Searchlight Cyber has assigned CVE-2026-63030 to “wp2shell,” a WordPress Core SQL injection issue that can lead to unauthenticated remote code execution. Shortly after publication, exploitation activity reportedly began, underscoring how quickly attackers weaponize newly disclosed pre-auth flaws. Organizations running affected WordPress versions should treat this as an urgent patch-and-hunt event, including checking for webshells and malicious plugin/theme changes.
Source: SANS ISC
ServiceNow AI Platform: critical pre-auth RCE (CVE-2026-6875) actively exploited
Attackers have started exploiting CVE-2026-6875, a critical pre-authentication code injection/sandbox-escape issue in the ServiceNow AI Platform. The flaw can allow unauthenticated attackers to execute code remotely on self-hosted instances, making internet-facing systems especially high risk. Given observed in-the-wild activity, defenders should rapidly prioritize patching, validate exposure scope, and monitor for suspicious process/script execution patterns.
Source: Help Net Security
Dnsmasq: remote heap buffer overflow fixed (CVE-2026-2291) with RCE impact demonstrated
Exodus Intelligence reports finding a heap buffer overflow in dnsmasq’s DNS handling, assigned CVE-2026-2291, fixed in versions 2.92rel2 and 2.93 (released May 11, 2026). The researchers describe remote code execution on OpenWRT targets via exploitation. Because dnsmasq is common on edge and embedded deployments, the key takeaway is to ensure firmware/package updates are pushed quickly across routers, IoT gateways, and home/SMB network environments.
Source: Exodus Intelligence
HOLLOWGRAPH: Microsoft 365 calendar events used as espionage command-and-control channel
Researchers linked a Cavern-aligned espionage toolkit component to HOLLOWGRAPH, which hides both instructions and stolen files inside Microsoft 365 calendar activity. Commands and exfiltration appear in legitimate-looking Graph API interactions, including appointments dated far in the future, making traditional “malicious email attachment” thinking less applicable. For defenders, this highlights the need for cloud telemetry detections that look beyond content hashes—focusing on behavioral anomalies in Graph usage, unusual file attachments, and calendar object patterns.
Source: Help Net Security
Exposed WebDAV “delivery lab” shows attacker workflow—and heavy GenAI-assisted documentation
Rapid7 describes an attacker leaving an open server directory that functioned as a complete WebDAV malware delivery and testing workspace, containing over 1,000 artifacts. The key insight isn’t just the samples, but the operational process: lures, execution “QA,” filename deception trials, and CVE-targeted method testing were organized like a production pipeline. This is a strong reminder that defenders should prioritize exposure management and misconfiguration detection (e.g., publicly reachable WebDAV paths), because one exposed directory can reveal an entire adversary development lifecycle.
Source: Rapid7
Hugging Face breach: autonomous AI agent intrusion via malicious dataset pipeline (and the “guardrails blocked IR” problem)
Hugging Face disclosed an intrusion carried out by an autonomous AI agent that compromised internal datasets and exposed service credentials. The initial access reportedly came through the data pipeline itself—triggered by a malicious dataset that allowed code execution—then the agent escaped workload isolation and harvested credentials across internal systems. A further emerging policy/ops lesson: commercial model safety guardrails reportedly blocked parts of incident response analysis, pushing organizations to plan for “AI-assisted investigation resilience,” not just model misuse prevention.
Source: Help Net Security
You May Also Be Interested In... Italy fines WINDTRE €1.7 million over security shortcomings behind two data breaches
Windows 10 support ‘hangover’ is becoming a security problem
AI agents are still logging in as humans