July 31, 2026
- MediaWiki CVE-2026-58025 (CVSS 9.8) is a deserialization RCE via malicious log-entry imports, and a public PoC is now available; exploitation requires import permissions, and fixes ship in 1.43.9, 1.44.6, 1.45.4, and 1.46.0 (DarkWebInformer / PoC). · Vulnerabilities & Exploits
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests