Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations,
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Ravie LakshmananJul 19, 2026Malware / Cyber Warfare Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to
NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure
A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code
Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI
Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI
WordPress Core “wp2shell” RCE flaws get public exploits, patch now
Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Swati KhandelwalJul 17, 2026Vulnerability / Web Security An anonymous HTTP request can run code on a WordPress site. The bug
Abbott probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its