Critical bug in CrowdStrike LogScale let attackers access files

2026-04-27T02:51:48Zc291865c95a6bd69f184c4978a45d4744384f11512466ff9b525b948cf6f7f99
APTBreeze CacheCISACVECiscoCrowdStrikeFIRESTARTERGo malwareGopherWhisperKnown Exploited VulnerabilitiesLogScalePack2TheRootPackageKitSignalTrigonaWordPressbackdoordata exfiltrationexploitationpath traversalphishingprivilege escalationransomwareunauthenticated accessvulnerability

What happened

The feed aggregates multiple high-impact security stories: CrowdStrike patched a critical unauthenticated path traversal in LogScale (CVE-2026-40050) that could allow remote file reads; WordPress Breeze Cache plugin is being actively exploited via a critical file-upload flaw (CVE-2026-3844); a 12-year-old PackageKit privilege-escalation bug (Pack2TheRoot, CVE-2026-41651) enables local root escalation; CISA added several KEV entries including CVE-2024-7399; ESET disclosed a new China-aligned APT dubbed GopherWhisper targeting Mongolian government entities with Go-based loaders/backdoors; Syman­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c291865c95a6bd69f184c4978a45d4744384f11512466ff9b525b948cf6f7f99
Enrichment time
2026-04-27T02:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.