The Matthew Chapman Podcast

WSO2 JWT Bypass Is Minting Forged Admin Tokens in the Wild

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:36
Here is your briefing for Wednesday, September 16, 2026. watchTowr says a critical WSO2 API Manager bug is under active exploitation, and its honeypots started catching forged J.W.T.s with baked-in admin privileges on September thirteenth. The flaw is C.V.E. twenty twenty-six dash five thousand four hundred thirty, scored nine point eight. Sign a token with an unsupported algorithm, and the service verifies it anyway, then hands you the keys. That covers API Manager four point one through four point six, plus Control Plane, Traffic Manager, and Universal Gateway. Once inside, the forged token can reach every backend endpoint, consumer keys, and secrets for registered apps, and the gateway itself sits in the path of internal A.P.I. traffic. Patch to the May updates WSO2 already shipped, and treat any unexpected admin J.W.T. traffic as an incident. Your A.P.I. front door just became the lateral-movement bus. Wordfence is blocking a critical unauthenticated file upload in WooCommerce Wholesale Lead Capture, C.V.E. twenty twenty-six dash twenty-seven thousand five hundred forty, another nine point eight. More than six thousand active installs. Attackers hit the wwlc_file_upload_handler A.J.A.X. action with a forged file_settings parameter and drop shell.php. Wordfence has stopped over one hundred thousand exploit attempts since June, including ninety-nine in the last day. The shell reports host details and opens a browser form to write more malware. Same window: The Events Calendar, on more than six hundred thousand sites, got two separate unauthenticated R.C.E. chains through its widget pipeline, fixed in six point seventeen point three point one and six point seventeen point four point one. Hunt unexpected .php under uploads, and if you run either plugin, update now. WordPress commerce and events plugins keep turning into free shell hosts. Google says a high-severity Pixel Cellular Modem flaw, C.V.E. twenty twenty-six dash fifty-eight thousand seven hundred four, scored eight point oh, may be under limited, targeted exploitation. It is a logic error that lets an adjacent attacker escalate privileges with no user interaction and no extra privileges required. Google is not naming the actor or the campaign. The September Pixel bundle also clears one hundred nine other bugs, including forty-six critical issues across bootloader, I.M.S., Trusted Execution, and related components. Security patch level twenty twenty-six dash oh nine dash oh five or later closes the set. If you carry a Pixel, take the update. Modem bugs that need only proximity are the kind of quiet targeted tooling nation-states love. Acronis warns that a high-severity privilege-escalation bug in its Backup plugin for cPanel and W.H.M., C.V.E. twenty twenty-six dash eighty-seven thousand eight hundred eighty-six, scored seven point eight, has been exploited in limited targeted attacks. Insecure file permissions let a low-privilege Linux user climb the box and run unauthorized code against the backup stack. Fixed builds are one point nine point three H.F. three for cPanel, build one point nine point three point one oh two one, and one point eight point eleven point six three eight for the Plesk extension. Details on the actor and goal are still thin. If your shared host runs Acronis backups through cPanel or Plesk, install the hotfix immediately. Backup plugins with bad permissions are a gift-wrapped path from one cheap account to the whole machine. Sysdig watched a skilled human exploit a pre-auth Marimo notebook R.C.E., C.V.E. twenty twenty-six dash thirty-nine thousand nine hundred eighty-seven, scored nine point three, then pivot to an S.S.H. bastion in eight seconds with a hand-rolled Python chain and no A.I. agent in the loop. WebSocket foothold, A.W.S. Secrets Manager pull, private key to disk, bastion login. Same speed defenders now expect from agentic malware, and the human skipped every honeypot trap the agents fell into. Over nine hours the operator ran more than eight hundred fifty interactive commands, custom tooling only, and never reached for a public framework. A.I. is changing the economics of mass exploitation. It has not retired the operator who can build the pivot live and walk past your agent bait. Lock notebook surfaces like production, and stop assuming eight-second dwell time only comes from bots. Forged admin J.W.T.s on WSO2 honeypots, WordPress plugins eating shells by the hundred thousand, a Pixel modem under quiet targeted use, an Acronis backup plugin climbing shared hosts, and a human who outran the A.I. playbook to a bastion in eight seconds. Identity at the A.P.I. edge, the plugins we install for convenience, and the notebooks we leave on the internet keep paying out to whoever moves first. That's your brief. Stay sharp, patch your systems, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show