An aggressive social engineering technique has been used by ClickLock, an information-stealing macOS malware, to obtain victims’ information about their system login passwords. Security researchers at Group-IB report that the malware disables normal system functionality, leaving users with little interaction…
Two new high severity WordPress vulnerabilities, patch immediately!
The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137…
GigaWiper
When Malware Doesn’t Have to Choose Between Espionage and Destruction This article has been indexed from CyberMaterial Read the original article: GigaWiper
Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a…
IT Security News Hourly Summary 2026-07-18 15h : 2 posts
2 posts were published in the last hour 13:4 : New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours 12:8 : U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its…
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from the initial breach to full network encryption in under 24 hours. The…
U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV)…
wp2shell – Code Trace Deep Dive
wp2shell carries two CVEs (so far); CVE-2026-63030 & CVE-2026-60137. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: wp2shell – Code Trace Deep Dive
Your Period Tracker Is (Probably) Spying on You
Plus: Russian cyberspies turn to infrastructure hacking, DHS repeatedly fails to realize it’d been hacked, a breach exposes an AI music generator’s scraping ways, and more. This article has been indexed from Security Latest Read the original article: Your Period…
IT Security News Hourly Summary 2026-07-18 12h : 3 posts
3 posts were published in the last hour 9:34 : WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 9:34 : Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation 9:5 : Critical WordPress Core…
WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030
The CVE-2026-63030 – “wp2shell”: Why Millions of WordPress Sites Are Vulnerable and Emergency to Patch If you run… The post WP2Shell: Why Millions of WordPress Sites Are at Risk | CVE-2026-63030 appeared first on Hackers Online Club. This article has…
Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged attackers to gain full SYSTEM access on affected machines. The more severe issue,…
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites globally. The flaw…
Prompt Injection Attacks Are Thwarting AI Hacking Agents
“Context bombing” tricks malicious AI agents into shutting down before they can do harm. This article has been indexed from Security Latest Read the original article: Prompt Injection Attacks Are Thwarting AI Hacking Agents
EY Data Breach – Hackers Access Third-Party IT Support Platform and Steal Client Tax Documents
Ernst & Young LLP (EY) has confirmed a data security incident in which an unauthorized third party breached a third-party IT service management platform used by its tax practice, exfiltrating documents containing client personal and financial information. The Big Four…
OpenSSL DoS Vulnerability Lets Remote Attackers Exhaust Server Memory With an 11-Byte Payload
A newly disclosed vulnerability reminds us how deeply our digital infrastructure relies on foundational libraries. The Okta Red Team recently discovered “HollowByte,” a Denial of Service (DoS) flaw in OpenSSL that allows a remote, unauthenticated attacker to force a server…
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix Endpoint Analysis Client for Windows. The more serious of the two, tracked as CVE-2026-53565, allows a…
AI Is Supercharging Cyberattacks | Cybersecurity Today On The Weekend | July 18, 2026
Artificial intelligence is changing cybersecurity on both sides of the battle. While defenders are adopting AI to improve detection and response, attackers are using it to discover vulnerabilities, automate exploitation, and dramatically accelerate the pace of attacks. In this episode…
IT Security News Hourly Summary 2026-07-18 06h : 3 posts
3 posts were published in the last hour 3:32 : Why Operational Resilience and Digital Sovereignty Top the CIO Agenda – by Martin Lentle 3:32 : Agentic AI, Red Hat OpenShift, and NVIDIA: Shifting to precision security 3:31 : New…
Why Operational Resilience and Digital Sovereignty Top the CIO Agenda – by Martin Lentle
For CIOs across the Middle East Africa, keeping systems online is the foundation of customer trust. As public sector institutions and private enterprises accelerate their digital transformation, maintaining this operational uptime is the top priority. In a complex business landscape,…
Agentic AI, Red Hat OpenShift, and NVIDIA: Shifting to precision security
Red Hat is pioneering the use of agentic AI to shift vulnerability management from volume to precision. By combining the security-hardened foundation of Red Hat OpenShift with advanced AI frameworks from NVIDIA, we’re delivering actionable security intelligence that provides genuine…
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s Assetnote research team…
PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase…
Apple Sued Over Hide My Email Privacy Claims
Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims. The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic. This article has been…