Hotel Wi-Fi DNS Hijack Campaign Steals Microsoft 365 Accounts
July 26, 2026 Threat actors are hijacking hotel and conference center Wi-Fi gateways to redirect business travelers to fake Microsoft 365 login pages. The campaign, active since at least June 2026, uses DNS manipulation and device-code authentication to…
RefluXFS CVE: Nine-Year-Old Linux Kernel Flaw Grants Root
July 23, 2026 A nine-year-old race condition in the Linux kernel’s XFS filesystem, tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on disk and gain persistent root access. The flaw, dubbed RefluXFS by Qualys,…
SharePoint CVE-2026-50522: Critical RCE Under Active Exploitation to Steal Machine Keys
July 22, 2026 Microsoft SharePoint administrators are racing to patch a critical remote code execution vulnerability that attackers are actively exploiting in the wild. The flaw, tracked as CVE-2026-50522, allows unauthenticated remote code execution…
ServiceNow CVE: Critical Pre-Auth RCE Exploit
July 21, 2026 A critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform is being actively exploited in the wild. The flaw, tracked as CVE-2026-6875, allows unauthenticated attackers to escape the JavaScript sandbox…
HelloNet APT Campaign Abuses ViPNet Update System
July 20, 2026 An advanced threat actor is abusing the update mechanism of ViPNet, a Russian-certified private networking suite, to implant persistent backdoors in government agencies and critical infrastructure across Russia. Dubbed HelloNet by Kaspersky…
wp2shell WordPress Core RCE: CVEs Enable Unauthenticated Code Execution
July 18, 2026 A critical pair of vulnerabilities in WordPress Core, dubbed wp2shell, enables unauthenticated remote code execution on millions of websites. The flaws are tracked as CVE-2026-63030 and CVE-2026-60137. They were patched in WordPress 6.9.5…
OpenSSL HollowByte DoS Flaw: 11-Byte Payload Freezes Server Memory
July 17, 2026 OpenSSL silently patched a denial-of-service vulnerability dubbed HollowByte that lets unauthenticated attackers freeze server memory with an 11-byte payload. There is no CVE assigned, no advisory published, and no changelog entry pointing…
CVE-2026-58644: CISA Adds SharePoint RCE Zero-Day to KEV Catalog
July 18, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-58644 to its Known Exploited Vulnerabilities (KEV) catalog on July 16, 2026. This critical Microsoft SharePoint Server flaw carries a CVSS score of 9.8 and…
Zoom CVE: Critical Account Takeover Vulnerability in Windows Desktop Client
July 15, 2026 Zoom has released security updates for a critical vulnerability in its Windows desktop client and SDK that could allow an unauthenticated attacker to hijack accounts over the network. The flaw, tracked as CVE-2026-53412, carries a CVSS…
SonicWall SMA1000 Zero-Day Exploitation
July 15, 2026 SonicWall has disclosed two actively exploited zero-day vulnerabilities in SMA1000 secure remote access appliances. Tracked as CVE-2026-15409 and CVE-2026-15410, both flaws carry a combined CVSS 10.0 severity rating. The U.S. Cybersecurity…