Tag: exploit
-
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/
-
‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover
-
Hugging Face Says Autonomous AI Agents Breached Data, Credentials
Tags: access, ai, cloud, credentials, cyberattack, data, exploit, flaw, framework, infrastructure, vulnerabilityAttackers Exploited Dataset Processing Flaws to Access Internal Clusters. Hugging Face said an autonomous AI agent framework exploited dataset processing vulnerabilities to compromise internal infrastructure, harvest cloud credentials and move laterally across clusters, exposing both the rise of agentic cyberattacks and the limits of AI safety guardrails during incident response. First seen on govinfosecurity.com Jump…
-
Researchers trace SonicWall SMA1000 exploitation to late June
Multiple threat actors, including INC ransomware, have targeted vulnerable firewall systems. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/researchers-sonicwall-sma1000-exploitation-june/825654/
-
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/
-
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Tags: ai, authentication, cve, exploit, intelligence, rce, remote-code-execution, threat, vulnerabilityAttackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/
-
Researchers Build WordPress Exploit Using OpenAI’s GPT
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/researchers-wordpress-exploit/
-
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
Tags: authentication, cyber, exploit, flaw, injection, rce, remote-code-execution, sql, vulnerability, wordpressA critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain using GPT-5.6 Sol Ultra during a multi-agent audit of the WordPress source code. GPT-5.6 Sol…
-
One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor
Tags: advisory, backdoor, cisa, cyber, data-breach, exploit, malicious, microsoft, remote-code-execution, update, vulnerabilityA newly disclosed cluster of Microsoft SharePoint Server vulnerabilities is actively being exploited in the wild, allowing attackers to convert a single crafted web request into full remote code execution and long-term persistence across enterprise environments. Security updates released in July 2026, alongside a CISA advisory, confirm that multiple vulnerabilities are already being weaponized against…
-
Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
-
Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks…
-
Weekly Cybersecurity Newsletter The 50 Biggest Cybersecurity Stories Microsoft Patch, AI Attack, Exploits Releases, Data Breaches More
Welcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 40 most important stories from July 1317, 2026. What a week: Microsoft shattered records with 570 vulnerabilities patched in a single Patch Tuesday, China-linked hackers weaponized Claude Code and DeepSeek against government networks, GPT-5.6 wrote a complete Chrome […]…
-
Furtex Linux Toolkit Uses io_uring and eBPF to Bypass EDR and Falco Detection
A newly published Linux toolkit named Furtex showcases a wide range of concepts related to post-exploitation, persistence, data access, and monitoring evasion. It is built around io_uring, eBPF, BPF maps, and raw system calls. The project includes over 100 tools organized into modules that cover asynchronous I/O operations, BPF inspection and manipulation, EDR evasion techniques,…
-
ACR Stealer exploits user interaction to steal sensitive data
First seen on scworld.com Jump to article: www.scworld.com/brief/acr-stealer-exploits-user-interaction-to-steal-sensitive-data
-
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations…
-
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026.Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this First…
-
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
-
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cybersecurity, exploit, flaw, fortinet, infrastructure, kev, microsoft, remote-code-execution, update, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog. This week, Microsoft’s July 2026 Patch Tuesday addressed the SharePoint remote code execution bug…
-
Inc Ransomware Exploits SonicWall SMA Zero-Days
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall’s mobile access appliances. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
-
CISA Adds FortiSandbox Bugs to KEV Catalog
Agencies Have Until Sunday to Patch Two Critical Command Injection Flaws. CISA added two critical FortiSandbox command injection vulnerabilities to its Known Exploited Vulnerabilities catalog after evidence of active attacks. Experts warn that unauthenticated remote code execution could let attackers compromise malware analysis systems and pivot deeper into enterprise networks. First seen on govinfosecurity.com Jump…
-
Attackers are Exploiting Trust in 2026, not Just Technology
Attackers are exploiting trust, not just technology, making continuous identity verification more critical than ever. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/attackers-are-exploiting-trust-in-2026-not-just-technology/
-
Kurz nach Microsoft-Patchday: Schadcode-Attacken auf Sharepoint-Server beobachtet
Angreifer nutzen eine kritische Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten ihre Systeme zügig absichern. First seen on golem.de Jump to article: www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint-luecke-wird-aktiv-ausgenutzt-2607-211000.html
-
Kurz nach Microsoft-Patchday: Kritische Sharepoint-Lücke wird aktiv ausgenutzt
Angreifer nutzen eine kritische Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten ihre Systeme zügig absichern. First seen on golem.de Jump to article: www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint-luecke-wird-aktiv-ausgenutzt-2607-211000.html
-
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/
-
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
NadMesh is a new, industrial”‘grade Go”‘based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed”‘loop platform. In early July 2026, researchers identified NadMesh as a high”‘volume Go-written botnet that was aggressively deploying bot agents across internet”‘facing…
-
TP-Link Kasa Camera Flaws Let Attackers Steal Admin Credentials and Geolocation Data
TP-Link has revealed several serious vulnerabilities affecting its Kasa EC70 and EC71 smart camera models, which could expose users to credential theft and geolocation data leakage. These vulnerabilities are CVE-2026-9770 and CVE-2026-13230 and specifically affect version 4 of both devices. Attackers with access to the same local network could exploit these flaws, raising concerns about…
-
CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cisa-urgent-patch-fortinet/
-
U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog
Tags: cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, microsoft, oracle, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall and Microsoft flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: The vulnerability CVE-2023-4346 (CVSS…

