Security news.
Today's cybersecurity news is dominated by widespread exploitation of recently disclosed vulnerabilities, with critical flaws in WordPress, ServiceNow, and Palo Alto VPNs now actively targeted. The evolving landscape of AI security also features prominently, highlighting new attack vectors and the risks associated with AI-generated code and agent-driven systems.
Critical Palo Alto VPN Bug Exploited by Qilin Ransomware
The Qilin ransomware gang is actively exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach networks.
WordPress 'wp2shell' Exploitation Grows
Attackers are increasingly exploiting critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) for unauthenticated remote code execution and website compromise.
ServiceNow AI Platform Vulnerability Exploited Days After Disclosure
A critical ServiceNow AI platform vulnerability (CVE-2026-6875) allowing unauthenticated remote code execution is now being actively exploited.
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Hackers exfiltrated personal, financial, and health information from Estée Lauder's Oracle EBS instance in August 2025 by exploiting a zero-day flaw.
Open-Source Android AI Agents Vulnerable to Invisible Screen Text Attacks
Researchers demonstrated how Android apps can trick AI agents into running commands on host PCs using invisible screen text, showcasing seven different attack chains.
HollowGraph Malware Abuses Microsoft 365 Calendar for C&C
A new espionage implant, HollowGraph, uses compromised Microsoft 365 accounts' calendars as a two-way dead-drop for command and control, leveraging legitimate Microsoft Graph API traffic.
New ENCFORGE Ransomware Targets AI Model Files
Researchers linked a second attack on a Langflow server to the JADEPUFFER operator, which is now deploying ENCFORGE, a new Go ransomware designed to encrypt AI infrastructure files.
AI-Generated Coding Risk Varies Significantly
AI-generated code introduces an average of 15 vulnerabilities per codebase, with risk levels heavily dependent on the chosen framework rather than the AI model itself.