π Security Pulse Β· 2026-08-01 16:00 UTC
β‘ TL;DR
Multiple critical vulnerabilities disclosed in Johnson Controls and Decidim participatory democracy software pose active exploitation risks; ongoing malware found on GitHub active for one year confirms sustained threat presence. Overall threat level elevated.
π CYBER THREATS
- π΄π΄π΄ CVE-2026-34490 and CVE-2026-34495 Johnson Controls XAAP and FM Systems Employee apps suffer cleartext sensitive data storage and stored XSS allowing attackers on compromised devices to extract data and execute code [1][2].
- π΄π΄π΄ CVE-2026-21662 Unrestricted file upload in Johnson Controls FM Systems Employee enables attackers to use malicious files for attacks [3].
- π΄π΄ Decidim participatory democracy platform suffers multiple vulnerabilities (CVE-2026-45086, CVE-2026-45330, CVE-2026-45376) allowing admin endpoint access and identity verification bypass pre-0.32.0.rc2 versions [4][5][6].
- π΄ CVE-2026-9044 TP-Link AXE75 V1 router VPN module vulnerability allows adjacent authenticated attacker to execute arbitrary OS commands, risking network compromise [7].
- π΄ GitHub hosting persistent malware ("FunkyStar") with complex .NET payloads actively remained on platform for a year despite detection efforts, indicating poor threat removal and elevated risk to developers and open-source community [8][9].
- π‘ CVE-2026-54787 sigstore-go library fails to verify signing timestamps pre-1.2.1, possibly enabling aged signature misuse in CI/CD pipelines [10].
- π‘ CVE-2026-54725 vault-secrets-webhook flaw enables direct secret injection into Kubernetes pods before 1.23.1, increasing insider or cluster compromise risks.
- π‘ Multiple Thumbor (open-source photo service) vulnerabilities (CVE-2026-53500-53505) allow regex exhaustion, HMAC bypass, and filter flaws before 7.8.0, risking denial-of-service and unauthorized photo manipulation [27-31].
π‘οΈ NATIONAL SECURITY
- π‘ CISA issues public guidance on recognizing and reporting unattended/suspicious items in public spaces to enhance vigilance against possible physical threats or attacks.
- π’ US government actively recruiting security personnel to bolster national resilience and protection of critical infrastructure systems amid growing threats.
β οΈ RISK FLAGS
- β οΈβ οΈ Persistent malware presence on GitHub detected for over a year (FunkyStar), involving active resistance to removal and bans on security researchers, posing active threat to open source ecosystems and supply chain security [8][9].
- β οΈ Unpatched Johnson Controls systems remain exposed to file upload and XSS exploits with broad potential impact on building management infrastructure sensitive data and control [1][3][2].
- β οΈ Rapidly exploitable Decidim platform administration flaws risk manipulation of democratic processes in targeted countries using this software, requiring urgent patching [4][5][6].
π§ THREAT MOOD
Elevated - Multiple critical software vulnerabilities actively exploited combined with extended malware persistence on major development platforms sustain a high-risk cyber environment requiring immediate remediation focus. National security vigilance continues with moderate alert from physical threat awareness campaigns. π‘π‘
π Sources
- CVE-2026-34490 Cleartext storage of sensitive information vulnβ¦ β @CVEnew
- CVE-2026-34495 Improper neutralization of input during web pagβ¦ β @CVEnew
- CVE-2026-21662 Unrestricted upload of file with dangerous typeβ¦ β @CVEnew
- CVE-2026-45086 Decidim is a participatory democracy framework.β¦ β @CVEnew
- CVE-2026-45330 Decidim is a participatory democracy framework.β¦ β @CVEnew
- CVE-2026-45376 Decidim is a participatory democracy framework.β¦ β @CVEnew
- CVE-2026-9044 An OS command injection vulnerability exists in β¦ β @CVEnew
- What I find so impressive though is that this malware has beenβ¦ β @vxunderground
- > get dm > "smelly, is this goop?" (malware) > "i found it on β¦ β @vxunderground
- CVE-2026-54787 sigstore-go is a Go library for Sigstore signinβ¦ β @CVEnew
Educational & informational only β not financial advice. Markets carry risk; do your own research.
Serial 20260801-16-v27 Β· 2026-08-01 16:00 UTC Β· pulse.uzylab.com