Security news.
Today's cybersecurity landscape is marked by urgent patching for critical vulnerabilities in widely used software and active exploitation campaigns. Threat actors are leveraging zero-days in SonicWall SMA appliances, weaponizing WordPress flaws, and deploying sophisticated malware with nation-state backing.
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor, UTA0533, exploited zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances prior to their public disclosure, gaining root access.
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released on June 25 to address a remote code execution vulnerability that allows attackers to execute malicious code via specially crafted compressed files.
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits are now available for critical "wp2shell" remote code execution vulnerabilities in WordPress Core, making immediate patching essential for all administrators.
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a significant increase in attacks leveraging the ACR Stealer malware to exfiltrate browser-stored passwords, authentication tokens, and sensitive documents from enterprise customers.
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is exploiting the update mechanism of the ViPNet private networking product suite to target Russian organizations, including government agencies.
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors, attributed to UAC-0145 (a Sandworm sub-cluster), are using the ClickFix strategy to trick Ukrainian targets into installing data-stealing malware.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added CVE-2026-25089 and CVE-2026-39808 (Fortinet FortiSandbox OS Command Injection) and CVE-2026-58644 (Microsoft SharePoint Deserialization of Untrusted Data) to its KEV Catalog, urging immediate remediation due to active exploitation.
New Windows LegacyHive zero-day gives hackers admin privileges
A new Windows zero-day exploit, "LegacyHive," allows attackers to escalate privileges on up-to-date Windows systems.