Press "Enter" to skip to content

OSINT / CyberSec report 19.07.2026 00:08

1. A critical pre authentication remote code execution vulnerability in WordPress core known as wp2shell allows unauthenticated attackers to run malicious code on affected sites (https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html).

2. CISA added a critical deserialization vulnerability in Microsoft SharePoint Server tracked as CVE-2026-58644 to its list of actively exploited vulnerabilities (https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html).

3. The HollowByte vulnerability in OpenSSL allows unauthenticated attackers to trigger a denial of service condition by freezing server memory with an 11 byte payload (https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html).

4. A cluster of seven malicious npm packages named ViteVenom is targeting the Vite frontend ecosystem to deliver a remote access trojan using blockchain based command and control infrastructure (https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html).

5. The NadMesh botnet is actively scanning for exposed AI services like Ollama and ComfyUI to steal AWS keys and Kubernetes tokens (https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html).

6. The Chinese threat group GoldenEyeDog has been linked to the April 2026 breach of DigiCert which resulted in the theft of code signing certificates (https://thehackernews.com/2026/07/goldeneyedog-subgroup-linked-to.html).

7. North Korean threat actors are using steganography in SVG images within fake job postings to deliver the OtterCookie malware (https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html).

8. Inc Ransomware is actively exploiting two chained zero day vulnerabilities in SonicWall SMA appliances to gain root level access (https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days).

9. A researcher released a Windows zero day exploit called LegacyHive that enables privilege escalation to administrator on fully patched systems (https://www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/).

10. Abbott Laboratories is investigating two separate cyber incidents involving unauthorized access to internal systems and potential data theft (https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyber-incidents-amid-extortion-claims/).

11. Ernst and Young disclosed a data breach resulting from the compromise of a third party support ticket system used by its IT staff (https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/).

12. The Chinese linked malware Daxin has resurfaced in a Taiwanese manufacturing firm alongside a previously undocumented backdoor named Stupig (https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html).

13. A security researcher discovered that a vulnerability in Shark robot vacuums allows attackers to execute root commands and access cameras on devices across an entire AWS region (https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html).

14. Google Gemini on Android currently allows unauthorized users to send messages from a locked device (https://www.bitdefender.com/en-us/blog/hotforsecurity/googles-gemini-strangers-messages-locked-android-phone).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *