Cyber Briefing: 2026.07.20

Over 2,000 hospitals hit in a major billing software breach, while a sophisticated new malware strain evades EDR tools by routing stolen corporate data through Microsoft 365 calendars. This article has been indexed from CyberMaterial Read the original article: Cyber…

GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE

A critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain…

HOLLOWGRAPH malware hides in M365 calendar invites

A previously unknown Windows malware strain is exploiting Microsoft 365 calendar functionality to conduct covert espionage operations, according to research published by Group-IB. This article has been indexed from CyberMaterial Read the original article: HOLLOWGRAPH malware hides in M365 calendar…

Craneware data breach affects 2,000+ US hospitals

Craneware, a healthcare technology company headquartered in Edinburgh and listed on London’s AIM market, has disclosed a data breach affecting more than 2,000 hospitals across the United States. This article has been indexed from CyberMaterial Read the original article: Craneware…