← Latest brief

Security news.

·Morning Brief

Today's security news highlights critical vulnerabilities and active exploitation, urging immediate action from developers and IT teams. Patches are vital for WordPress, 7-Zip, and Windows, while threat actors continue to evolve their tactics with new malware and supply chain attacks.

BLEEPINGRCE
1d agoREAD

WordPress Core "wp2shell" RCE Flaws Get Public Exploits

Public exploits are now available for critical "wp2shell" remote code execution vulnerabilities in WordPress Core (versions 6.9 and 7.0), making immediate patching crucial for all administrators.

BLEEPINGRCE
1d agoREAD

7-Zip Fixes RCE Flaw Exploitable with Malicious Archives

7-Zip version 26.02 has been released to address a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files.

BLEEPINGZERO-DAY
2d agoREAD

New Windows LegacyHive Zero-Day Grants Admin Privileges

A security researcher has released a Windows zero-day exploit, dubbed LegacyHive, allowing attackers to escalate privileges on up-to-date Windows systems.

BLEEPINGBREACH
1d agoREAD

Microsoft Warns of Surge in ACR Stealer Attacks

Microsoft has observed a significant increase in attacks utilizing the ACR Stealer malware to exfiltrate browser-stored passwords, authentication tokens, and sensitive documents from enterprise customers.

DARK READINGRANSOMWARE
2d agoREAD

Inc Ransomware Exploits SonicWall SMA Zero-Days

The Inc Ransomware group is actively exploiting two chained zero-day vulnerabilities in SonicWall's mobile access (SMA) appliances, allowing threat actors to gain root-level capabilities.

CISAKEV
3d agoREAD

CISA Adds Three Known Exploited Vulnerabilities to KEV Catalog

CISA has added CVE-2026-25089, CVE-2026-39808 (Fortinet FortiSandbox OS Command Injection), and CVE-2026-58644 (Microsoft SharePoint Deserialization of Untrusted Data) to its KEV Catalog, based on evidence of active exploitation.

THNVULN
2d agoREAD

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

A denial-of-service vulnerability dubbed "HollowByte" in OpenSSL can cause unpatched servers to allocate up to 131 KB of memory with a mere 11-byte malicious TLS request.

THNSUPPLY CHAIN
2d agoREAD

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Researchers have discovered seven malicious npm packages targeting the Vite frontend tooling ecosystem, part of a software supply chain attack dubbed "ViteVenom" using a four-tier blockchain-based command-and-control (C2) infrastructure.

Generated twice daily from public security RSS feeds. Informational only.