One in three websites just got a skeleton key
Searchlight Cyber disclosed a pre-authentication remote code execution flaw in WordPress Core itself. Not a plugin, not a theme, but the platform that runs an estimated 500 million-plus websites. Dubbed wp2shell, the attack has no preconditions: an anonymous user can exploit a stock install with no plugins at all.
Meanwhile, Group-IB uncovered HOLLOWGRAPH, a Windows malware strain that quietly turns Microsoft 365 calendar entries into a command-and-control channel, sending instructions to infected machines and stealing files without ever touching an attacker-controlled server. One is a mass-exploitation event waiting to happen. The other is a reminder that your trusted SaaS tools can be repurposed against you.
Searchlight Cyber's security research team has discovered a pre-authentication RCE in WordPress Core. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins. It is estimated that over 500 million websites use WordPress
https://wp2shell.com/
Microsoft blocked the rollout of Windows 11's latest Patch Tuesday update for a number of Dell PCs after it was reported that the update clashed with Intel's IPF driver, causing a number of issues including unexpected shutdowns, overheating, and slow performance.
https://www.windowscentral.com/microsoft/windows-11/microsoft-issues-emergency-windows-11-kb5121767-update-to-address-unexpected-shutdowns-and-overheating-on-certain-dell-pcs
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 and 1.31.3, as well as NGINX Plus 37.0.3.1. Triggering the flaw can crash or restart the worker, causing denial of service; where ASLR is disabled or can be bypassed, F5 says it may also allow remote code execution. The overflow lives in nginx’s script engine, surfacing only under a specific configuration: a regex-based map whose output variable is referenced in a string expression after a capture from an earlier regex match.
https://bitnewsbot.com/critical-nginx-flat-allows-unauthenticated-remote-code/
A denial-of-service (DoS) vulnerability named 'HollowByte' was identified in unpatched OpenSSL servers, allowing an attacker to allocate up to 131 KB of memory per process with an 11-byte TLS request. The flaw, reported by Okta's Red Team, causes memory exhaustion until the affected process restarts, particularly on glibc-based systems. OpenSSL released a fix in June 2026 without assigning a CVE, issuing an advisory, or documenting the change in the changelog. No remote code execution or authentication requirements were mentioned, but the impact is limited to service disruption. The vulnerability was addressed silently in the patch.
https://www.cyberhub.blog/article/29287-hollowbyte-dos-vulnerability-discovered-in-unpatched-openssl-servers
Researchers from Pennsylvania State University and Idaho National Laboratory will discuss their findings in a session called "Blind Trust in the 6 GHz Band: Weaponizing Wi-Fi Automated Frequency Coordination (AFC)" at Black Hat USA 2026. Two pieces of technology are at the center of this research: the cutting edge 6 GHz Wi-Fi spectrum and AFC, which regulates the 6 GHz band and keeps its powerful signal from interfering with radio towers, cellular backhaul, and spectrum-adjacent public safety networks.
https://www.darkreading.com/perimeter/6-ghz-wi-fi-flaws-disrupt-critical-systems
CVE-2026-14440, formerly tracked as NotCVE-2026-0001: a Cloudflare Universal SSL / CAA / RFC 8657 vulnerability in which Cloudflare's authoritative DNS can serve an auto-managed CAA RRset that supersedes customer-configured CAA records at query time. As a result, RFC 8657 accounturi and validationmethods protections are not enforced end-to-end on affected Universal SSL zones. If a domain relies on those CAA constraints, it remains exposed to this scenario while it stays in the vulnerable Universal SSL automatic CAA management mode.
https://david-osipov.vision/en/blog/cybersecurity/cloudflare-ssl-mitm-flaw-2026/
More than 1 million email attacks were detected since April 2026 using text salting techniques to bypass keyword-based email security scans, including AI tools. Text salting involves filling an email’s source code with hidden content containing benign keywords to avoid being classified as spam by security scanners, such as large language model (LLM) based scanners. Automated scanners will read all of the text in the email, including the hidden content, while human users will only see the portion of the email containing the phishing attempt, luring them to click on a malicious link or divulge sensitive information.
https://www.scworld.com/news/over-1-million-malicious-emails-found-using-text-salting-to-fool-ai-scanners
Egyptian full-stack developer ZedAxis (@M-Abozaid on GitHub) has already built one. Using an ESP32-C3 "SuperMini" board, he's created a backup DNS for his home network that still provides ad blocking. His primary router is a Pi-hole, which is a Raspberry Pi running specialized software to manage DHCP addressing and DNS resolution with integrated ad-blocking.
https://www.tomshardware.com/networking/clever-hacker-fits-537-000-domains-in-a-tiny-usd5-esp32-ad-blocking-dongle-firmware-uses-only-around-50kb-of-ram-and-can-answer-blocked-lookups-in-10-milliseconds
Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026. A standard user creates a Wallet ESE database containing a persisted callback and redirects their Documents known folder to it. Vulnerable WalletService opens the database as LocalSystem with persisted callbacks enabled, causing ESE to load the supplied DLL. The payload starts a command prompt as SYSTEM in the active desktop session.
https://github.com/DavidCarliez/CVE-2026-49176_LPE_POC
A newly discovered Windows malware strain called HOLLOWGRAPH represents exactly this evolution. According to research from Group-IB, attackers have transformed Microsoft 365 calendar functionality into a hidden command-and-control (C2) system, allowing them to send instructions to infected machines and steal sensitive files without relying on traditional attacker-controlled servers.
https://undercodenews.com/hollowgraph-the-windows-malware-that-turned-microsoft-365-calendars-into-a-secret-spy-network-video
Researchers have identified a previously unknown IoT botnet framework called TuxBot v3 Evolution, which appears to have been developed with the assistance of a large language model. The involvement of a large language model in the development of this botnet framework is notable, as it suggests a new approach to creating malicious code. However, the results of this collaboration were not entirely successful, as the generated code included a safety feature that may have hindered its effectiveness.
https://happeningnow.news/s/tuxbot-v3-evolution-shows-signs-of-llm-assisted-io-83ec01
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. WSUS was introduced almost twenty years ago to help IT administrators schedule updates for Microsoft products on enterprise networks from a single local update server, rather than updating each endpoint directly from Redmond's servers.
https://www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's primary foreign military intelligence agency.
https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware.
https://www.bleepingcomputer.com/news/security/new-u-boot-flaws-could-enable-stealthy-firmware-attacks/
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. Between late April and mid-June, the threat actor used the ClickFix social-engineering method, WebDAV servers, and the MSHTA (Microsoft HTML Application Host) utility to deliver the info-stealing payload.
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/
Coca-Cola, which owns Fairlife, announced Thursday that its dairy company had identified “unauthorized access by a third party” to a portion of its systems, including those related to production. The company disclosed that this was in connection to a ransomware event — and in response, it took some operations offline. “Product quality and safety have not been impacted,” Atlanta-based Coca-Cola said in a statement. “However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended.”
https://apnews.com/article/fairlife-milk-cyberattack-cocacola-e3a5574043f58a7340500c89d74c2ba6