Daily Security Intel

Archives
Log in
Subscribe
August 26, 2026

[SecurityIntel] 26 Aug | MiniOrange SSO Flaws Target WordPress Websites

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, August 26, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

MiniOrange SSO Flaws Target WordPress Websites

CRITICAL

5

C2 IPs

57

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by active exploitation of WordPress sites via critical MiniOrange SSO vulnerabilities (CVE-2026-61979 and CVE-2026-15981) and the emergence of the AnonyMousKIT PhaaS platform using voice AI to steal iPhone passcodes. Additionally, a massive DDoS campaign has disrupted Norway's public services, while threat actors are abusing npm mirrors to host deceptive Cloudflare CAPTCHA pages.

■ CRITICAL STORIES

CRITICAL#1

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

Attackers are actively exploiting CVE-2026-61979 and CVE-2026-15981, which allow authentication bypass on sites using the MiniOrange SAML 2.0 SSO plugin.

HIGH#2

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are abusing npm and unpkg mirrors to host malicious HTML pages impersonating Cloudflare CAPTCHAs, redirecting users to malicious sites via a ClickFix-style campaign.

HIGH#3

AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

A new phishing-as-a-service platform automates passcode retrieval and Activation Lock bypass on stolen Apple devices using voice AI agents.

HIGH#4

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

A high-severity vulnerability in Marimo notebook software allows remote attackers to execute malicious Model Context Protocol (MCP) commands before cell execution.

■ CVEs IDENTIFIED

CVE-2026-61979

MiniOrange SAML 2.0 SSO (WordPress Plugin) — Authentication Bypass

Critical

CVE-2026-15981

MiniOrange SAML 2.0 SSO (WordPress Plugin) — Authentication Bypass

Critical

CVE-TBD (Marimo)

Marimo Notebook — Remote Command Execution via MCP

High

CVE-TBD (NVIDIA)

NVIDIA NemoClaw / Ollama — Unauthenticated Control and Model Poisoning

High

■ THREAT ACTORS

Black Axe

Organized Crime Group

Supported by an Argentine crime-as-a-service network providing domains and laundering

AnonyMousKIT Operators

Cybercriminals

Operating a PhaaS platform using voice AI to phish iPhone passcodes

Mirage2FA Operators

Cybercriminals

Running a massive 2FA-bypass phishing campaign targeting Microsoft 365

■ ATT&CK TTPs

T1566
Phishing | Used by AnonyMousKIT (voice AI) and Mirage2FA (M365 login flows) to harvest credentials
T1189
Drive-by Compromise | Malicious npm packages redirecting users to fake Cloudflare CAPTCHAs
T1204.001
User Execution: Malicious Link | Users redirected from npm mirrors to attacker-controlled sites
T1102
Web Service | Using unpkg and npm mirrors to host phishing infrastructure
T1090
Proxy | FTP banners used as dead drop resolvers for E4del and PINHOLE RATs
T1210
Exploitation of Remote Services | Authentication bypass in MiniOrange SAML SSO plugin

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

MiniOrange SAML 2.0 SSO (WordPress) — Active exploitation of authentication bypass flaws (CVE-2026-61979, CVE-2026-15981) — SecurityWeek

[P1 PATCH NOW]≤24h

Marimo Notebook — High-severity flaw allows arbitrary MCP command execution in edit mode — The Hacker News

[P2 PATCH NOW]≤72h

NVIDIA NemoClaw / Ollama — Unauthenticated control and local model poisoning risk — The Hacker News

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch MiniOrange SAML 2.0 SSO WordPress plugin immediately to remediate critical authentication bypass vulnerabilities CVE-2026-61979 and CVE-2026-15981.
2[P1] Update Marimo Notebook software to the latest version to prevent unauthorized Model Context Protocol (MCP) command execution.
3[P2] Audit local deployments of NVIDIA NemoClaw and Ollama to ensure web interfaces cannot be abused for unauthenticated model poisoning.
4[P2] Block and monitor traffic to known unpkg and npm mirror subdomains hosting unauthorized HTML/phishing content.
5[P3] Implement WhatsApp's newly released multi-passkey and enhanced two-step verification features to secure corporate mobile endpoints.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 27 Aug | FBI Disrupts Chinese Espionage Proxy Infrastructure Older → [SecurityIntel] 25 Aug | Iranian Hackers Shut Down UK Power Plant
Powered by Buttondown, the easiest way to start and grow your newsletter.