WordPress wp2shell Vulnerability (CVE-2026-63030): Quick FAQ for CISOs
WordPress wp2shell Vulnerability (CVE-2026-63030): Quick FAQ for CISOs WordPress patched wp2shell (CVE-2026-63030) on July 17, 2026, a critical pre-authentication RCE in core that lets an anonymous at...
FIFA World Cup 2026 Fraud Campaigns
FIFA World Cup 2026 Fraud Campaigns Between April and July 2026, the SOCRadar Threat Research Unit (STRU) tracked the fraud ecosystem built around the FIFA World Cup 2026 spanning counterfeit merchand...
CVE-2026-59208 Enables Cross-Issuer Impersonation in n8n
CVE-2026-59208 Enables Cross-Issuer Impersonation in n8n AI and workflow automation platforms can connect identities directly to actions across email, cloud services, databases, and other business sys...
July 2026 Patch Tuesday: 622 Vulnerabilities, 3 Zero-Days
July 2026 Patch Tuesday: 622 Vulnerabilities, 3 Zero-Days Microsoft released its July 2026 Patch Tuesday security updates on July 14, 2026, addressing 622 CVEs – one of the largest single releases on ...
SAP Security Patch Day July 2026 Fixes Critical NetWeaver CVE-2026-447...
SAP Security Patch Day July 2026 Fixes Critical NetWeaver CVE-2026-44747 On July 14, 2026, SAP released its monthly security updates, delivering 16 new Security Notes and one GitHub security advisory,...
How HalluSquatting Could Fuel Agentic Botnets
How HalluSquatting Could Fuel Agentic Botnets AI agents can make software development and automation faster, but they can also introduce a new supply chain risk. HalluSquatting, also known as adversar...
MDASH and AI Reshape Windows Patching
MDASH and AI Reshape Windows Patching Microsoft is planning to bring AI deeper into Windows vulnerability management through tools such as MDASH, an internal system designed to identify and validate s...
How WP-SHELLSTORM Exposed 1.4M WordPress Sites
How WP-SHELLSTORM Exposed 1.4M WordPress Sites The SOCRadar Threat Intelligence Team traces an exposed directory back to a Chinese-linked cybercrime operation and details findings from the investigati...
RoguePlanet Zero-Day Fixed in Microsoft Defender
RoguePlanet Zero-Day Fixed in Microsoft Defender Microsoft has patched RoguePlanet, a Microsoft Defender elevation-of-privilege zero-day vulnerability tracked as CVE-2026-50656. The flaw affects the M...
Ubiquiti Fixes CVE-2026-50746 in UniFi Connect
Ubiquiti Fixes CVE-2026-50746 in UniFi Connect Ubiquiti has released fixes for multiple vulnerabilities in the UniFi ecosystem under Security Advisory Bulletin 066 (SAB-066). The highest-severity issu...
BeyondTrust Fixes RS/PRA CVE-2026-40138 and More
BeyondTrust Fixes RS/PRA CVE-2026-40138 and More BeyondTrust has published security advisory BT26-03 for four vulnerabilities in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) appl...
What to Expect From the 2026 NATO Summit in Turkiye
What to Expect From the 2026 NATO Summit in Turkiye NATO leaders meet in Ankara, Turkiye on July 7–8 for what Secretary General Mark Rutte has called “maybe even more important than The Hague.” The Ha...
June 2026: FortiBleed Cracks Fortinet Firewalls, Supply Chain Worms Hi...
June 2026: FortiBleed Cracks Fortinet Firewalls, Supply Chain Worms Hit npm and PyPI June 2026 was headlined by FortiBleed, a Russian-attributed credential harvesting campaign that exposed over 86,000...
CISA Flags SharePoint RCE (CVE-2026-45659) for Active Exploitation
CISA Flags SharePoint RCE (CVE-2026-45659) for Active Exploitation CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities (KEV) catalog as of July 1, 2026, indicating active exploitation...
CVE-2026-8037: Progress Kemp LoadMaster RCE Exploited in the Wild
CVE-2026-8037: Progress Kemp LoadMaster RCE Exploited in the Wild A critical vulnerability tracked as CVE-2026-8037 affects Progress Kemp LoadMaster (Progress ADC / LoadMaster). The issue is a pre-aut...
Adobe ColdFusion and Campaign Classic: Critical RCE Flaws Among Multip...
Adobe ColdFusion and Campaign Classic: Critical RCE Flaws Among Multiple CVSS 10.0 Issues [Update] July 6, 2026: CVE-2026-48282 Reported as Exploited in the Wild Adobe has published two “Priority 1” s...
CVE-2026-8451 Adds a New NetScaler Memory Overread to the CitrixBleed ...
CVE-2026-8451 Adds a New NetScaler Memory Overread to the CitrixBleed Pattern Citrix has patched CVE-2026-8451, a vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The issue is an in...
CVE-2026-48558: SimpleHelp OIDC Auth Bypass Used to Deploy Infostealer...
CVE-2026-48558: SimpleHelp OIDC Auth Bypass Used to Deploy Infostealer Payloads CVE-2026-48558 is a critical authentication bypass affecting SimpleHelp, a remote support and RMM (remote monitoring and...
Klue Breach: What You Need to Know
Klue Breach: What You Need to Know The Klue breach shows how stolen OAuth tokens from a trusted SaaS integration can expose Salesforce CRM data. Learn what happened, which companies confirmed impact, ...
WhatsApp VBScript Campaign Installs ManageEngine Endpoint Central for ...
WhatsApp VBScript Campaign Installs ManageEngine Endpoint Central for Persistent Remote Access A newly reported malware campaign uses WhatsApp direct messages to deliver VBScript (VBS/VBE) attachments...