malware Sneaky Windows stealer targets 300+ apps, gives crims an AI profiler to maximize profits A new Windows stealer, dubbed ‘Sneaky,’ is targeting over 300 applications, providing criminals with an AI profiler to maximize profits from stolen data. The malware leverages vulnerabilities in extensions to compromise… The Register · Jul 22, 2026 High malwareextensiondata theft
threat-intel LG to Ban Residential Proxies from Smart TV Apps LG Electronics USA is suspending smart TV apps that utilize residential proxy SDKs, following research by Spur which found that over 42% of apps on the webOS platform were incorporating these components. This allows thir… Krebs on Security · Jul 22, 2026 Medium residential proxyprivacysecurity
threat-intel Multiples vulnérabilités dans les produits Mozilla (22 juillet 2026) Multiple vulnerabilities have been discovered in Mozilla products. Some of these vulnerabilities allow an attacker to cause remote code execution, privilege escalation, and a denial-of-service. These vulnerabilities are… CERT-FR · Jul 22, 2026 High CVE-2026-15718CVE-2026-15719CVE-2026-16349vulnerabilityfirefoxsecurity
threat-intel Cisco's open-weight bug busters take on Google and OpenAI This article covers a variety of cybersecurity and technology news items, including Cisco's efforts to compete with Nvidia's AI hardware, a security breach involving Joomla extensions, and various other developments in t… The Register · Jul 21, 2026 Medium securitycybersecurityjoomla
threat-intel AI's cheatin' heart will make you weep This article covers a range of cybersecurity and technology news, including AMD's challenge to Nvidia in AI compute, security vulnerabilities in Joomla extensions, a Russian phishing campaign mimicking Signal support, an… The Register · Jul 21, 2026 Medium USIRSWcybersecurityphishingransomware
threat-intel Kratos phishing-as-a-service kit loses its battle with international law enforcement International law enforcement agencies have taken down a phishing-as-a-service kit operated by Russian threat actors, who were using it to launch attacks mimicking Signal support. The kit exploited vulnerabilities in Joo… The Register · Jul 21, 2026 Medium RUphishingjoomlaopen source
threat-intel Captive Portal Detection, (Tue, Jul 21st) This article details how operating systems and browsers detect captive portals – the splash screens that appear when connecting to public Wi-Fi networks. Instead of intercepting old non-TLS homepages, these systems now… SANS Internet Storm Center · Jul 21, 2026 Medium captive portalwifinetwork detection
threat-intel WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning A public exploit, dubbed ‘wp2shell,’ is being aggressively used to target vulnerable WordPress installations, leading to widespread scanning and exploitation. Attackers are leveraging two vulnerabilities – CVE-2026-63030… The Hacker News · Jul 21, 2026 High CVE-2026-63030CVE-2026-60137CHDEGBwordpressremote code executionexploit
vulnerability ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 21, 2026 Critical apachestrutsvulnerability
threat-intel Attackers pummel critical WordPress vuln to create all sorts of mischief This article covers a range of cybersecurity and technology news, including a vulnerability exploited to create mischief, a Russian phishing campaign mimicking Signal support, and a significant acquisition in the cyberse… The Register · Jul 20, 2026 Medium CVE-2026-63030CVE-2026-60137vulnerabilityphishingransomware
threat-intel 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover A newly discovered exploit chain, dubbed ‘WP2Shell,’ is rapidly being used to compromise millions of WordPress sites. Attackers are chaining together a SQL injection vulnerability (CVE-2026-60137) and a logic flaw in the… Dark Reading · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030sql injectionremote code executionwordpress
threat-intel Malicious cloud customers can bring down the power grid This article covers a range of cybersecurity and technology news, including a report on Russian phishing attacks posing as Signal support, a Microsoft SharePoint vulnerability, and a broader discussion about the evolving… The Register · Jul 20, 2026 Medium IRphishingvulnerabilityransomware
threat-intel WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) A critical WordPress webshell vulnerability (CVE-2026-63030) is being actively exploited. This vulnerability, stemming from a SQL injection flaw in the WordPress Core REST API, allows unauthenticated remote code executio… SANS Internet Storm Center · Jul 20, 2026 Critical CVE-2026-63030sql injectionwebshellwordpress
threat-intel WP2Shell WordPress Vulnerabilities Exploited in the Wild Two recently patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. Attackers are leveraging these flaws to gain remote code execution on WordPress site… SecurityWeek · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft
vulnerability Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution A critical vulnerability (CVE-2026-42533) in NGINX allows unauthenticated remote code execution, potentially due to a heap buffer overflow triggered by a specific configuration involving regex-based maps. The vulnerabili… The Hacker News · Jul 19, 2026 High CVE-2026-42533CVE-2026-42945CVE-2026-9256heap-overflowregexremote-code-execution
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability
vulnerability OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests A memory-exhaustion denial-of-service vulnerability, dubbed HollowByte, exists in OpenSSL versions 3.6.3, 3.5.7, 3.4.6, 3.0.21, 4.0.1, 3.6.2, and 3.6.3. The vulnerability stems from a flawed memory allocation process dur… The Hacker News · Jul 17, 2026 High CVE-2025-66199CVE-2026-34183memory-exhaustiondostls
threat-intel TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Researchers at Palo Alto Networks Unit 42 have uncovered TuxBot v3 Evolution, a developing IoT botnet framework leveraging AI assistance. While the LLM provided some code, it also introduced errors that needed manual cor… The Hacker News · Jul 15, 2026 High iotbotnetddos