Cyber Decision LedgerTechnology

Web application

8 public Decision Records in the whole ledger carry this label. Back to the full Ledger →

Decision Records

WordPress supply-chain containmentCRT-2026-02292026.08.11Morning roundtable6 references

BdThemes WordPress plugin containment

For affected or potentially affected BdThemes WordPress products, disable the components until administrators can verify a clean source, snapshot sites, inspect administrator accounts, plugin installs, web roots, scheduled tasks, MU-plugins, and outbound connections, and rotate credentials where untrusted code may have run.

For sites using affected or potentially affected BdThemes WordPress products, disable those components until a clean source can be verified and inspect for persistence or privilege changes. Snapshot first, review administrator accounts, plugin and web-root changes, scheduled jobs, MU-plugins, outbound connections, and rotate credentials if untrusted code may have run.

ActiveLast revised 2026-08-11
TechWeb applicationAreaSupply chain
SeverityHigh
ConfidenceHigh confidence · 0/8 backed · 2 gaps
WordPress core patch prioritizationCRT-2026-02202026.08.10Afternoon roundtable5 references

WordPress emergency patching without mass RCE framing

Emergency-patch externally exposed and administrator-heavy WordPress sites, restrict login and admin paths to VPN or known IPs where patching is delayed, and reserve full containment for sites with post-exploitation indicators. Do not label the issue as mass unauthenticated remote code execution based on the reviewed evidence.

Treat WordPress core CVE-2026-64638 as urgent patching for exposed or administrator-heavy sites, restrict login and admin paths if patching is delayed, and reserve containment for sites with post-exploitation indicators. The reviewed packet does not support describing it as mass unauthenticated remote code execution.

ActiveLast revised 2026-08-10
TechWeb applicationAreaPatch prioritization
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Licensed WordPress update-channel supply-chain responseCRT-2026-01802026.08.04Morning roundtable4 references

ShapedPlugin Pro update-channel containment

For ShapedPlugin Pro deployments that used the affected licensed update path or cannot validate recent packages, freeze updates until validated, inventory affected plugins, compare recent packages against known-good versions, hunt for hidden or fake plugin behavior, and restore from trusted packages if compromise is found.

Organizations using ShapedPlugin Pro products should pause further updates where recent licensed-channel packages cannot be validated, inventory relevant plugins, compare packages to trusted copies, hunt for hidden plugin behavior, and restore from known-good packages where local compromise is confirmed.

ActiveLast revised 2026-08-04
TechWeb applicationAreaPatch prioritizationSupply chain
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Rails vulnerability triageCRT-2026-01732026.08.04Morning roundtable5 references

Targeted triage for Rails file-processing exposure

Patch today and hunt uploads for public Rails applications that accept attacker-controlled files, use Active Storage with Vips or libvips variant processing, and run affected versions. For applications without those exposure conditions, verify configuration and use expedited maintenance rather than a blanket emergency stop.

For Rails applications with public untrusted upload paths and vulnerable image variant processing, patch and hunt on the same day. For other Rails applications, verify exposure and use expedited maintenance; avoid exact version claims until vendor release evidence is attached.

ActiveLast revised 2026-08-04
TechWeb applicationAreaPatch prioritizationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
CMS webshell exposure handlingCRT-2026-00792026.07.14Morning roundtable6 references

Split CMS webshell incidents from exposure-only cases

Use an evidence-based split: isolate confirmed compromised CMS hosts with webshell evidence, preserve evidence, rotate related credentials, and rebuild from clean media; if there is only matching exposure without shell evidence, patch and hunt, remove public admin paths, and add WAF/CDN controls.

For public CMS hosts with confirmed webshell evidence, treat the host as an incident: isolate it, preserve evidence, rotate related credentials, and rebuild from clean media. For exposure without compromise evidence, patch and hunt, remove public admin paths, and add WAF/CDN controls. Avoid product-specific or global-campaign claims until authoritative details are attached.

ActiveLast revised 2026-07-14
TechWeb applicationAreaCampaignPatch prioritization
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Internet-facing CMS containment and patch triageCRT-2026-00652026.07.12Morning roundtable6 references

Treat exposed CMS compromise indicators as containment work

Inventory and triage internet-facing CMS exposure now; patch vulnerable or unknown-state platforms and plugins, hunt for webshells and abnormal web-server child processes, and isolate or rebuild hosts when compromise indicators are present.

Organizations with internet-facing CMS exposure in this scenario should inventory exposed systems, patch vulnerable or unknown-state platforms and plugins, hunt for webshell or web-server process indicators, and isolate or rebuild hosts where compromise indicators are present; the packet does not identify every affected product or version.

ActiveLast revised 2026-07-12Prediction · due 11 AugNext checkpoint 11 Aug
TechWeb applicationAreaPatch prioritizationSOC escalationVulnerability
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
API authorization assuranceCRT-2026-00242026.06.30Morning roundtable4 references

Run sector-specific GraphQL BOLA assurance for booking APIs

Do not move the airline GraphQL booking API BOLA disclosure ahead of Cisco/SimpleHelp/Oracle for generic enterprises. Make it HIGH this week for airline, travel, or public booking API owners: test cross-booking access, aliases/batching, field-level leakage, and anonymous or pre-auth lookup flows; add resolver-level object authorization, field-level controls, rate limits, mismatch logging, and temporary PII redaction where needed.

Do not displace the generic enterprise surge queue for most organizations. Airline, travel, and public booking API owners should run high-priority assurance this week for GraphQL/BOLA-style cross-booking access, batching or alias abuse, field leakage, and anonymous lookup paths, and should add resolver-level authorization, field controls, rate limits, mismatch logging, and temporary PII redaction where needed.

ActiveLast revised 2026-06-30
TechWeb applicationAreaPatch prioritization
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
ShapedPlugin Pro supply-chain containmentCRT-2026-00082026.06.25Morning roundtable5 references

Treat reported ShapedPlugin Pro update-channel compromise as affected-site incident

Sites that installed or updated the reported affected ShapedPlugin paid Pro plugins during the reported April-to-June 2026 window should assume possible full compromise until integrity is proven; rotate WordPress admin, 2FA, SMTP/API/payment credentials and wp-config.php salts; inspect for hidden plugins, REST backdoors, unexpected file writes, and webshells; rebuild if integrity cannot be proven.

For sites that installed or updated the reported affected ShapedPlugin paid Pro plugins during the reported April-to-June 2026 window, treat the site as potentially compromised until integrity is proven. Rotate WordPress admin, 2FA, SMTP/API/payment credentials and wp-config.php salts; inspect for hidden plugins, REST backdoors, unexpected file writes, and webshells; rebuild if integrity cannot be proven. Keep exact window, patch, and CVE details caveated until primary advisory or vendor refs are attached.

ActiveLast revised 2026-06-25
TechWeb applicationAreaBreachPatch prioritizationSupply chain
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps

Unified Search

Search the public record.