SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, August 26, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY MiniOrange SSO Flaws Target WordPress Websites | CRITICAL |
|
5 C2 IPs | 57 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by active exploitation of WordPress sites via critical MiniOrange SSO vulnerabilities (CVE-2026-61979 and CVE-2026-15981) and the emergence of the AnonyMousKIT PhaaS platform using voice AI to steal iPhone passcodes. Additionally, a massive DDoS campaign has disrupted Norway's public services, while threat actors are abusing npm mirrors to host deceptive Cloudflare CAPTCHA pages. |
|
■ CRITICAL STORIES WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Attackers are actively exploiting CVE-2026-61979 and CVE-2026-15981, which allow authentication bypass on sites using the MiniOrange SAML 2.0 SSO plugin. |
Hackers abuse npm mirrors to host phishing redirect pages Threat actors are abusing npm and unpkg mirrors to host malicious HTML pages impersonating Cloudflare CAPTCHAs, redirecting users to malicious sites via a ClickFix-style campaign. |
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes A new phishing-as-a-service platform automates passcode retrieval and Activation Lock bypass on stolen Apple devices using voice AI agents. |
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode A high-severity vulnerability in Marimo notebook software allows remote attackers to execute malicious Model Context Protocol (MCP) commands before cell execution. |
|
■ CVEs IDENTIFIED CVE-2026-61979 MiniOrange SAML 2.0 SSO (WordPress Plugin) — Authentication Bypass |
CVE-2026-15981 MiniOrange SAML 2.0 SSO (WordPress Plugin) — Authentication Bypass |
CVE-TBD (Marimo) Marimo Notebook — Remote Command Execution via MCP |
CVE-TBD (NVIDIA) NVIDIA NemoClaw / Ollama — Unauthenticated Control and Model Poisoning |
|
■ THREAT ACTORS Black Axe | Organized Crime Group |
Supported by an Argentine crime-as-a-service network providing domains and laundering |
AnonyMousKIT Operators | Cybercriminals |
Operating a PhaaS platform using voice AI to phish iPhone passcodes |
Mirage2FA Operators | Cybercriminals |
Running a massive 2FA-bypass phishing campaign targeting Microsoft 365 |
|
|
|
■ ATT&CK TTPs | T1566 | | Phishing | Used by AnonyMousKIT (voice AI) and Mirage2FA (M365 login flows) to harvest credentials |
| T1189 | | Drive-by Compromise | Malicious npm packages redirecting users to fake Cloudflare CAPTCHAs |
| T1204.001 | | User Execution: Malicious Link | Users redirected from npm mirrors to attacker-controlled sites |
| T1102 | | Web Service | Using unpkg and npm mirrors to host phishing infrastructure |
| T1090 | | Proxy | FTP banners used as dead drop resolvers for E4del and PINHOLE RATs |
| T1210 | | Exploitation of Remote Services | Authentication bypass in MiniOrange SAML SSO plugin |
|
■ PATCH PRIORITY MiniOrange SAML 2.0 SSO (WordPress) — Active exploitation of authentication bypass flaws (CVE-2026-61979, CVE-2026-15981) — SecurityWeek |
Marimo Notebook — High-severity flaw allows arbitrary MCP command execution in edit mode — The Hacker News |
NVIDIA NemoClaw / Ollama — Unauthenticated control and local model poisoning risk — The Hacker News |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch MiniOrange SAML 2.0 SSO WordPress plugin immediately to remediate critical authentication bypass vulnerabilities CVE-2026-61979 and CVE-2026-15981. |
| 2 | [P1] Update Marimo Notebook software to the latest version to prevent unauthorized Model Context Protocol (MCP) command execution. |
| 3 | [P2] Audit local deployments of NVIDIA NemoClaw and Ollama to ensure web interfaces cannot be abused for unauthenticated model poisoning. |
| 4 | [P2] Block and monitor traffic to known unpkg and npm mirror subdomains hosting unauthorized HTML/phishing content. |
| 5 | [P3] Implement WhatsApp's newly released multi-passkey and enhanced two-step verification features to secure corporate mobile endpoints. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |