Security news.
Today's cybersecurity landscape highlights a surge in active exploitation, particularly targeting WordPress, SharePoint, and Palo Alto Networks VPNs, with CISA adding several to its Known Exploited Vulnerabilities Catalog. Ransomware groups are quickly leveraging newly disclosed flaws, while AI continues to be a double-edged sword, assisting in both vulnerability discovery and new attack vectors.
Critical wp2shell WordPress flaws actively exploited
Hackers are exploiting critical vulnerabilities CVE-2026-63030 and CVE-2026-60137 in WordPress Core to install persistent webshells and malicious plugins.
Critical SharePoint RCE (CVE-2026-50522) under active exploitation
A critical deserialization of untrusted data flaw in Microsoft Office SharePoint, patched in July 2026, is now being actively exploited following a public Proof-of-Concept.
Qilin ransomware exploiting critical Palo Alto VPN bug
The Qilin ransomware gang is leveraging a critical PAN-OS GlobalProtect authentication bypass flaw (CVE-2026-0257) to breach networks and deploy their ransomware.
CISA adds four vulnerabilities to KEV Catalog
CISA has added CVE-2021-27137, CVE-2026-0770, CVE-2026-63030, and CVE-2026-60137 to its Known Exploited Vulnerabilities Catalog, urging immediate remediation.
Anubis ransomware claims Coca-Cola Fairlife attack
The Anubis ransomware group has taken credit for a cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to leak stolen data if a ransom is not paid.
AWS Kiro flaw allowed poisoned web pages to run code
A vulnerability in AWS's agentic coding IDE, Kiro, allowed hidden text on a web page to rewrite its configuration and execute attacker code on a developer's machine.
Hacker turns AI jailbreaks into offensive attack platform
A Russian-speaking actor known as "Trim" has been observed integrating dismantled frontier AI models with offensive security tools to create an attack platform.
New ENCFORGE ransomware targets AI model files
Researchers link a second attack on a Langflow server to the JADEPUFFER operator, now deploying ENCFORGE, a new Go ransomware designed to encrypt AI infrastructure files.