July 23, 2026
- WordPress wp2shell — detection and hunt guidance shipped. As the pre-auth RCE chain (CVE-2026-63030 route-confusion + CVE-2026-60137 SQLi) stays under active exploitation (earlier coverage), Elastic Security Labs published an end-to-end walkthrough with detection rules, IOCs and hunt queries (Elastic) (discussion).
· Vulnerabilities & Exploits
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 22, 2026
- WordPress "wp2shell" exploitation continues to broaden into mass scanning and webshell deployment. Wiz and BleepingComputer report attackers chaining CVE-2026-63030 and CVE-2026-60137 for unauthenticated RCE and persistent webshells; NCSC-FI has amplified the exploitation warning (earlier coverage). Wiz, BleepingComputer.
· Vulnerabilities & Exploits
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 21, 2026
- WordPress "wp2shell" is now being exploited in the wild with a public working exploit. SANS ISC confirms active exploitation began shortly after disclosure of CVE-2026-63030 (a WordPress core SQL injection) chained with CVE-2026-60137 for unauthenticated RCE, and Horizon3 published a technical breakdown plus remediation-verification guidance (earlier coverage). Patch to 6.9.5 / 7.0.2 immediately. SANS ISC, Horizon3, Dark Reading. (discussion).
· Vulnerabilities & Exploits
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 20, 2026
- wp2shell exploitation broadened in the wild. SecurityWeek confirmed active attacks against CVE-2026-63030 and CVE-2026-60137 shortly after disclosure, and NCSC-FI's Daniel Card reported live batch-route exploitation attempts (most failing against auto-patched or WAF-fronted sites; ~20% of a 3.5K-host sample was still unpatched). Eye Security published a defender's guide with forensic artifacts, a compromise-scanner plugin, and a browser extension to check patch status (SecurityWeek, PwnDefend, Eye Security) (earlier coverage).
· Vulnerabilities & Exploits
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
July 18, 2026
- "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST
/batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory.
· Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All