Critical bug in CrowdStrike LogScale let attackers access files
2026-04-27T02:51:48Z•c291865c95a6bd69f184c4978a45d4744384f11512466ff9b525b948cf6f7f99
APTBreeze CacheCISACVECiscoCrowdStrikeFIRESTARTERGo malwareGopherWhisperKnown Exploited VulnerabilitiesLogScalePack2TheRootPackageKitSignalTrigonaWordPressbackdoordata exfiltrationexploitationpath traversalphishingprivilege escalationransomwareunauthenticated accessvulnerability
What happened
The feed aggregates multiple high-impact security stories: CrowdStrike patched a critical unauthenticated path traversal in LogScale (CVE-2026-40050) that could allow remote file reads; WordPress Breeze Cache plugin is being actively exploited via a critical file-upload flaw (CVE-2026-3844); a 12-year-old PackageKit privilege-escalation bug (Pack2TheRoot, CVE-2026-41651) enables local root escalation; CISA added several KEV entries including CVE-2024-7399; ESET disclosed a new China-aligned APT dubbed GopherWhisper targeting Mongolian government entities with Go-based loaders/backdoors; Syman
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c291865c95a6bd69f184c4978a45d4744384f11512466ff9b525b948cf6f7f99
- Enrichment time
- 2026-04-27T02:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.