July 23, 2026
- WordPress wp2shell — detection and hunt guidance shipped. As the pre-auth RCE chain (CVE-2026-63030 route-confusion + CVE-2026-60137 SQLi) stays under active exploitation (earlier coverage), Elastic Security Labs published an end-to-end walkthrough with detection rules, IOCs and hunt queries (Elastic) (discussion).
· Vulnerabilities & Exploits
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 22, 2026
- WordPress "wp2shell" exploitation continues to broaden into mass scanning and webshell deployment. Wiz and BleepingComputer report attackers chaining CVE-2026-63030 and CVE-2026-60137 for unauthenticated RCE and persistent webshells; NCSC-FI has amplified the exploitation warning (earlier coverage). Wiz, BleepingComputer.
· Vulnerabilities & Exploits
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 21, 2026
- WordPress "wp2shell" is now being exploited in the wild with a public working exploit. SANS ISC confirms active exploitation began shortly after disclosure of CVE-2026-63030 (a WordPress core SQL injection) chained with CVE-2026-60137 for unauthenticated RCE, and Horizon3 published a technical breakdown plus remediation-verification guidance (earlier coverage). Patch to 6.9.5 / 7.0.2 immediately. SANS ISC, Horizon3, Dark Reading. (discussion).
· Vulnerabilities & Exploits
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 20, 2026
- wp2shell exploitation broadened in the wild. SecurityWeek confirmed active attacks against CVE-2026-63030 and CVE-2026-60137 shortly after disclosure, and NCSC-FI's Daniel Card reported live batch-route exploitation attempts (most failing against auto-patched or WAF-fronted sites; ~20% of a 3.5K-host sample was still unpatched). Eye Security published a defender's guide with forensic artifacts, a compromise-scanner plugin, and a browser extension to check patch status (SecurityWeek, PwnDefend, Eye Security) (earlier coverage).
· Vulnerabilities & Exploits
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
July 19, 2026
- WordPress "wp2shell" (CVE-2026-63030) is now weaponized. Multiple researchers — including Assetnote's hash_kitten and teams at calif.io and FullHunt — have reproduced the unauthenticated REST API batch-route confusion chain that yields RCE against default installs, and public PoCs are circulating. Advice has shifted from "patch" to "patch and consider vulnerable systems compromised." Fixed in WordPress 6.8.6, 6.9.5 and 7.0.2 (BleepingComputer, FullHunt analysis + scanner, NCSC-NL) (earlier coverage) (discussion).
· Vulnerabilities & Exploits
in WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation
July 18, 2026
- "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST
/batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory.
· Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All