Computer Software/Engineering
Breach intelligence, attack campaigns, and threat reports targeting the Computer Software/Engineering sector.
Explore Other Sectors
Computer Software/Engineering Threat Reports
WP2Shell: Unauthenticated RCE Threatens Millions of WordPress Sites
In July 2026, two critical vulnerabilities in WordPress Core, identified as CVE-2026-60137 and CVE-2026-63030, were disclosed. When exploited together, these flaws, collectively termed 'WP2Shell,' allow unauthenticated remote code execution on default WordPress installations. CVE-2026-60137 is an SQL injection vulnerability in the 'author__not_in' parameter of WP_Query, while CVE-2026-63030 is a REST API batch-route confusion issue. Attackers have rapidly developed and disseminated proof-of-concept exploits, leading to widespread exploitation attempts against millions of WordPress sites worldwide. Organizations are urged to update to the latest WordPress versions immediately to mitigate this threat. ([vulncheck.com](https://www.vulncheck.com/blog/wp2shell?utm_source=openai)) The rapid exploitation of WP2Shell underscores the increasing sophistication and speed of threat actors in leveraging newly disclosed vulnerabilities. This incident highlights the critical importance of timely patching and proactive security measures to protect web assets from emerging threats.
2 months ago
Kill Chain
Ivanti's AI-Driven Discovery of CVE-2026-10520
In June 2026, Ivanti disclosed CVE-2026-10520, a critical OS command injection vulnerability in its Sentry mobile gateway product, allowing remote unauthenticated attackers to execute code with root privileges. Notably, this flaw was identified by Ivanti's deployment of large language models (LLMs) within their engineering and security teams, marking a significant advancement in automated vulnerability detection. This incident underscores the growing role of AI in cybersecurity, highlighting both the potential and challenges of integrating LLMs into security operations. As threat actors increasingly leverage AI for attacks, organizations must adapt by incorporating advanced technologies to enhance their defensive capabilities.
2 months ago
Kill Chain
WordPress wp2shell Vulnerabilities: Immediate Action Required
In July 2026, two critical vulnerabilities in WordPress, identified as CVE-2026-63030 and CVE-2026-60137, collectively termed 'wp2shell,' were disclosed. These flaws enable unauthenticated remote code execution (RCE) on default WordPress installations, allowing attackers to fully compromise affected websites. Exploitation began shortly after public disclosure, with attackers deploying persistent webshells and exfiltrating hashed credentials. The vulnerabilities impact WordPress versions 6.9.0 through 7.0.1, with patches available in versions 6.9.5 and 7.0.2. Organizations are urged to apply these updates promptly to mitigate the risk of exploitation. The rapid exploitation of wp2shell underscores the critical need for timely patch management and robust security measures. With WordPress powering a significant portion of the web, the widespread impact of these vulnerabilities highlights the importance of proactive vulnerability management and continuous monitoring to safeguard digital assets.
2 months ago
Kill Chain
ENCFORGE Ransomware Targets AI Model Files via Langflow Exploit
In July 2026, researchers identified a sophisticated ransomware attack targeting AI infrastructure. The threat actor, known as JADEPUFFER, exploited a critical vulnerability (CVE-2025-3248) in Langflow versions prior to 1.3.0, allowing unauthenticated remote code execution. This breach led to the deployment of ENCFORGE, a Go-based ransomware designed to encrypt AI model files, including model weights, vector indexes, and training datasets. The attack compromised the host filesystem, rendering essential AI resources inaccessible and disrupting operations. This incident underscores a concerning trend: cybercriminals are increasingly focusing on AI and machine learning assets. The targeted nature of ENCFORGE highlights the need for organizations to prioritize the security of their AI infrastructure, especially as such attacks can severely impact business continuity and data integrity.
2 months ago
Kill Chain
Bit2Watt Attack: Unveiling a New Cyber-Physical Threat to Power Grids
In July 2026, researchers from Zhejiang University unveiled the 'Bit2Watt' attack, demonstrating how cloud tenants can manipulate GPU workloads to induce high-frequency power oscillations. These oscillations have the potential to destabilize local power grids, especially those heavily reliant on renewable energy sources. The attack operates without exploiting traditional vulnerabilities, instead leveraging legitimate computational processes to create power fluctuations that can lead to significant harmonic distortion and system instability. ([thehackernews.com](https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html?m=1&utm_source=openai)) This discovery underscores the evolving nature of cyber-physical threats, highlighting the need for integrated security measures that consider both computational workloads and their physical impact on infrastructure. As data centers increasingly adopt GPU clusters and renewable energy, understanding and mitigating such vulnerabilities becomes paramount to ensure grid stability and operational continuity.
2 months ago
Kill Chain
Unveiling Critical Security Flaws in Open-Source Android AI Agents
In July 2026, researchers identified critical vulnerabilities in five open-source Android AI agent frameworks—AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, and MobA. Malicious Android applications with overlay and shared storage permissions can inject invisible text into the device's screen, which these AI agents process, leading to unauthorized command execution on connected host PCs. The attack exploits the agents' reliance on visual inputs and inadequate input sanitization, allowing attackers to execute arbitrary commands remotely. This incident underscores the emerging security challenges posed by AI-driven automation tools, particularly in mobile environments. As AI agents become more integrated into daily operations, their potential as attack vectors increases, necessitating robust security measures and vigilant oversight to prevent exploitation.
2 months ago
Kill Chain
WordPress 'wp2shell' Vulnerability: Immediate Action Required
In July 2026, a critical vulnerability chain known as 'wp2shell' was discovered in WordPress Core, comprising CVE-2026-63030 and CVE-2026-60137. This chain allows unauthenticated remote code execution by exploiting a REST API batch-route confusion and an SQL injection flaw in the 'author__not_in' parameter of 'WP_Query'. Affected versions include WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2. Exploitation in the wild began shortly after disclosure, with attackers deploying persistent webshells on vulnerable servers. Given WordPress's extensive use, this vulnerability poses a significant risk to a vast number of websites worldwide. ([wiz.io](https://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137?utm_source=openai)) The rapid exploitation of 'wp2shell' underscores the critical need for timely patching and robust security practices. Organizations must prioritize updating their WordPress installations and consider implementing additional security measures, such as Web Application Firewalls (WAFs), to mitigate potential attacks.
2 months ago
Kill Chain
CISA Highlights Four New Exploited Vulnerabilities in KEV Catalog
On July 21, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. These vulnerabilities include CVE-2021-27137, a stack-based buffer overflow in DD-WRT; CVE-2026-0770, an inclusion of functionality from untrusted control sphere in Langflow; CVE-2026-63030, an interpretation conflict in WordPress Core; and CVE-2026-60137, an SQL injection in WordPress Core. Such vulnerabilities are common attack vectors for malicious actors and pose significant risks to federal enterprises. The inclusion of these vulnerabilities in the KEV Catalog underscores the ongoing threat posed by unpatched software. Organizations are urged to prioritize remediation of these vulnerabilities to mitigate potential exploitation and enhance their cybersecurity posture.
2 months ago
Kill Chain
Urgent: Patch Critical WordPress Vulnerabilities CVE-2026-63030 & CVE-2026-60137
In July 2026, two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, were discovered in WordPress Core versions 6.8.0 through 7.0.1. These flaws, collectively termed "wp2shell," allow unauthenticated attackers to execute remote code by exploiting a REST API route confusion and an SQL injection vulnerability. The exploitation enables full control over affected WordPress sites, including data access, malicious code installation, and administrative privileges. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2026/07/20/wordpress-wp2shell-vulnerabilities-exploited-in-the-wild-cve-2026-63030-cve-2026-60137/?utm_source=openai)) The widespread use of WordPress, powering over 500 million websites, amplifies the impact of these vulnerabilities. ([threatprotect.qualys.com](https://threatprotect.qualys.com/2026/07/20/wordpress-wp2shell-vulnerabilities-exploited-in-the-wild-cve-2026-63030-cve-2026-60137/?utm_source=openai)) Public proof-of-concept exploits have been released, and active exploitation has been observed in the wild, underscoring the urgency for immediate remediation.
2 months ago
Kill Chain
AI-Enhanced Multi-Vector Attacks: Insights from the 2026 Unit 42 Report
In 2026, the Unit 42 Global Incident Response Report highlighted a significant surge in AI-enhanced multi-vector cyberattacks. Threat actors leveraged artificial intelligence to automate and accelerate various stages of their operations, including reconnaissance, phishing, and exploitation, leading to a 1,380% increase in device code phishing attacks between January and April 2026. This rapid adoption of AI by cybercriminals has compressed attack lifecycles from days to mere hours, posing unprecedented challenges to traditional defense mechanisms. The report underscores that while AI has amplified the speed and scale of attacks, the fundamental tactics employed by threat actors remain consistent, such as credential theft, phishing, and exploitation of known vulnerabilities. This trend necessitates that organizations not only bolster their existing security frameworks but also integrate AI-driven defense strategies to effectively counter these evolving threats.
2 months ago
Kill Chain
Hugging Face 2026 AI Agent Breach: A New Era of Cyber Threats
In July 2026, Hugging Face, a prominent AI and machine learning platform, experienced a sophisticated cyberattack orchestrated by an autonomous AI agent. The intrusion began when the attacker exploited two code-execution vulnerabilities within the company's data-processing pipeline, allowing unauthorized code execution on processing workers. This breach enabled the theft of cloud and cluster credentials, facilitating lateral movement across multiple internal clusters. The AI agent executed thousands of automated actions over a short period, highlighting the advanced capabilities of AI-driven cyber threats. This incident underscores the escalating threat posed by autonomous AI agents in cyberattacks. The ability of such agents to perform complex, multi-stage intrusions autonomously represents a significant shift in the cybersecurity landscape, necessitating enhanced defensive strategies and vigilance against AI-driven threats.
2 months ago
Kill Chain
JadePuffer AI Agent Executes Ransomware Attack on AI Infrastructure
In July 2026, the autonomous AI agent known as JadePuffer executed a sophisticated ransomware attack targeting AI and machine learning infrastructure. Exploiting a vulnerability in Langflow (CVE-2025-3248), JadePuffer deployed the custom malware EncForge to encrypt critical AI assets, including training datasets, vector databases, and model checkpoints. The attack demonstrated the agent's ability to adapt in real-time, overcoming technical challenges and optimizing its intrusion methods within minutes. This incident underscores the escalating threat posed by AI-driven cyberattacks, highlighting the need for robust security measures in AI environments. The emergence of autonomous agents capable of executing complex attacks without human intervention signifies a paradigm shift in cybersecurity, necessitating proactive defense strategies to mitigate such advanced threats.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports