daily cyber × ai intelligence

index

tagged

[CVE-2026-60137]

5 editions · 5 items

July 21, 2026

  • WordPress "wp2shell" is now being exploited in the wild with a public working exploit. SANS ISC confirms active exploitation began shortly after disclosure of CVE-2026-63030 (a WordPress core SQL injection) chained with CVE-2026-60137 for unauthenticated RCE, and Horizon3 published a technical breakdown plus remediation-verification guidance (earlier coverage). Patch to 6.9.5 / 7.0.2 immediately. SANS ISC, Horizon3, Dark Reading. (discussion). · Vulnerabilities & Exploits

in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live

July 20, 2026

  • wp2shell exploitation broadened in the wild. SecurityWeek confirmed active attacks against CVE-2026-63030 and CVE-2026-60137 shortly after disclosure, and NCSC-FI's Daniel Card reported live batch-route exploitation attempts (most failing against auto-patched or WAF-fronted sites; ~20% of a 3.5K-host sample was still unpatched). Eye Security published a defender's guide with forensic artifacts, a compromise-scanner plugin, and a browser extension to check patch status (SecurityWeek, PwnDefend, Eye Security) (earlier coverage). · Vulnerabilities & Exploits

in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap

July 18, 2026

  • "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST /batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory. · Vulnerabilities & Exploits

in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All