23Articles
8Categories
2026-07-18Date
🚨 CISA KEV 1[−]
18 Jul KEVU.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft ShareP…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 5[−]
18 JulCVE-2026-47729 Squid: Memory disclosure in FTP gatewayInformation published.MSRC.MICROSOFT.COM
18 JulTwo new high severity WordPress vulnerabilities, patch immediately!The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60…HELPNETSECURITY.COM
⚠️ VULNERABILITY DISCLOSURE 8[−]
18 JulOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS RequestsEleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no chan…THEHACKERNEWS.COM
18 JulNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeAn anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-u…THEHACKERNEWS.COM
18 JulAI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks. In this ep…CYBERSECURITYTODAY.LIBSYN.COM
18 JulWordPress releases emergency update for critical ‘wp2shell’ RCE flawThe WordPress project has released emergency security updates to fix a critical vulnerability chain dubbed wp2shell, that can allow unauthenticated attackers to achieve remote code execution (RCE) on vulnerable websites. The flaws affect WordPress 6.9 through 7.0.1 and have alrea…CYBERINSIDER.COM
18 JulNY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic DataThere’s another update in the litigation involving 23andMe, below, but this won’t be the last update, as California’s Attorney General has also recently sued them under California’s privacy laws. New York Attorney General Letitia James and a bipartisan coa…DATABREACHES.NET
18 JulWordPress Core "wp2shell" RCE flaws get public exploits, patch nowPublic exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...]BLEEPINGCOMPUTER.COM
18 JulUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. [...]BLEEPINGCOMPUTER.COM
18 JulOpenSSL Fixes HollowByte Memory Exhaustion BugOkta disclosed HollowByte, an 11-byte OpenSSL flaw that lets remote attackers exhaust server memory and trigger denial-of-service attacks. Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 byte…SECURITYAFFAIRS.COM
📢 SECURITY ADVISORIES 1[−]
18 JulThe Future of Age Verification: Your Face Never Leaves Your DeviceAs age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies age without transmitting or storing facial images, reducing biometric privacy risk…BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 3[−]
18 JulWhen trusted sites turn.Lauren Fievisohn⁠, Ph.D, Senior Threat Researcher from ⁠Silent Push⁠, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat act…THECYBERWIRE.COM
18 JulYour Period Tracker Is (Probably) Spying on YouPlus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more.WIRED.COM
18 JulDaxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s NetworkResearchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinati…SECURITYAFFAIRS.COM
🕵️ THREAT INTELLIGENCE 2[−]
18 JulNew North Korean campaign uses fake coding interviews to steal developer credentialsDPRK-aligned hackers hid malware inside SVG flag images to backdoor developer job interview coding tests. Not one antivirus vendor caught it.ELASTIC.CO
18 JulVoting Works Like AuthenticationThe voting process described uses identity verification, authorization checks, machine scanning, voter confirmation, and stored paper records. Security is not only about preventing digital attacks. Physical processes also rely on layered controls to verify who can participate and…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
18 JulSeven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RATCybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which wa…THEHACKERNEWS.COM
18 JulMicrosoft warns of surge in ACR Stealer attacks on customersMicrosoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]BLEEPINGCOMPUTER.COM
📡 INFOSEC NEWS 1[−]
18 JulPrompt Injection Attacks Are Thwarting AI Hacking Agents“Context bombing” tricks malicious AI agents into shutting down before they can do harm.WIRED.COM