threat-intel 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover A newly discovered exploit chain, dubbed ‘WP2Shell,’ is rapidly being used to compromise millions of WordPress sites. Attackers are chaining together a SQL injection vulnerability (CVE-2026-60137) and a logic flaw in the… Dark Reading · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030sql injectionremote code executionwordpress
threat-intel 25 Years After Code Red: What the Worm Era Can Teach Us About AI Security Twenty-five years after the Code Red worm, a pivotal moment in cybersecurity history, experts are drawing parallels to the current rush towards AI adoption. The article highlights how Code Red exploited a widespread, oft… Dark Reading · Jul 20, 2026 Medium CHaisecurityvulnerability
threat-intel CISOs Feel the Heat Over AI Risk CISOs are facing increased pressure and job insecurity due to the rapid and often chaotic adoption of AI within companies. A recent Splunk survey revealed that 26% of top security executives are considering leaving their… Dark Reading · Jul 20, 2026 High aicybersecurityrisk
threat-intel Attackers Combo Up Evasion Tactics for BEC Phishing Attackers are employing increasingly sophisticated evasion techniques to deliver BEC phishing attacks, utilizing a multi-stage process involving disguised font files, Lua interpreters, and fileless execution to bypass en… Dark Reading · Jul 20, 2026 High phishingbecevasion
threat-intel FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware A sophisticated campaign dubbed FakeGit has leveraged nearly 7,600 malicious GitHub repositories to spread SmartLoader malware, utilizing AI agents to discover these fake repositories and execute the attack. The campaign… The Hacker News · Jul 20, 2026 High aigithubmalware
threat-intel Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign A cybercriminal, utilizing AI coding tools and a sophisticated pipeline, exposed a comprehensive phishing toolkit targeting Mexican users and beyond. The operator, likely leveraging LLMs and tools like Coderrr, created a… The Hacker News · Jul 20, 2026 High CVE-2025-33053CVE-2026-21513CVE-2025-24054MXUSDEphishingwebdavai
threat-intel Mythos Didn't Break Your Security Program. Your Exposure Window Could. The vulnerability landscape is exploding, with a projected 66,000 new CVEs in 2026, and many organizations struggle to remediate them due to slow mobilization processes. The gap between vulnerability disclosure and actua… The Hacker News · Jul 20, 2026 High vulnerabilitiesexposure windowattack path analysis
threat-intel Hugging Face Hacked in Autonomous AI Attack Hugging Face, a popular AI collaboration platform, suffered a data breach orchestrated by an autonomous AI agent. The attackers exploited vulnerabilities within their data processing pipeline to gain unauthorized access… SecurityWeek · Jul 20, 2026 High aiautonomousattack
supply-chain SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines A sophisticated supply chain attack, dubbed SleeperGem, has been targeting Ruby developers through three previously dormant malicious RubyGems packages. These packages, including a fake Git Credential Manager, were updat… The Hacker News · Jul 20, 2026 High rubysupply chainmalware
vulnerability Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution A critical vulnerability (CVE-2026-42533) in NGINX allows unauthenticated remote code execution, potentially due to a heap buffer overflow triggered by a specific configuration involving regex-based maps. The vulnerabili… The Hacker News · Jul 19, 2026 High CVE-2026-42533CVE-2026-42945CVE-2026-9256heap-overflowregexremote-code-execution
threat-intel New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh is actively targeting exposed AI services and cloud infrastructure, specifically seeking AWS keys, Kubernetes tokens, and Docker API access. The botnet, discovered by XLab and previously identi… The Hacker News · Jul 17, 2026 High CVE-2026-39987CVE-2026-41176CVE-2022-22947botnetcloud-securitydocker
threat-intel Google Bets 'Agentic Defense' Strategy Can Outpace Attackers Google is implementing an ‘agentic defense’ strategy, leveraging its acquisition of Wiz to automate threat detection and response in a rapidly evolving cybersecurity landscape. This involves deploying AI-powered agents a… Dark Reading · Jul 17, 2026 High UNCHaicloud securitygraph analysis
threat-intel AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report Unit 42’s 2026 Global Incident Response Report indicates that while AI is increasingly being used by attackers to speed up attacks and streamline operations – like malware development and command-and-control – the fundam… Palo Alto Unit 42 · Jul 16, 2026 Medium UNaicybersecuritythreat intelligence
threat-intel 1M+ Emails Use Hidden Text to Dupe AI Security Filters Hackers are using a simple, age-old technique – text salting – to bypass modern email security filters, including those powered by AI. Researchers at Barracuda Networks observed over 1 million retail-themed phishing emai… Dark Reading · Jul 16, 2026 Medium phishingtext-saltingai-security
threat-intel New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands Researchers at Seoul National University, the University of Illinois Urbana-Champaign, and Largosoft have discovered a new attack method called Agent Data Injection (ADI) that can manipulate AI agents by subtly corruptin… The Hacker News · Jul 16, 2026 High CVE-2025-32711prompt-injectiondata-exfiltrationai-security
threat-intel Police Disrupt a €140M Cyber Fraud Ring in Spain Spanish police disrupted a €140 million cyber fraud ring operating across multiple countries, involving over 70 individuals and a complex network of money laundering. The operation involved sophisticated techniques like… Dark Reading · Jul 16, 2026 High SPPOPAcybercrimefraudmoney laundering
vulnerability Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Several cybersecurity firms, including Trend Micro, Tenable, ESET, and Palo Alto Networks, have released patches to address critical vulnerabilities in their products. These vulnerabilities range from local privilege esc… SecurityWeek · Jul 16, 2026 High CVE-2026-15265vulnerabilitypatchsecurity
threat-intel OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop softwa… The Hacker News · Jul 15, 2026 High BRVNCAphishingmalwarehardware wallet
threat-intel Claude Flaw Automatically Sends Malicious Prompts to AI Agents A vulnerability, dubbed ‘PromptFiction,’ has been discovered in Anthropic’s Claude Desktop application, allowing attackers to automatically submit malicious prompts to the AI assistant with a single click, bypassing the… Dark Reading · Jul 15, 2026 High prompt-injectionai-securityuri-scheme
threat-intel Dutch police dismantle global crypto investment scam, arrest alleged mastermind Dutch police have dismantled a global cryptocurrency investment scam involving over 700 employees operating from dozens of call centers across multiple countries. The operation, led by a ‘well-known hacker’ with Israeli… The Record · Jul 15, 2026 High NEPOBEcryptocurrencyfraudscam