Categories Breaking News

Breaking News – Cyber Threats – 2026-07-20 13:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-07-20 13:00 PDT

  • WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
    SANS ISC Diary (full) • 2026-07-20 11:41 • isc.sans.edu

    Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can lead to unauthenticated remote code execution. Shortly after being announced, the vulnerability started to be exploited.


    https://isc.sans.edu/diary/rss/33168

  • FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
    The Hacker News • 2026-07-20 11:23 • thehackernews.com
    Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.

    “FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
    https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html

  • New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
    BleepingComputer • 2026-07-20 10:43 • www.bleepingcomputer.com
    A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data. […]
    https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
  • Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
    The Hacker News • 2026-07-20 10:29 • thehackernews.com
    A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.

    What makes it more than a
    https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html

  • HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
    The Hacker News • 2026-07-20 07:33 • thehackernews.com
    A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.

    Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so the activity looks
    https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html

  • An AI SOC Evaluation Guide for Security Leaders
    BleepingComputer • 2026-07-20 07:01 • www.bleepingcomputer.com
    Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. […]
    https://www.bleepingcomputer.com/news/security/an-ai-soc-evaluation-guide-for-security-leaders/

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Written By

More From Author

You May Also Like