The Matthew Chapman Podcast

Roundcube Pre-Auth SQL Injection Is Live in the Wild

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 6:17
Here is your briefing for Friday, September 25, 2026. Canada's Cyber Centre says a patched Roundcube Webmail bug is under active exploitation. C.V.E. twenty twenty-six dash forty-eight thousand eight hundred forty-two is an eight point one pre-auth SQL injection in the virtuser_query plugin on one point six before one point six point sixteen and one point seven before one point seven point one. A preg_replace backslash escape bypass lets an unauthenticated caller shove arbitrary SQL into the database backend. SentinelOne says that path can expose mail account credentials and stored messages. Roundcube shipped the fix in May. Shadowserver still sees more than five hundred twenty-three thousand Roundcube hosts on the open internet, with a small set still flagged vulnerable as of September twenty-third. Roundcube already drew China-aligned web-shell campaigns earlier this year, and CISA tagged two earlier Roundcube bugs as exploited in February. If you run Roundcube and skipped May's train, you are late to a fight that is already live. Bitget says suspected North Korean actors stole three hundred fifty-one point six million dollars from hot and warm wallets after a backend compromise at eighteen thirty-one U.T.C. on September twenty-fourth. Cold wallets and most platform assets were untouched, customer balances still match, and deposits and trading stayed up, but withdrawals are paused while Mandiant and SlowMist investigate. C.E.O. Gracy Chen says the attacker compromised a critical wallet-infrastructure backend, spoofed transaction data, and triggered authorization to move funds across Ethereum, X.R.P. Ledger, Arbitrum, Avalanche, Optimism, B.S.C., and Base. Assets hit include E.T.H., X.R.P., B.N.B., A.V.A.X., U.S.D.T., and U.S.D.C. Bitget Wallet, the self-custodial product on separate infrastructure, was not in scope. Chen says I.P. and on-chain patterns line up with known North Korean playbooks, and some chain foundations have already frozen attacker addresses. Backend trust for hot-wallet authorization just became a three hundred fifty-one million dollar lesson. Cloudflare and researchers at Accomplish disclosed a Containers flaw that let one paying customer read disk leftovers from other customers' containers on the same shared server. The data was from blocks earlier containers had released, not live workloads, and you could not aim at a chosen victim. Cloudflare Sandboxes, sold as a safe place to run untrusted code including A.I. agent output, sat on the same path. Thin-provisioned sixty-four kilobyte blocks rejoined a shared pool without the wipe that is normally the default. Write four kilobytes into a reused block, read the whole block raw, and the other sixty kilobytes still held the prior tenant's bytes. Production tests recovered leftovers on eighteen of twenty-four tries across four continents, including directory trees, SQLite databases, Chromium profiles, and .env and credential files. Cloudflare turned wiping back on, then drained every running container disk and cleared image caches by September nineteenth. It says detection against retained disk activity found only authorized testing. Multi-tenant disks that skip wipe are still a sandbox story, especially when the product is marketed for agent code. CISA added two critical flaws to KEV on Thursday with a September twenty-seventh deadline for federal civilian agencies. C.V.E. twenty twenty-six dash five thousand four hundred thirty is a nine point eight path traversal in WSO2 A.P.I. Control Plane, A.P.I. Manager, Traffic Manager, and Universal Gateway that unlocks unrestricted upload and remote code execution. watchTowr has seen in-the-wild forged J.W.T. traffic against honeypots since at least September thirteenth. C.V.E. twenty twenty-six dash seventy-one thousand three hundred sixty-two is a nine point one incorrect-authorization bug in Adobe Commerce and Magento that lets an attacker switch a customer session onto another account and read private customer data. Sansec blocked exploitation attempts in August, and Previdian saw an Australian I.P. hitting honeypots on September tenth. WSO2 sits in banking, government, telecom, and logistics. Magento still runs a huge slice of e-commerce. Patch both before the federal clock, not after the scanners finish the census. Manifold Security found that third-party.com, a docs and test placeholder for years the way example.com is supposed to be, now serves a ClickFix lure to Windows browsers and a harmless decoy to everyone else. Unlike example.com, it was never IANA-reserved. Someone registered it, and every README, skill, and M.C.P. server doc that hard-coded it now points readers at attacker infrastructure. VirusTotal and Google Safe Browsing already mark it malicious. The Windows page mimics a Cloudflare check, poisons the clipboard, and tells the victim to paste into Run, which pulls a remote PowerShell payload. The domain has been live with that lure since at least June, and GitHub still shows it in over seventeen hundred public repos, including A.I. agent skills. Manifold also flagged thirteen more squattable placeholders

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show