WordPress 7.0.2 and related security updates address a critical pre-authentication RCE (wp2shell, CVE-2026-63030) and a separate high severity issue (CVE-2026-60137). Public proof-of-concept details indicate attackers can chain these weaknesses to achieve remote code execution on vulnerable WordPress installations without authentication. Given how widely WordPress is deployed, defenders should treat this as an urgent patch-and-verify event (including web application firewall rules and incident logging checks).
Source: Help Net Security
CISA adds FortiSandbox and Microsoft SharePoint vulnerabilities to KEV
The U.S. CISA has added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog. KEV listings typically signal that vulnerabilities are being actively exploited or are of high risk, raising pressure for rapid remediation across affected environments. Organizations using these platforms should validate exposure, prioritize patching, and confirm compensating controls are in place for any systems that cannot be updated immediately.
Source: Security Affairs
OpenSSL “HollowByte” flaw: 11-byte payload can cause memory exhaustion (DoS)
Okta disclosed HollowByte, an OpenSSL issue that allows remote, unauthenticated attackers to exhaust server memory using a minimal 11-byte payload. While the impact is primarily denial-of-service, attackers can potentially weaponize it to degrade availability or create conditions for follow-on attacks. Systems should be updated promptly and monitored for anomalous connection patterns consistent with the described payload behavior.
Source: Security Affairs
Public wp2shell exploits accelerate WordPress RCE risk across the internet
Security reporting indicates that newly released wp2shell exploits enable attackers to take over vulnerable WordPress sites by achieving pre-authentication remote code execution. The emphasis on default installations and “no preconditions” increases the likelihood of broad scanning and rapid exploitation by opportunistic threat actors. Administrators should ensure all patched versions are deployed, review public-facing routes, and hunt for webshell/command execution indicators in web server and application logs.
Source: Security Affairs
13-year-old Daxin China-linked rootkit still active on manufacturer networks
Researchers reported Symantec-detected activity involving Daxin, a China-linked Windows kernel-mode rootkit first documented years ago, alongside a new Stupig backdoor. The finding that Daxin was still running on a compromised host in 2026 highlights how long-lived advanced malware can persist across environments and rebuild capabilities over time. Organizations should increase focus on stealth detection (kernel-level indicators, driver persistence) and validate whether legacy compromises remain buried beneath routine maintenance.
Source: Security Affairs
Chrome issues two critical security updates in 48 hours—review patch timelines
Google released a second critical Chrome security update within two days of the previous one, which is unusual and suggests fast-moving threat findings. For security teams, this is a reminder to reduce patch lag and ensure browser security updates propagate quickly across endpoints—especially for high-privilege users and kiosk-like environments. Confirm that automatic updates are enabled and verify that managed device policies aren’t unintentionally delaying rollout.
Source: Forbes Security
Prompt injection “context bombing” undermines AI hacking agents’ ability to act
Researchers describe “context bombing,” an approach that tricks AI agents into shutting down early—potentially preventing them from completing malicious tasks or, in some scenarios, causing them to fail open depending on safeguards. This reinforces that AI security is not only about model training, but also about controlling the prompts and tool-use context an agent receives. Teams deploying AI assistants for security workflows should harden tool permissions, isolate untrusted inputs, and add robust validation before agent actions are executed.
Source: Wired
You May Also Be Interested In...
Imperva: Customers protected against wp2shell pre-authentication RCE
Kalshi insider trading probe: surveillance team breach risk
Mac malware triggers an 83-hour password-entry loop