wp2shell WordPress Core RCE: CVEs Enable Unauthenticated Code Execution
July 18, 2026 A critical pair of vulnerabilities in WordPress Core, dubbed wp2shell, enables unauthenticated remote code execution on millions of websites. The flaws are tracked as CVE-2026-63030 and CVE-2026-60137. They were patched in WordPress 6.9.5…
CVE-2026-58644: CISA Adds SharePoint RCE Zero-Day to KEV Catalog
July 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. This critical Microsoft SharePoint Server flaw carries a CVSS score of 9.8 and…
Zoom CVE: Critical Account Takeover Vulnerability in Windows Desktop Client
July 15, 2026 Zoom has released security updates for a critical vulnerability in its Windows desktop client and SDK that could allow an unauthenticated attacker to hijack accounts over the network. The flaw, tracked as CVE-2026-53412, carries a CVSS…
SonicWall SMA1000 Zero-Day Exploitation
July 15, 2026 SonicWall has disclosed two actively exploited zero-day vulnerabilities in SMA1000 secure remote access appliances. Tracked as CVE-2026-15409 and CVE-2026-15410, both flaws carry a combined CVSS 10.0 severity rating. The U.S. Cybersecurity…
CISA KEV Alert: Joomla iCagenda and Balbooa Forms Zero-Days Enable Unauthenticated RCE
July 13, 2026 CISA has added two maximum-severity Joomla extension flaws to its Known Exploited Vulnerabilities catalog after both were exploited as zero-days in the wild. CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms both score 10.0 on…
RedHook Android Malware Abuses Wireless ADB for Shell Access
July 12, 2026 Group-IB researchers have uncovered a major upgrade to the RedHook Android malware that abuses Wireless ADB to gain shell privileges on devices without needing a computer connection. Consequently, the threat significantly expands what…
Critical Gitea Docker Authentication Bypass Under Active Exploitation
July 10, 2026 A critical authentication bypass vulnerability in the official Gitea Docker image is under active exploitation just thirteen days after disclosure. Attackers can impersonate any user including administrators with a single crafted HTTP…
RoguePlanet CVE-2026-50656: Microsoft Defender SYSTEM Privilege Escalation Patched
July 10, 2026 Microsoft has finally released a security update for the RoguePlanet CVE-2026-50656 vulnerability. This flaw allowed local attackers to escalate privileges to SYSTEM level through a race condition in the Microsoft Malware Protection Engine.…
Injective SDK npm Supply Chain Attack: Crypto Wallet Keys Stolen via Compromised Package
July 9, 2026 Threat actors compromised a legitimate GitHub contributor account for the Injective Labs SDK project and published a malicious npm package that steals cryptocurrency wallet private keys and mnemonic seed phrases. The attack affected version…
TrojPix Attack Exfiltrates Data From Air-Gapped Systems via Video Cables
July 6, 2026 Researchers at Shandong University have unveiled TrojPix, a novel attack that leaks data from air-gapped systems by modulating video cable electromagnetic emissions. The technique achieves a peak throughput of 8.1 Mbps and reaches distances…