tracked as CVE-2026-35273, has been reportedly <b>actively exploited</b> as early as May 27<sup>th</sup> 2026. </p><p>Threat actors associated with Shiny Hunters have reportedly leveraged this vulnerability in a campaign targeting over 100 organizations worldwide. The vulnerability is remotely exploitable without authentication with potential to achieve remote code execution on exposed Oracle PeopleSoft instances. </p><p>Oracle released security updates to address the vulnerability on June 10<sup>th</sup>, but provided limited technical details at the time of disclosure. No public proof-of-concept exploit code has been released at the time of this writing. </p><p>Given the sensitive business and personnel data commonly stored within PeopleSoft environments and reports of active exploitation by a prolific threat actor, Beazley Security strongly recommends affected organizations apply available fixes immediately and conduct a thorough review for any signs of compromise. </p></div><div class="rtf"><h3 class="rtf-title">Affected Systems or Products</h3><table><tbody><tr><td><p>Product </p></td><td><p>Affected Versions </p></td></tr><tr><td><p>PeopleSoft Enterprise PeopleTools </p></td><td><p>8.61, 8.62 </p></td></tr></tbody></table></div><div class="rtf"><h3 class="rtf-title">Mitigations / Workarounds</h3><p>No official mitigations or workarounds aside from the software updates were publicly provided by Oracle at the time of disclosure. However, GTIC published a <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/"><u>detailed report</u></a> on the attacker infrastructure used by ShinyHunters for their campaign leveraging this CVE, and helpfully included the following hardening recommendations: </p><ul><li><p>Disable the Environment Management Hub (EMHub) Service in Multi-Server configurations or completely remove the PSEMHUB application in Single-Server configurations, as advised by Oracle's security alert guidance. </p></li><li><p>If you cannot disable the EMHub Service, block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the network perimeter or firewall level. </p></li></ul></div><div class="rtf"><h3 class="rtf-title">Patches</h3><p>Official security fixes were made available by Oracle <a href="https://support.oracle.com/support/?documentId=CPU187"><u>here</u></a>. Users must have an account to access the patches and documentation. </p></div><div class="rtf"><h3 class="rtf-title">Indicators of Compromise (IoCs)</h3><p>Active exploitation of this vulnerability has been confirmed in the wild. Mandiant and Google Threat intelligence Group (GTIG) <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/"><u>identified</u></a> an active campaign attributed to ShinyHunters with activity predating Oracle’s June 10<sup>th</sup> advisory and released the following indicators of compromise: </p><table><tbody><tr><td><p><b>IP Address</b> </p></td><td><p><b>Role</b> </p></td></tr><tr><td><p>142.11.200.186 </p></td><td><p>Staging / C2 </p></td></tr><tr><td><p>142.11.200.187 </p></td><td><p>Staging / C2 </p></td></tr><tr><td><p>142.11.200.188 </p></td><td><p>Staging / C2 </p></td></tr><tr><td><p>142.11.200.189 </p></td><td><p>Staging / C2 </p></td></tr><tr><td><p>142.11.200.190 </p></td><td><p>Staging / C2 </p></td></tr><tr><td><p>azurenetfiles.net </p></td><td><p>C2 Domain </p></td></tr><tr><td><p>176.120.22.24 </p></td><td><p>ShinyHunters DLS Mirror </p></td></tr></tbody></table><p><b>Payloads &amp; Files:</b> </p><table><tbody><tr><td><p><b>File Name</b> </p></td><td><p><b>Description</b> </p></td><td><p><b>SHA-256</b> </p></td></tr><tr><td><p>.bash_history </p></td><td><p>Attacker command history </p></td><td><p>2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35 </p></td></tr><tr><td><p>meshagent64-azure-ops.exe </p></td><td><p>Pre-configured Windows agent </p></td><td><p>f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc </p></td></tr><tr><td><p>meshagent64-v2.exe </p></td><td><p>Pre-configured Windows agent </p></td><td><p>d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f </p></td></tr><tr><td><p>meshagent32-azure-ops.exe </p></td><td><p>Pre-configured Windows agent </p></td><td><p>c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f </p></td></tr><tr><td><p>meshagent </p></td><td><p>Unconfigured Linux agent </p></td><td><p>68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309 </p></td></tr></tbody></table><p><b>Dropped Filenames:</b> </p><table><tbody><tr><td><p><b>File Name</b> </p></td></tr><tr><td><p>README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT </p></td></tr><tr><td><p>[victim_abbreviation]_fanout.sh </p></td></tr></tbody></table></div><div class="rtf"><h3 class="rtf-title">Technical Details</h3><p>As previously noted, Oracle has not released technical details regarding this vulnerability, and no public proof-of-concept exploits are currently available. However, a threat report published by GITC includes indicators associated with the exploitation of CVE-2026-35273. </p><p>According to the report, observed activity targeted PeopleSoft Environment Management Hub (PSEMHUB) components through malicious HTTP POST requests directedat the /PSEMHUB/hub and /PSIGW/HttpListeningConnector endpoints. </p><p>GITC also observed post exploitation activity resulting in suspicious .jsp files within /webserv/applications/peoplesoft/PSEMHUB.war/, and unexpectedfiles or directories within the /PSEMHUB.war/envmetadata/transactions/, logs, persistantstorage, or scratchpad in PSEMHUB paths. </p><p>The combination of suspicious HTTP POST traffic followed by the presence of unexpected files suggests the vulnerability may enable unauthenticated file uploads, arbitrary file write, up to remote command execution capabilities. At the time of writing, the exact root cause and exploitation mechanism remain unconfirmed.</p></div><div class="rtf"><h3 class="rtf-title">Our Organizational Response</h3><p>Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found. </p><p>We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients. </p><p>If you believe your organization may have been impacted by this attack campaign and need support, please <a href="https://beazley.security/report-security-breach"><u>contact our Incident Response team</u></a>. </p></div><div class="rtf"><h3 class="rtf-title">Sources</h3><ul><li><p><a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html"><u>https://www.oracle.com/security-alerts/alert-cve-2026-35273.html</u></a> </p></li><li><p><a href="https://dailysecurityreview.com/resources/oracle-peoplesoft-cve-2026-35273-shinyhunters-breaches-100-orgs/"><u>https://dailysecurityreview.com/resources/oracle-peoplesoft-cve-2026-35273-shinyhunters-breaches-100-orgs/</u></a> </p></li><li><p><a href="https://www.linkedin.com/posts/charlescarmakal_urgent-multiple-0-day-vulnerabilities-share-7470696836803117057-mf6m/"><u>https://www.theregister.com/cyber-crime/2026/06/11/shinyhunters-claims-oracle-peoplesoft-0-day-hit-100-orgs/5254443</u></a> </p></li><li><p><a href="https://support.oracle.com/support/?documentId=CPU187"><u>https://support.oracle.com/support/?documentId=CPU187</u></a> </p></li><li><p><a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/"><u>https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/</u></a> </p></li></ul></div>]]></content><summary type="html">On June 10th Oracle released a security advisory impacting the Environment Management component within Oracle’s PeopleSoft application. The vulnerability, now publicly tracked as CVE-2026-35273, has been reportedly actively exploited as early as May 27th 2026. </summary></entry>
</feed>
