|
|
Orkes Conductor Evaluator Remote Code Execution
Attackers are actively targeting Orkes Conductor servers vulnerable to CVE-2026-58138, a critical unauthenticated remote code execution vulnerability in its GraalVM script evaluators. FortiGuard telemetry is observing active attack attempts targeting vulnerable Orkes Conductor deployments.
The vulnerability allows an unauthenticated attacker to submit a malicious workflow definition containing JavaScript or Python expressions to the Conductor workflow API. Because vulnerable evaluators can be configured with unrestricted host access, the attacker can escape the intended scripting environment and execute arbitrary operating system commands with the privileges of the Conductor process.
Public proof-of-concept exploit code is available, including a working exploit targeting Conductor v3.23.0. Exploit material has also been published through Exploit-DB, increasing the likelihood of opportunistic scanning and exploitation of exposed deployments. |
QuickFox Supply Chain Attack
FortiGuard Labs has uncovered a long-running supply chain compromise targeting QuickFox, a Windows VPN/network acceleration application primarily used by overseas Chinese users. Attackers tampered with official Windows installers to deploy a custom backdoor tracked as FDMTP, enabling selective victim profiling and post-compromise access. The campaign has reportedly been active since August 2025 before being publicly disclosed in August 2026. |
WP2Shell RCE
FortiGuard Labs continues to detect exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical unauthenticated remote code execution (RCE) vulnerability affecting WordPress Core. Telemetry collected over the past seven days shows the highest volume of blocked attacks originating from or targeting Poland, Australia, Japan, the United States, and Turkey. |
| Distributed by aarss.com. |
|
|
|
|
|
Joe's Cable Products |
Joe's Cable offers client specific products. As a client of Joe's
Cable you can view product information that you have already
purchased from Joe's Cable, or you can order more of the same
products.As a Client of Joe's Cable you can also request a
new product via this web site or by calling Joe's Cable anytime.
If you were already logged in to this site, and are seeing
this message your session has expired. To protect your personal data
Joe'sCable.com limits sessions to one hour. You may log in as often
as you like. There is no limit to the amount of times you can log
in, so please login again.
|
|
|