Short, tactical, daily. The weekly Issues are the verdict — these are the notes scrawled in between.
-
An unpatched StyleSmuggler zero-day is backdooring Magento and Adobe Commerce stores, MikroTik routers are being hijacked over exposed SSH, and JetBrains got breached through its own unpatched TeamCity.
-
Citrix NetScaler auth bypass (CVE-2026-19490) is under active exploitation and PaperCut RCE chain is hitting schools; patch both now.
-
Chrome V8 zero-day CVE-2026-85046 is under active exploitation while attackers hammer WordPress Elementor Pro and Super Forms RCE flaws with over 440,000 attempts.
-
CISA flags seven exploited flaws including a 10.0 SonicWall SMA 1000 SSRF zero-day, while JFrog Artifactory and Sangoma Switchvox are under active exploitation.
-
SonicWall SMA1000 zero-days (CVE-2026-83548/83549) are being chained for unauthenticated RCE, while JFrog Artifactory (CVE-2026-82329) and Langflow (CVE-2026-0768) are under active exploitation days after disclosure.
-
PaperCut NG/MF zero-days (CVE-2026-82078, CVE-2026-81578) are now in CISA KEV and driving data theft, while JFrog Artifactory auth bypass CVE-2026-82329 is under active exploitation days after disclosure.
-
Fire Ant is inside Cisco IOS XR routers and TACACS servers, and PaperCut shipped a second emergency patch for two actively exploited CVEs.
-
Microsoft details TerminalFix, a ClickFix variant abusing Windows Terminal, while five critical WordPress flaws (including CVE-2026-76581) open the door to site takeover and RCE.
-
PaperCut ships a second emergency patch after attackers bypass the first, GiveWP hits max severity with unauthenticated RCE, and CISA adds an actively exploited ownCloud flaw to the KEV catalog.
-
PaperCut zero-day under active exploitation, three CVSS 10.0 ServiceNow flaws are patched but self-hosted instances remain exposed, and 8,300+ Gitea servers are being hit with RCE.
-
CISA set a Saturday deadline for CVE-2026-8452 in Citrix NetScaler as it hits KEV under active exploitation, while a zero-click RCE chain lands in the Avada WordPress theme.
-
CISA confirms active exploitation of a critical Gitea RCE (CVE-2026-60004) as attackers drop miner payloads, and a new SLEEPWALKER Windows backdoor waits silently for a single crafted packet before executing.
-
CISA flags a max-severity Oracle WebLogic bug (CVE-2026-21962) under active exploitation, alongside two miniOrange WordPress SAML auth bypasses being hit in the wild and a three-day patch deadline for a Zimbra takeover flaw.
-
CISA orders a three-day patch on an actively exploited Zimbra flaw, while Iran-linked actors took a UK power plant offline for four days.
-
Check Point's BTR.sys technique weaponizes Microsoft Defender's own signed driver to delete security software at boot, while 9,300+ leaked AWS keys remain live and a new phishing kit plants attacker passkeys for post-reset persistence.
-
Max-severity Entra ID RCE (CVE-2026-69836) and GitLab CVE-2026-19478 are both under active exploitation, while a poisoned arrayref Rust crate slips build-time malware into the supply chain.
-
Active exploitation hits Zimbra and GitLab while Citrix NetScaler's auth bypass waits for its turn; patch the edge before it patches you.
-
CISA flags active exploitation of a critical Windows IKE RCE while Clop's Windchill web shell and MLflow SSRF attacks show the mass-exploitation crews are already inside.
-
Actively exploited Ray RCE and Windows Task Host flaw hit CISA KEV, while two critical unauthenticated bugs (Forminator RCE and GitLab GraphQL) land with mass exposure.
-
China-nexus APT is exploiting VMware vCenter CVE-2026-59310 to drop Babuk-derived ransomware, while SAP Commerce Cloud CVE-2026-58231 fell to attackers three days after disclosure.
-
Attackers are exploiting a public macOS Screen Sharing auth-bypass PoC to drop Monero miners, while a service provider flaw led to €30M in Commerzbank fraud.
-
Two active exploitation campaigns dominate today: VMware vCenter CVE-2026-59310 is being used for reverse SSH persistence, while an unpatched GeoServer SQLi zero-day is under attack.
-
Lazarus is burning a Windows zero-day (CVE-2026-68820) against defense firms while SharePoint (CVE-2026-55040) falls to public PoC exploitation.
-
Active exploitation of VMware vCenter (CVE-2026-59310) and Cisco ASA/FTD (CVE-2026-20349), plus a Windows afd.sys zero-day (CVE-2026-68820) in this month's Patch Tuesday.
-
SonicWall SMA1000 flaws are under active ransomware exploitation, Gunra ransomware is chaining Fortinet and Schneider Electric bugs against critical infrastructure, and a maximum-severity Metabase SQL zero-day still has no CVE.
-
A CVSS 10.0 Metabase SQLi zero-day is being exploited to steal customer data, Progress Kemp LoadMaster's CVE-2026-8037 hit CISA KEV after nearly 800 exploit attempts, and N-able N-central attackers are persisting on managed systems.
-
Cisco patches three 9.9-severity SD-WAN/IOS XE bugs, Switzerland confirms a SharePoint breach, and the Microsoft 365 AitM phishing campaign is actively hijacking finance-team inboxes.
-
JetBrains TeamCity CVE-2026-63077 is under active exploitation, CISA added Langflow, N-central, and Apache Tomcat flaws to KEV with a 3-day fix deadline, and a Zbtlink router backdoor ships unauthenticated root shells.
-
CISA confirms active exploitation of Langflow, Tomcat, and N-central flaws while the self-propagating ChainDrop worm rips through npm and CVE-2026-59774 hands unauthenticated file reads on Gitea.
-
N-able N-central auth bypass CVE-2026-18577 is in CISA KEV under active exploitation, INC Ransomware is hammering SonicWall SMA 1000, and Unit 42's Pass-ta-key attacks show malware can lift Google-synced passkeys.
-
N-able N-central authentication bypass (CVE-2026-18577) is under active exploitation after an incomplete fix, and INC Ransomware is hitting SonicWall SMA1000 appliances for root access.
-
A firmware PRNG flaw in Coldcard hardware wallets enabled a $70M Bitcoin sweep across 1,196 addresses in 41 minutes.
-
CISA warns of active PLC attacks on U.S. water utilities, Adform's ad script was poisoned to swap crypto wallet addresses, and Adobe patched a CVSS 10.0 auth flaw in Campaign Classic.
-
Iran-linked actors hit 30-plus Minnesota water systems while unauthenticated RCE flaws land in TeamCity and VMware, both prime targets for the same playbook.
-
Cisco FMC static-credential zero-day (CVE-2026-20316) is in CISA KEV, Russia's Void Blizzard is riding an OWA zero-day for persistent mailbox access, and 30-plus Minnesota water utilities got hit in a coordinated OT attack.
-
Active exploitation of a Check Point SmartConsole auth bypass (CVE-2026-16232) now has a public PoC, while coordinated OT intrusions hit Minnesota water utilities and Gitea/vBulletin ship critical RCE fixes.
-
Two maximum-severity flaws under active exploitation (Arista VeloCloud CVE-2026-16812 and an unpatched Fastjson RCE), plus a critical unauthenticated TeamCity bug with a fix already out.
-
A threat actor is hijacking public Wi-Fi captive portals to phish Microsoft 365 credentials from traveling staff, while healthcare breaches at DentaQuest and MCBS expose over 24 million people.
-
The SourTrade malvertising campaign has browsers assemble malware in memory to dodge URL-based detection, while ClickFix cryptominer lures hit Steam forums.
-
A public PoC for an authenticated RCE in self-managed GitLab lands the same day as an active hotel Wi-Fi DNS campaign harvesting Microsoft 365 credentials.
-
Russia's Laundry Bear exploited a Zimbra zero-click flaw to loot Western mailboxes, Redis shipped seven fixes after public authenticated RCE PoCs dropped, and NodeBB patched eight high-severity bugs with exploit code already live.
-
Check Point's actively exploited SmartConsole auth bypass (CVE-2026-16232) leads, alongside two Linux local root flaws with public PoCs.
-
SharePoint CVE-2026-50522 and the wp2shell WordPress flaws are under active exploitation with machine-key theft and rapid webshell deployment, both post-patch persistence problems.
-
Three flaws are under active exploitation this week: WordPress wp2shell (CVE-2026-63030 + CVE-2026-60137), ServiceNow AI Platform CVE-2026-6875, and the Palo Alto GlobalProtect bypass now driving Qilin ransomware.
-
ServiceNow CVE-2026-6875 and WordPress WP2Shell flaws are under active exploitation, while a critical unauthenticated NGINX RCE (CVE-2026-42533) sits one crafted request away from your edge.
-
Public exploits are live for WordPress Core 'wp2shell' RCE, and 7-Zip patched a malicious-archive RCE in 26.02.
-
WordPress core wp2shell RCE has a public PoC and Inc ransomware is chaining SonicWall SMA zero-days for root, both under active or imminent exploitation.
-
A critical SharePoint RCE (CVE-2026-58644) is under active exploitation with a CISA July 19 deadline, while CISA also flags two exploited Fortinet FortiSandbox flaws.
-
CISA sets a Saturday deadline for the actively exploited Oracle E-Business Suite flaw while Zoom patches a 9.8 account-takeover bug for Windows.
-
Two SonicWall SMA1000 zero-days (CVE-2026-15409/15410) and three actively exploited SharePoint flaws are under attack right now, while Microsoft ships a record 570-plus patch load.
-
CISA flags active exploitation of Joomla iCagenda and Balbooa Forms RCE flaws, while a Jscrambler npm supply chain compromise and ShinyHunters OAuth abuse of Salesforce show trusted code and connections remain the soft entry.
-
CISA adds two max-severity Joomla extension flaws (CVE-2026-48939 and iCagenda) to KEV after zero-day exploitation, while Progress tells ShareFile customers to shut down servers over a credible threat.
-
A compromised jscrambler 8.14.0 npm release runs a Rust infostealer on install across Windows, macOS, and Linux.
-
Progress tells ShareFile admins to power off Storage Zone Controllers over a credible threat, Gitea's Docker auth bypass is under active exploitation, and a compromised Injective Labs npm package is stealing wallet keys.
-
Okta and Bleeping Computer detail active vishing-driven Entra passkey enrollment attacks (O-UNC-066, Helix) hitting Microsoft 365, while attackers actively exploit the 'Ill Bloom' wallet flaw and a poisoned Injective npm package to drain crypto.
-
A China-linked cluster is actively exploiting Roundcube to hijack university mail, Tenda ships an unpatched firmware backdoor (CVE-2026-11405), and Microsoft finally patched the RoguePlanet Defender zero-day (CVE-2026-50656).
-
Active exploitation of max-severity ColdFusion (CVE-2026-48282), Langflow, and Gitea (CVE-2026-20896) flaws, plus GhostLock (CVE-2026-43499), a 15-year-old Linux root escape hitting every mainstream distro.
-
NetScaler is under active exploitation again with a public PoC, while BeyondTrust ships critical pre-auth bypass fixes and a 16-year-old KVM escape (Januscape) drops with a working proof-of-concept.
-
Opera GX patched a zero-click flaw that let malicious sites auto-install mods and exfiltrate page data, while Google and the FBI disrupted the NetNut residential proxy botnet.
-
A local-root Linux kernel flaw (CVE-2026-46242) now has a fix and hits Android, while North Korea's npm typosquats keep bleeding developer secrets.
-
Anubis affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) for ransomware access while FortiBleed actors monetize thousands of compromised Fortinet firewalls with a Nextcloud zero-day.
-
Three active-exploitation items lead today: SharePoint RCE CVE-2026-45659 hits CISA KEV, Cisco confirms Unified CM exploitation, and an unpatched Argo CD flaw threatens full Kubernetes cluster takeover.
-
Active exploitation of Langflow RCE (CVE-2026-33017) and an ongoing Azure CLI password spray dominate today, alongside a batch of max-severity Adobe ColdFusion patches.
-
Three actively exploited critical flaws hit at once: SimpleHexlp CVE-2026-48558, Oracle EBS CVE-2026-46817, and Windows Defender 'BlueHammer,' all with confirmed in-the-wild abuse.
-
Active exploitation hits SimpleHelp (CVE-2026-48558) and Oracle EBS (CVE-2026-46817), while a public PoC drops for the libssh2 client flaw CVE-2026-55200.