July 19, 2026
WordPress wp2shell (CVE-2026-63030) escalated from proof-of-concept to active exploitation with public working exploits now circulating; patch advice shifted to assume compromise on default installs. Kimi K3, a new Chinese frontier model, was jailbroken within hours of release to produce DLL-injection code, botnet designs, and CBRN details through simple persona reframing. Scattered Spider members Thalha Jubair and Owen Flowers received 5.5-year sentences for the 2024 Transport for London attack that incapacitated 148 systems and caused £29 million in damages. Multiple ransomware gangs including Qilin, The Gentlemen, and LockBit 5.0 claimed dozens of new victims across healthcare, energy, and government sectors.
June 22, 2026
A usbliter8 BootROM exploit for Apple A12/A13 devices and the LACUNA Chain EDR evasion technique represent major offensive advances, while Klue's OAuth token-theft incident exposed Salesforce customers to the Icarus actor. Supply-chain threats include a malicious node-fetch-utils npm package deploying fileless Python implants and active exploitation of CVE-2026-4020 in Gravity SMTP WordPress plugin.
June 18, 2026
A critical vulnerability blitz dominates this digest: Oracle PeopleSoft CVE-2026-35273, Splunk CVE-2026-20253, and an unpatched Microsoft Defender RoguePlanet zero-day are actively exploited, with ShinyHunters and other threat actors targeting higher education and enterprise networks. The AI/security layer has emerged as a major attack surface, exemplified by Microsoft 365 Copilot SearchLeak (one-click data exfiltration), Google Vertex AI cross-tenant RCE, and the Novo Nordisk breach that exposed proprietary AI model checkpoints and training infrastructure as ransomware extortion payload—underscoring that AI IP is now a strategic target.