ZeroHour
SecurityWeekpublished ()ingested SecurityWeek News2

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

mediumIndustry exploited in the wildimportance 45CVE-2026-14894
AI summary · glm-5.3-flash

SecurityWeek weekly roundup covers exploited WordPress Super Forms flaw CVE-2026-14894, a $10M bounty on an Iranian cyber official, InjectEave attacks, and more.

SecurityWeek's weekly roundup aggregates short items across the threat landscape, including Microsoft's report of invisible Unicode tag characters used in financial phishing lures at up to 2.37 million messages per day, and active exploitation of critical WordPress Super Forms plugin flaw CVE-2026-14894 to deploy PHP webshells. Policy items include a $10 million US bounty for IRGC-CEC Cyber Operations Command lead Amir Yaryab, a 16-month prison sentence for ex-AT&T employee Kenneth Carter over SIM swaps with nearly $600,000 in intended losses, and the US arraignment of Russian Sergei Anatolyevich Filimonov over credential harvesting. Technical items include InjectEave electromagnetic side-channel attacks tested on 11 devices, an FBI warning on OAuth consent phishing, and VulnCheck's finding that only 202 of 26,153 Anthropic Project Glasswing findings were fixed.

  • Attackers exploit CVE-2026-14894 in WordPress Super Forms to upload PHP webshells; update to 6.3.314
  • Microsoft: invisible Unicode tag characters used in phishing lures at up to 2.37M messages per day
  • US offers $10M bounty for IRGC-CEC Cyber Operations Command lead Amir Yaryab
  • VulnCheck: only 202 of 26,153 Project Glasswing findings fixed; Claude rated 91.5% high or critical vs 51.3% by maintainers
  • InjectEave EM side-channel attacks recovered private audio and appliance states from 11 tested devices

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-14894
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the sub

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.

NVD description · AI analysis pending
9.85%
  • WordPress
Full article705 words · extracted from securityweek.com · click to collapse

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape.

This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers stay well-informed about the evolving cybersecurity environment.

Here are this week’s highlights: 

Invisible Unicode slips past phishing filters

Microsoft says attackers are using invisible Unicode tag characters, a technique associated with AI prompt injection (ASCII Smuggling), to evade phishing detection. In a campaign tracked from February through June, the characters were inserted into financial lure terms such as “funding,” generating as many as 2.37 million messages per day and potentially disrupting ML- and NLP-based filtering.

WordPress Super Forms flaw under attack

Advertisement. Scroll to continue reading.

Attackers are exploiting CVE-2026-14894, a critical flaw in the WordPress Super Forms plugin that allows unauthenticated arbitrary file uploads. Exploitation can be used to upload and execute PHP webshells, potentially giving attackers complete control of affected sites. Users are advised to update to version 6.3.314.

US puts $10 million bounty on Iranian cyber official

The US is offering up to $10 million for information leading to the identification or location of Amir Yaryab, an IRGC-CEC official who leads its Cyber Operations Command. US authorities say groups under his direction have targeted critical infrastructure across sectors including defense, energy, financial services, telecommunications, shipping and travel, while affiliated groups such as CyberAv3ngers have used malware against civilian infrastructure worldwide.

CISA updates insider threat playbook

CISA has released an updated insider threat guide covering measures to mitigate both physical and cyber threats posed by insiders, addressing aspects such as remote work and AI advancements. The guide is designed to help organizations develop or improve their insider threat program. 

FBI warns of consent phishing 

The FBI is warning that threat actors are using OAuth consent phishing to gain persistent access to victims’ accounts without stealing their passwords. Attackers impersonate trusted figures and direct targets to malicious applications that request legitimate-looking permissions, allowing them to access email, files and other data. 

Deep ties between Chinese hacking group QTFY and military contractors

A new analysis from Natto Thoughts expands on a joint US advisory linking China-based hacking group QTFY to Nanjing Xinjiuwei Network Technology Co. (XJW), highlighting ties involving ELEX and Nanjing Lexbell Information Technology. The analysis says ELEX’s historical client lists included MSS, Ministry of Public Security and PLA-affiliated entities, while Lexbell has military-focused products, PLA-linked leadership and contracts with the National University of Defense Technology.

Ex-AT&T employee sentenced to prison for SIM swapping

Former AT&T employee Kenneth Carter was sentenced to 16 months in prison for using his access to perform SIM swaps that helped criminals take over customers’ bank accounts. Three victims suffered intended losses of nearly $600,0000, with Carter typically receiving $1,000 to $2,000 for each fraudulent SIM swap.

Russian accused of running cybercrime infrastructure

Russian national Sergei Anatolyevich Filimonov was extradited from Georgia and arraigned in the US over an alleged credential-harvesting and bank fraud operation targeting US banking customers. Prosecutors say fake financial websites and sponsored search results directed victims to phishing sites, while infrastructure allegedly maintained by Filimonov stored more than 5,000 stolen credentials and supported attempts to steal millions of dollars.

InjectEave attack turns devices into eavesdropping targets

Researchers demonstrated InjectEave, a new class of electromagnetic side-channel attacks in which an external RF signal induces hardware nonlinearities that leak low-frequency analog information. Tests on 11 commercial devices, including headphones, VoIP phones, smart fans and lamps, showed that attackers could recover private audio or determine appliance states without physical access or modifying the devices.

Glasswing findings face a reality check

VulnCheck’s review of Anthropic’s Project Glasswing ledger found that only 202 of 26,153 claimed findings had been fixed after nearly five months, while 245 had been withdrawn. It also found a significant gap between Claude’s severity assessments and those of maintainers: Claude rated 91.5% of findings with available ratings as high or critical, compared with 51.3% from maintainers.

Related: In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

Related: In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/in-other-news-injecteave-attack-sim-swapper-sentenced-glasswing-findings-review/