Breaking News – Cyber Threats (last 6h)
Generated: 2026-07-20 13:00 PDT
- WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
SANS ISC Diary (full) • 2026-07-20 11:41 • isc.sans.eduLast week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
The Hacker News • 2026-07-20 11:23 • thehackernews.com
Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.“FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html - New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
BleepingComputer • 2026-07-20 10:43 • www.bleepingcomputer.com
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. […]
https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/ - Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
The Hacker News • 2026-07-20 10:29 • thehackernews.com
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.What makes it more than a
https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html - HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
The Hacker News • 2026-07-20 07:33 • thehackernews.com
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html - An AI SOC Evaluation Guide for Security Leaders
BleepingComputer • 2026-07-20 07:01 • www.bleepingcomputer.com
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. […]
https://www.bleepingcomputer.com/news/security/an-ai-soc-evaluation-guide-for-security-leaders/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
