🚨 ACTIVE EXPLOITATION
-
WP2Shell WordPress Vulnerabilities CVE-2026-60137 and CVE-2026-63030 Exploited in the Wild — securityweek.com
Attackers are exploiting two critical WordPress vulnerabilities to achieve unauthenticated remote code execution.- Affects WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1
- Vulnerabilities include CVE-2026-60137 (SQL injection) and CVE-2026-63030 (arbitrary code execution)
- Exploitation requires no authentication or plugins on stock WordPress installs
- Attackers chain the two flaws to gain full control of targeted WordPress sites
- Exploitation began shortly after public disclosure with proof-of-concept exploits available
-
Critical ServiceNow CVE-2026-6875 code execution flaw now actively exploited — bleepingcomputer.com
Attackers have started exploiting a critical remote code execution flaw in ServiceNow AI Platform.- Applies to ServiceNow AI Platform, including self-hosted and hosted instances
- Vulnerability CVE-2026-6875 allows unauthenticated attackers to escape sandbox and execute code remotely
- Exploitation observed days after patches were released on July 13, 2026
- Attack payloads target the /assessment_thanks.do endpoint using a sandbox-escape gadget
- ServiceNow runs over 100 billion workflows yearly and powers AI apps at 85% of Fortune 500 companies
💥 BREACHES & INCIDENTS
-
Hugging Face Breached in Autonomous AI-Driven Attack on Production Infrastructure — securityweek.com
Hugging Face suffered a data breach from an autonomous AI attack compromising internal datasets and credentials.- Applies to Hugging Face's production infrastructure and internal datasets
- Attack exploited two code-execution paths in dataset processing for initial access
- Used autonomous AI agent executing tens of thousands of actions in short-lived sandboxes
- Attack involved node-level escalation, credential harvesting, and lateral movement
- No evidence found of tampering with public models, datasets, or software supply chain
-
Korean National Diplomatic Academy Hacked for 10 Months — chosun.com
The National Diplomatic Academy in Korea was breached for about 10 months.- Applies to the National Diplomatic Academy under Korea's Ministry of Foreign Affairs
- The academy's systems were compromised and accessed for approximately 10 months
- No specific CVEs or technical details about the attack vector have been disclosed
🕵️ RESEARCH & DEEP DIVES
-
7-Zip CVE-2026-14266 Heap Overflow Lets Crafted XZ Archives Run Code — thehackernews.com
A heap-based buffer overflow in 7-Zip's XZ archive processing allows code execution.- Applies to 7-Zip versions before 26.02, affecting users opening XZ archives
- Vulnerability is a heap-based buffer overflow in XZ chunked data processing
- Attack requires victim to open a crafted XZ archive delivered locally or remotely
- Code executes with 7-Zip's current process privileges, typically limited on Windows
- Fix released in 7-Zip 26.02 on June 25, 2026; no public exploits reported yet
-
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — thehackernews.com
A solo Russian-speaking threat actor known as "bandcampro" outsourced operations to Google's open-source Gemini CLI AI and controlled a botnet.- Analysis based on 200 Gemini CLI session logs from March to April 2026