A new threat actor, identified as UTA0533, has been exploiting zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances before these issues were publicly disclosed. This activity has been tracked since June 22, 2026, and was uncovered during an incident response investigation by cybersecurity firm Volexity. The attackers gained root access to systems, raising serious concerns about the security of organizations using these VPN appliances. This incident is particularly alarming as it highlights the potential risks associated with undisclosed vulnerabilities, which can be exploited by malicious actors before users have a chance to protect themselves. Organizations using SonicWall SMA appliances should be vigilant and prepare for potential impacts from these vulnerabilities.
Articles tagged "Vulnerability"
Found 1435 articles
Help Net Security
Last week, two high severity vulnerabilities were discovered in WordPress that require immediate attention from users and site administrators. The 7.0.2 security release addresses one critical issue along with a high severity problem, both of which could potentially expose websites to serious risks. WordPress users are urged to update their installations promptly to protect against possible exploitation. Additionally, there was a mention of an open-source research agent that poses risks when it interacts with live cloud accounts, emphasizing the importance of securing credentials. These vulnerabilities serve as a reminder of the ongoing need for vigilance in website security.
Security Affairs
Recent discoveries have revealed serious vulnerabilities in WordPress, specifically two flaws tracked as CVE-2026-63030 and CVE-2026-60137. These vulnerabilities, known as wp2shell, can be exploited by attackers to execute code remotely without needing authentication. This means that anyone with these vulnerabilities can potentially take control of a WordPress site, particularly those running default configurations. The availability of public proof-of-concept exploits raises the urgency for website owners to address these flaws promptly, as they are now at greater risk of being targeted by malicious actors. It’s critical for users to be aware of these vulnerabilities and take immediate action to secure their sites.
7-Zip has released version 26.02 to address a serious remote code execution (RCE) vulnerability. This flaw allows attackers to execute malicious code on users' systems if they open specially crafted compressed files. Users of 7-Zip should update to the latest version to protect themselves from potential exploitation. The vulnerability is particularly concerning as it could be exploited easily by tricking users into opening harmful files. Keeping software up to date is crucial in maintaining security and preventing such attacks.
Security Affairs
Okta has reported a new vulnerability in OpenSSL, dubbed HollowByte, which allows remote attackers to exploit a flaw that can lead to memory exhaustion on servers. This specific vulnerability is only 11 bytes long, and when exploited, it can cause a server to allocate up to 131 KB of memory. As a result, this could trigger denial-of-service attacks, rendering the affected servers unable to respond to legitimate requests. Organizations using affected versions of OpenSSL should prioritize patching this vulnerability to protect their systems from potential exploitation. The risk is significant, as attackers can exploit this flaw without needing authentication, making it easier for malicious actors to disrupt services.
Recent vulnerabilities known as 'wp2shell' have been discovered in WordPress Core, allowing remote code execution. These flaws are particularly concerning because public exploits have now been released, meaning attackers can actively take advantage of them. Administrators of WordPress sites need to act quickly to patch their systems to protect against potential breaches. The urgent nature of this situation is underscored by the fact that these vulnerabilities can compromise the security of websites, putting sensitive data at risk. Users of WordPress should ensure they are running the latest version to mitigate these risks.
WordPress has released a security update, version 7.0.2, to address two significant vulnerabilities that pose risks to users. The first vulnerability, identified as CVE-2026-60137, is a SQL injection issue that could allow attackers to manipulate databases. The second, also CVE-2026-60137, relates to a REST API batch-route confusion that could lead to remote code execution, potentially giving attackers full control over affected systems. The vulnerabilities affect WordPress version 6.9 and earlier. Users are strongly advised to update their installations immediately to mitigate the risks associated with these security flaws.
Ernst & Young (EY) has reported a data breach stemming from a compromised third-party IT support ticket system. This breach potentially exposed sensitive client documents and tax information, raising significant concerns about data security for affected clients. The attackers gained access to a platform used by EY's IT teams to manage support requests, indicating a serious vulnerability in the handling of third-party services. As a result, clients may need to monitor their accounts for suspicious activity and consider taking additional security measures. This incident serves as a reminder for companies to thoroughly vet third-party vendors and ensure robust security practices are in place.
A serious vulnerability has been discovered in the WordPress core that allows unauthenticated attackers to execute code on affected sites. This flaw impacts any WordPress installation running versions 6.9 and 7.0, even those without any plugins installed. The issue was identified by Adam Kues from Assetnote, and WordPress has since addressed it with updates 6.9.5 and 7.0.2, which were released on Friday. These updates include a feature called forced updates to help secure sites against this vulnerability. It's crucial for WordPress users to ensure they are running the latest version to protect their sites from potential exploitation.
A recently discovered vulnerability in OpenSSL, dubbed the HollowByte flaw, can cause unpatched servers to reserve up to 131 KB of memory for a tiny 11-byte TLS request that never arrives. This issue can lead to a denial-of-service condition, where the server's memory is tied up until the process is restarted. The problem was identified by Okta's Red Team, which reported it without a CVE or formal advisory. OpenSSL issued a fix for this vulnerability in June, but the lack of documentation means many users may remain unaware of the risk. As a result, organizations running affected OpenSSL versions should ensure they apply the update to avoid potential service disruptions.
A newly discovered vulnerability known as HollowByte poses a significant risk to OpenSSL servers by allowing unauthenticated attackers to create a denial-of-service (DoS) condition with a payload as small as 11 bytes. This flaw can lead to excessive memory consumption on affected servers, potentially causing them to crash or become unresponsive. The issue affects various OpenSSL implementations, which are widely used for secure communications on the internet. As the vulnerability is easy to exploit, it raises concerns for organizations relying on OpenSSL for their security infrastructure. Companies using OpenSSL should prioritize patching and implementing security measures to mitigate the risks associated with this vulnerability.
Security Affairs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included new vulnerabilities in its Known Exploited Vulnerabilities catalog, specifically targeting the KNX Protocol Connection Authorization Option 1 from the KNX Association and various flaws related to Oracle products. This update is crucial as it indicates that these vulnerabilities could be actively exploited by attackers, posing risks to organizations using affected systems. The inclusion of these vulnerabilities serves as a warning to IT departments and security teams to prioritize patching and mitigation efforts. Notably, CISA also added vulnerabilities from SonicWall and Microsoft to the catalog, emphasizing the ongoing need for vigilance in cybersecurity practices. Companies should review their systems and apply necessary updates to safeguard against potential attacks.
Coca-Cola's Fairlife brand has halted milk production in the U.S. due to a ransomware attack that was disclosed on July 16, 2026. The company confirmed that while product quality and safety remain intact, all production operations at Fairlife in the U.S. have been temporarily suspended. This incident raises concerns about the vulnerability of food production systems to cyberattacks, especially as ransomware increasingly targets critical infrastructure. Fairlife's operations in Canada appear to be unaffected for now, but the situation could have broader implications for supply chains and food availability if not resolved quickly. The attack is a reminder of the growing risks businesses face from cybercriminals seeking to disrupt operations and demand ransom payments.
A newly discovered vulnerability in SharePoint has been exploited by attackers shortly after its disclosure. This critical flaw allows remote, authenticated attackers to execute arbitrary code on the server, posing a significant risk to organizations using the platform. The vulnerability could lead to unauthorized access and manipulation of sensitive data, making it crucial for affected users to take immediate action. Companies utilizing SharePoint need to prioritize security updates to protect their systems from potential breaches. The rapid exploitation of this vulnerability serves as a reminder of the importance of timely patch management in cybersecurity.
The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server to its list of Known Exploited Vulnerabilities. This flaw, identified as CVE-2026-58644, has a high severity score of 9.8, indicating that it poses a significant risk. Federal Civilian Executive Branch agencies are mandated to implement necessary patches by July 19, 2026. The vulnerability involves a deserialization issue that could allow attackers to execute remote code on affected systems, making it crucial for organizations using SharePoint to take immediate action. By addressing this vulnerability, agencies can help prevent potential exploitation by malicious actors.