← Latest brief

Security news.

·Afternoon Brief

Today's cybersecurity landscape highlights a surge in active exploitation, particularly targeting WordPress, SharePoint, and Palo Alto Networks VPNs, with CISA adding several to its Known Exploited Vulnerabilities Catalog. Ransomware groups are quickly leveraging newly disclosed flaws, while AI continues to be a double-edged sword, assisting in both vulnerability discovery and new attack vectors.

BLEEPINGEXPLOIT
Jul 21READ

Critical wp2shell WordPress flaws actively exploited

Hackers are exploiting critical vulnerabilities CVE-2026-63030 and CVE-2026-60137 in WordPress Core to install persistent webshells and malicious plugins.

THNRCE
Jul 21READ

Critical SharePoint RCE (CVE-2026-50522) under active exploitation

A critical deserialization of untrusted data flaw in Microsoft Office SharePoint, patched in July 2026, is now being actively exploited following a public Proof-of-Concept.

BLEEPINGRANSOMWARE
Jul 21READ

Qilin ransomware exploiting critical Palo Alto VPN bug

The Qilin ransomware gang is leveraging a critical PAN-OS GlobalProtect authentication bypass flaw (CVE-2026-0257) to breach networks and deploy their ransomware.

CISAKEV
Jul 21READ

CISA adds four vulnerabilities to KEV Catalog

CISA has added CVE-2021-27137, CVE-2026-0770, CVE-2026-63030, and CVE-2026-60137 to its Known Exploited Vulnerabilities Catalog, urging immediate remediation.

BLEEPINGRANSOMWARE
Jul 21READ

Anubis ransomware claims Coca-Cola Fairlife attack

The Anubis ransomware group has taken credit for a cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to leak stolen data if a ransom is not paid.

THNVULN
Jul 21READ

AWS Kiro flaw allowed poisoned web pages to run code

A vulnerability in AWS's agentic coding IDE, Kiro, allowed hidden text on a web page to rewrite its configuration and execute attacker code on a developer's machine.

DARK READINGAI
Jul 21READ

Hacker turns AI jailbreaks into offensive attack platform

A Russian-speaking actor known as "Trim" has been observed integrating dismantled frontier AI models with offensive security tools to create an attack platform.

THNRANSOMWARE
Jul 21READ

New ENCFORGE ransomware targets AI model files

Researchers link a second attack on a Langflow server to the JADEPUFFER operator, now deploying ENCFORGE, a new Go ransomware designed to encrypt AI infrastructure files.

Generated twice daily from public security RSS feeds. Informational only.