Crying Out Cloud Monthly Newsletter - August 2026

Discover the latest cloud security insights for August, featuring active exploits on WordPress Core, high-severity Linux kernel flaws, and major supply chain compromises.

Welcome back! This month we’ve seen a lot of action, with both vulnerabilities and security incidents that have left users affected. We bring you the latest cloud security highlights, to help you stay informed and stay secure.

Throughout July 2026, Wiz Threat Research tracked multiple vulnerabilities and attacks, including the active exploitation of the critical wp2shell vulnerabilities affecting WordPress Core, which were weaponized within days of public disclosure. The month also saw the disclosure of multiple high-severity Linux kernel vulnerabilities, including flaws enabling local privilege escalation and potential guest-to-host escapes. At the same time, software supply chain compromises continued to accelerate, with attackers targeting trusted open source ecosystems by compromising package maintainers, CI/CD pipelines, and developer tooling to distribute malware and steal sensitive credentials.

<Visit the Blog>

Highlights

wp2shell: Pre-Auth RCE Vulnerability in WordPress Core Exploited in-the-Wild

A critical pre-authentication remote code execution (RCE) chain affecting WordPress Core, dubbed wp2shell (CVE-2026-63030 and CVE-2026-60137), is being actively exploited in the wild. Wiz Threat Research identified active exploitation shortly after public disclosure, observing multiple threat actors compromising self-hosted WordPress instances and deploying persistent webshells. Attackers have been seen uploading malicious plugins, enumerating users, attempting local file inclusion, and establishing authenticated admin access following successful exploitation. Until patching is possible, restricting anonymous access to the WordPress Batch API endpoints via a WAF or disabling anonymous REST API access can help reduce exposure.

According to Wiz data, 16% of cloud environments have resources vulnerable to this vulnerability.

Learn more in our blog https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137  

🐞 High Profile Vulnerabilities

 

Linux Kernel Privilege Escalation Vulnerabilities

Several high-severity Linux kernel vulnerabilities disclosed this month highlight the continued risk of local privilege escalation and virtualization escapes in enterprise environments. Januscape (CVE-2026-53359) is a KVM/x86 guest-to-host escape vulnerability that could allow a root user in an untrusted virtual machine to crash or potentially escape to the underlying host in environments with nested virtualization enabled. GhostLock (CVE-2026-43499) is a long-standing use-after-free flaw in the Linux kernel's rtmutex subsystem that enables local privilege escalation to root and potential container escapes following initial code execution. RefluXFS (CVE-2026-64600) is a race condition in the XFS filesystem that allows an unprivileged local attacker to overwrite protected files and gain root privileges on systems using reflink-enabled XFS.

Learn more here [1,2,3]

LiteLLM MCP Authentication Bypass and Custom Code Guardrails RCE Vulnerabilities

Wiz Research discovered two vulnerabilities in LiteLLM affecting MCP endpoint authentication and Custom Code Guardrails. CVE-2026-59822 could allow unauthenticated attackers to access MCP tools using a fabricated bearer token, while CVE-2026-59821 could allow privileged attackers to execute arbitrary code inside the LiteLLM proxy container. Although CVE-2026-59821 initially received a low CVSS score due to its authentication requirements, it has been increased to high due to its practical impact. CVE-2026-59821 can be significant in real-world deployments because successful exploitation may enable theft of stored LLM API keys and lateral movement into connected cloud environments.

According to Wiz data, 43% of cloud environments have resources vulnerable to this vulnerability.

Learn more here [1,2]

PTC Windchill and FlexPLM Vulnerability Exploited by Cl0p Ransomware Group

Active Cl0p ransomware affiliates are exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting internet-exposed PTC Windchill PDMlink and PTC FlexPLM deployments. By chaining the RCE flaw with a pre-authentication information disclosure vulnerability, attackers are achieving unauthenticated code execution, deploying persistent webshells, and stealing engineering and design data before launching double-extortion campaigns that threaten to publicly leak stolen information.

According to Wiz data, less than 1% of cloud environments have resources vulnerable to this vulnerability.

Learn more here https://ransom-isac.com/blog/clop-windchill-flexplm-exploitation/  

🔓Security incidents & campaigns 

SleeperGem: RubyGems Supply Chain Attack Targets Dormant Maintainer Accounts

A software supply chain attack dubbed SleeperGem compromised multiple RubyGems packages after attackers hijacked dormant maintainer accounts to publish malicious gem versions. The trojanized packages were designed to download and execute remote payloads while evading CI/CD environments by specifically targeting developer workstations. Attackers also introduced malicious package dependencies to expand the campaign's reach. 

Learn more here  https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack 

NadMesh: Autonomous AI-Focused Botnet Targeting Cloud and AI Infrastructure

Researchers identified NadMesh, a Go-based botnet that automates the discovery, exploitation, and compromise of internet-facing cloud and AI infrastructure. The malware targets exposed services including Kubernetes, Docker, Redis, MCP deployments, and several AI platforms, while harvesting cloud credentials and other sensitive information from compromised systems.

Learn more here https://blog.xlab.qianxin.com/nadmesh-botnet-analysis-a-product-grade-threat-for-the-ai-service-era-en/

M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

Wiz Research discovered a software supply chain attack targeting the AsyncAPI ecosystem, in which an attacker exploited a misconfigured GitHub Actions workflow to steal privileged credentials and publish five malicious versions of popular @asyncapi npm packages. The compromised packages, which collectively receive millions of weekly downloads, delivered a multi-stage malware payload that established persistence, connected to resilient command-and-control infrastructure, and targeted developer credentials, cloud secrets, and cryptocurrency wallets. 

Learn more in our blog  https://www.wiz.io/blog/m-red-team-asyncapi-supply-chain-compromise-via-github-actions 

Compromised Injective SDK npm Package Exfiltrates Cryptocurrency Wallet Secrets

A malicious version of the @injectivelabs/sdk-ts npm package (version 1.20.21) was briefly published to the official Injective Labs npm namespace after a contributor account was compromised. The package contained credential-stealing functionality that silently exfiltrated cryptocurrency wallet mnemonic phrases and private keys during normal library usage. Although the malicious release was detected and replaced within approximately one hour, the compromised version remained available for download after being deprecated, and additional Injective packages were released with dependencies pinned to the malicious SDK version.

Learn more here https://socket.dev/blog/compromised-injective-sdk-npm-package 

 
Hold on to your headphones! 

Tune in to "Crying Out Cloud", our monthly roundup of cloud security news podcast! Hosted by the talented duo Eden Naftali and Amitai Cohen 👏 

Listen on Spotify and Apple Podcasts.