2026-07-18
- vulnerabilities
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 addresses a remote code execution vulnerability that could be exploited through specially crafted compressed files. The flaw allows attackers to execute code if users open malicious archives created by threat actors.
Why it matters: Any organization or user with 7-Zip installed faces code execution risk from archive files sent via email or downloads; update to version 26.02 immediately.
- vulnerabilities
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits are now available for critical remote code execution vulnerabilities in WordPress Core known as 'wp2shell'. WordPress administrators should apply patches immediately to mitigate active exploitation risk.
Why it matters: WordPress site operators face direct threat of remote code execution and site compromise; patching is urgent given public exploit availability.
- vulnerabilitiesCVE-2026-60137
Two new high severity WordPress vulnerabilities, patch immediately!
WordPress released version 7.0.2 to address one critical and one high severity vulnerability. The issues include CVE-2026-60137, a facilitated SQL injection flaw, and a separate REST API batch-route confusion vulnerability leading to remote code execution. Both require immediate patching across affected WordPress 6.9 installations.
Why it matters: All WordPress site operators must apply version 7.0.2 immediately, as these vulnerabilities expose installations to SQL injection and remote code execution attacks that could compromise website integrity and user data.
- threat intel
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has detected an increase in attacks leveraging ACR Stealer malware targeting its enterprise customers. The malware focuses on stealing browser-stored passwords, authentication tokens, and sensitive documents from victims.
Why it matters: Enterprise customers using Microsoft products face credential theft and data exfiltration; security teams should review endpoint detection and response (EDR) logs for ACR Stealer indicators and enforce stronger credential protections.
- regulatory
The Future of Age Verification: Your Face Never Leaves Your Device
Age verification laws are driving demand for privacy-preserving alternatives to traditional biometric collection. On-device age estimation processes facial data locally without transmitting or storing images, allowing organizations to meet regulatory mandates while minimizing biometric privacy exposure.
Why it matters: Organizations subject to age verification requirements need compliance methods that reduce regulatory and privacy litigation risk; on-device processing shifts the risk calculus away from centralized data storage.
- regulatory
NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data
New York Attorney General Letitia James and a coalition of 42 state attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' genetic data. The enforcement action stems from inadequate security practices that exposed sensitive information. California's Attorney General has also initiated separate litigation against the company under state privacy laws.
Why it matters: Genetic data users and companies handling sensitive health information need to understand that state attorneys general are actively enforcing data protection standards, and 23andMe's settlement signals regulatory expectations for biometric and genetic data security.
- threat intel
Your Period Tracker Is (Probably) Spying on You
A news roundup covers concerns about period tracking applications collecting and potentially sharing user data, Russian cyber operations targeting infrastructure, a Department of Homeland Security incident involving repeated intrusions before detection, and a breach revealing unauthorized data scraping by an AI music generator.
Why it matters: Practitioners need to understand consumer privacy risks in health and productivity apps, defend critical infrastructure against nation-state actors, investigate detection gaps in federal systems, and address data governance in AI training pipelines.
- ai security
Prompt Injection Attacks Are Thwarting AI Hacking Agents
Researchers have identified a technique called context bombing that can trick malicious artificial intelligence agents into disabling themselves before launching attacks. The method works by overwhelming AI systems with irrelevant or conflicting information that causes them to halt execution.
Why it matters: Security practitioners need to understand both the defensive value of context bombing and its limitations as AI-powered attack tools evolve, ensuring defensive strategies remain effective against increasingly sophisticated autonomous threats.