Find notable cyber news and cases, enriched with sources, timelines, and signals.

WSO2 API Manager JWT signature bypass (CVE-2026-5430)

Vulnerability
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

Active exploitation of CVE-2026-5430 in WSO2 API Manager puts API Control Plane, Traffic Manager, and Universal Gateway deployments at risk of account takeover and unauthorized access.

Related Happenings

CISA KEV listing and FCEB remediation deadline for Oracle CVE-2026-21962

Public Sector Action
H score49 First: 25.08.2026 09:12 Last: 25.08.2026 09:12 Sources 1

About this happening: CISA added CVE-2026-21962 to the KEV catalog and set a remediation deadline for FCEB agencies, tightening federal exposure to an actively exploited Oracle flaw. Th...

Evooo1Bot modular Linux botnet activity

Malware Activity
H score33 First: 14.08.2026 16:00 Last: 14.08.2026 16:00 Sources 1

About this happening: Evooo1Bot is a new modular Linux botnet that Fortinet says has been active since July 2026 and uses Mirai-derived code to compromise internet-facing edge devices...

Latest development: 15.08.2026 17:14

Fortinet says Evooo1Bot targets internet-facing gateway devices and newer builds add an exploitation module for Hikvision cameras, Atlassian Confluence, Zyxel firewalls, TP-Link routers, D-Link NAS devices, WSO2 products, Kubernetes ingress-nginx, and vulnerable PHP-CGI installations. The malware reuses the Mirai DDoS engine, uses encrypted C2 over port 443, includes an SSH brute-force scanner, a SOCKS relay module, and a credential sniffer that monitors /proc/net/tcp.

BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances

Malware Activity
H score29 First: 18.02.2026 12:32 Last: 18.02.2026 12:32 Sources 1

About this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...

Timeline

  1. 16.09.2026 08:18 2 articles · 2h ago

    watchTowr honeypot captures forged admin JWTs for WSO2 API Manager

    Exploitation Observed

    watchTowr's honeypot network captures forged JWT tokens with baked-in administrator privileges against WSO2 API Manager, showing active exploitation of CVE-2026-5430 and suggesting the tokens could be used to reach API backend endpoints, credentials, consumer keys, and secrets for registered applications.

    Show sources
  2. 16.09.2026 08:18 1 articles · 2h ago

    WSO2 releases fixes for CVE-2026-5430 across API Manager products

    Mitigation Patch Update

    WSO2 releases fixes for CVE-2026-5430 for WSO2 API Manager, WSO2 API Control Plane, WSO2 Traffic Manager, and WSO2 Universal Gateway, with community pull requests and support update levels available for affected versions and guidance to apply the fixes as soon as possible to reduce JWT signature bypass risk and account takeover exposure.

    Show sources