HeadFlash

Security

Avada theme zero-click RCE chain exposes 1M+ sites; Gitea attacks active

Critical Avada and Gitea flaws under active exploitation, Norway hit by biggest-ever cyberattack, and EU officials targeted in Signal and WhatsApp spearphishing.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Critical Avada theme flaw enables zero-click remote code execution

A critical vulnerability chain in the Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code on servers, fully compromising websites. Tracked as CVE-2026-18431 with a 9.8 severity score, the exploit chains six security issues into a zero-click attack, targeting authorization, input-validation, trust-boundary, and file-handling weaknesses. Affected versions include Avada up to 7.16 and Fusion Builder plugin up to 3.16.

ThemeFusion released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 after Wordfence researchers discovered the chain using their internal agentic framework Argus, which developed proof-of-concept code in about two hours. Wordfence withheld complete technical details to give administrators time to update. Although Avada has more than 1 million sales, exploitation requires both vulnerable versions active, narrowing the pool of potential targets.

Critical Avada WordPress theme flaw enables zero-click RCE →

Hackers exploit critical Gitea flaw in code injection attacks, CISA adds to KEV

Attackers are actively exploiting a critical code injection vulnerability in Gitea, a self-hosted Git service, according to CISA. The flaw, CVE-2026-60004, allows an authenticated user with repository write access to execute arbitrary shell commands by submitting malicious patches via the diffpatch API endpoint. Default-configured instances have self-registration enabled, letting unauthenticated attackers register an account, create a repository, and trigger the vulnerability without prior credentials.

Gitea released version 1.27.1 on July 27 to address the issue. CISA added the flaw to its KEV catalog and ordered U.S. federal agencies to secure servers within three days, by August 28. Shadowserver tracks nearly 5,000 Gitea instances exposed online. The active exploitation reportedly involves deploying cryptocurrency mining malware on unpatched servers.

Hackers now exploit critical Gitea flaw in code injection attacks →

Pro-Russian group claims biggest-ever attack on Norway government services

A pro-Russian hacker group claimed responsibility for a cyberattack affecting multiple Norwegian government digital services over three days, which a state agency called the biggest attack it has ever experienced. The denial-of-service attacks began Monday, pushing massive traffic toward the Norwegian Digitalization Agency (Digdir) to block services, including a single-login system for public services. Digdir managed to keep services running practically all the time, said spokesperson Are Kvistad.

In a Telegram post, the group Server Killers claimed credit and declared cyber war on Norway after the country renewed security cooperation with Ukraine and pledged 85 billion Norwegian crowns ($9.2 billion) to Ukraine from next year’s budget. Norwegian officials did not comment on the claim. Norwegian media linked Server Killers to previous cyberattacks in Norway and other European countries.

Pro-Russian group claims credit for biggest-ever hack on Norway government services after $9.2 billion pledge to Ukraine →

State actors tried to hack EU officials’ Signal and WhatsApp accounts

State-sponsored actors have attempted to hack into Signal and WhatsApp accounts of EU officials, according to a confidential European Commission presentation obtained by Euronews. The Interinstitutional Cybersecurity Board acknowledged for the first time that state actors have engaged in spearphishing, using personalized messages to steal data or install malware. Attempts included trying to take over accounts of senior officials and using social engineering techniques referencing EU-related topics like sanctions.

More than 190 threat actors were reported targeting the EU ecosystem over the past 12 months, with eight significant incidents in the first half of 2026. The presentation also flagged a cloud data breach in late March 2026 after hackers compromised AWS accounts hosting parts of the Europa.eu website, plus vulnerabilities in productivity software and hardware. Challenges include differing digital signatures across EU bodies and no common platform for sensitive documents.

State actors tried to hack EU officials’ messaging apps, cybersecurity body warns →

Tap-to-pay charity scam can charge thousands instead of small donations

Scammers are using tap-to-pay charity requests to trick people into authorizing charges far larger than intended donations. In one version, a solicitor enters a much larger amount into a payment reader before the victim taps a phone or card; if the victim taps without checking the displayed amount, the larger transaction is authorized. Washington state reported cases where people agreed to donate $15 or $20 and later discovered charges of nearly $4,800 or $5,000.

Recommended protections include never handing a stranger an unlocked phone, reading the amount before tapping, avoiding high-pressure requests, researching charities independently, and turning on bank alerts. Victims should contact their bank immediately, save evidence, check all financial accounts, and report the scam to local law enforcement and the FTC at ReportFraud.ftc.gov.

Tap-to-pay charity scam can cost you thousands →