Microsoft says attackers are exploiting SharePoint flaw CVE-2026-65660, roughly six weeks after it shipped a fix in August. Any server still missing that update should be treated as possibly compromised, checked for webshells and patched.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 68%
- Investor
- Investor 6%
Reality
- Evidence74
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence70
CVE-2026-5430 lets a token signed with an algorithm WSO2 does not support pass authentication as an administrator. watchTowr says tokens with administrator privileges baked in reached its honeypots on September 13.
Reality
- Evidence68
- Adoption20
- Hype gap+25
- Incentives45
- Confidence65
WSO2 published the fix in May. watchTowr saw forged tokens arrive at its honeypot in September. Its own replay against a correctly targeted deployment came back with the credentials the gateway holds.
Publishers:dev.to · security.docs.wso2.com Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence62
Setting 5 requests per 60 seconds in Bijira's console took a form field and a dropdown. Working out what the gateway meant by 60 seconds took two corrected conclusions and a header that read 57 where a rolling window would have read 60.
Reality
- Evidence66
- Adoption10
- Hype gap−12
- Incentives32
- Confidence55
FortiGuard Labs says Evooo1Bot packs SOCKS5 relaying, credential sniffing, SSH spreading and 16 flood modes into one binary across 12 CPU architectures. The tunnel matters more than the flood.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+18
- Incentives58
- Confidence42