πŸ” Security Pulse Β· 2026-08-01 16:00 UTC

⚑ TL;DR

Multiple critical vulnerabilities disclosed in Johnson Controls and Decidim participatory democracy software pose active exploitation risks; ongoing malware found on GitHub active for one year confirms sustained threat presence. Overall threat level elevated.

πŸ” CYBER THREATS

  • πŸ”΄πŸ”΄πŸ”΄ CVE-2026-34490 and CVE-2026-34495 Johnson Controls XAAP and FM Systems Employee apps suffer cleartext sensitive data storage and stored XSS allowing attackers on compromised devices to extract data and execute code [1][2].
  • πŸ”΄πŸ”΄πŸ”΄ CVE-2026-21662 Unrestricted file upload in Johnson Controls FM Systems Employee enables attackers to use malicious files for attacks [3].
  • πŸ”΄πŸ”΄ Decidim participatory democracy platform suffers multiple vulnerabilities (CVE-2026-45086, CVE-2026-45330, CVE-2026-45376) allowing admin endpoint access and identity verification bypass pre-0.32.0.rc2 versions [4][5][6].
  • πŸ”΄ CVE-2026-9044 TP-Link AXE75 V1 router VPN module vulnerability allows adjacent authenticated attacker to execute arbitrary OS commands, risking network compromise [7].
  • πŸ”΄ GitHub hosting persistent malware ("FunkyStar") with complex .NET payloads actively remained on platform for a year despite detection efforts, indicating poor threat removal and elevated risk to developers and open-source community [8][9].
  • 🟑 CVE-2026-54787 sigstore-go library fails to verify signing timestamps pre-1.2.1, possibly enabling aged signature misuse in CI/CD pipelines [10].
  • 🟑 CVE-2026-54725 vault-secrets-webhook flaw enables direct secret injection into Kubernetes pods before 1.23.1, increasing insider or cluster compromise risks.
  • 🟑 Multiple Thumbor (open-source photo service) vulnerabilities (CVE-2026-53500-53505) allow regex exhaustion, HMAC bypass, and filter flaws before 7.8.0, risking denial-of-service and unauthorized photo manipulation [27-31].

πŸ›‘οΈ NATIONAL SECURITY

  • 🟑 CISA issues public guidance on recognizing and reporting unattended/suspicious items in public spaces to enhance vigilance against possible physical threats or attacks.
  • 🟒 US government actively recruiting security personnel to bolster national resilience and protection of critical infrastructure systems amid growing threats.

⚠️ RISK FLAGS

  • ⚠️⚠️ Persistent malware presence on GitHub detected for over a year (FunkyStar), involving active resistance to removal and bans on security researchers, posing active threat to open source ecosystems and supply chain security [8][9].
  • ⚠️ Unpatched Johnson Controls systems remain exposed to file upload and XSS exploits with broad potential impact on building management infrastructure sensitive data and control [1][3][2].
  • ⚠️ Rapidly exploitable Decidim platform administration flaws risk manipulation of democratic processes in targeted countries using this software, requiring urgent patching [4][5][6].

🧭 THREAT MOOD

Elevated - Multiple critical software vulnerabilities actively exploited combined with extended malware persistence on major development platforms sustain a high-risk cyber environment requiring immediate remediation focus. National security vigilance continues with moderate alert from physical threat awareness campaigns. 🟑🟑

πŸ“Ž Sources

  1. CVE-2026-34490 Cleartext storage of sensitive information vuln… β€” @CVEnew
  2. CVE-2026-34495 Improper neutralization of input during web pag… β€” @CVEnew
  3. CVE-2026-21662 Unrestricted upload of file with dangerous type… β€” @CVEnew
  4. CVE-2026-45086 Decidim is a participatory democracy framework.… β€” @CVEnew
  5. CVE-2026-45330 Decidim is a participatory democracy framework.… β€” @CVEnew
  6. CVE-2026-45376 Decidim is a participatory democracy framework.… β€” @CVEnew
  7. CVE-2026-9044 An OS command injection vulnerability exists in … β€” @CVEnew
  8. What I find so impressive though is that this malware has been… β€” @vxunderground
  9. > get dm > "smelly, is this goop?" (malware) > "i found it on … β€” @vxunderground
  10. CVE-2026-54787 sigstore-go is a Go library for Sigstore signin… β€” @CVEnew

Educational & informational only β€” not financial advice. Markets carry risk; do your own research.
Serial 20260801-16-v27 Β· 2026-08-01 16:00 UTC Β· pulse.uzylab.com