2026-07-18
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- vulnerabilities
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 addresses a remote code execution vulnerability that could be exploited through specially crafted compressed files. The flaw allows attackers to execute code if users open malicious archives created by threat actors.
Why it matters: Any organization or user with 7-Zip installed faces code execution risk from archive files sent via email or downloads; update to version 26.02 immediately.
- vulnerabilities
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits are now available for critical remote code execution vulnerabilities in WordPress Core known as 'wp2shell'. WordPress administrators should apply patches immediately to mitigate active exploitation risk.
Why it matters: WordPress site operators face direct threat of remote code execution and site compromise; patching is urgent given public exploit availability.
- vulnerabilitiesCVE-2026-60137
Two new high severity WordPress vulnerabilities, patch immediately!
WordPress 7.0.2 patches one critical and one high severity vulnerability affecting WordPress 6.9. CVE-2026-60137 involves a facilitated SQL injection issue, while a separate REST application programming interface (API) batch-route confusion flaw can lead to remote code execution (RCE). Both require immediate patching.
Why it matters: WordPress site administrators running version 6.9 must update immediately to close SQL injection and RCE vectors that attackers can exploit remotely without authentication.
- threat intel
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has detected an increase in attacks leveraging ACR Stealer malware targeting its enterprise customers. The malware focuses on stealing browser-stored passwords, authentication tokens, and sensitive documents from victims.
Why it matters: Enterprise customers using Microsoft products face credential theft and data exfiltration; security teams should review endpoint detection and response (EDR) logs for ACR Stealer indicators and enforce stronger credential protections.
- regulatory
The Future of Age Verification: Your Face Never Leaves Your Device
Age verification laws are driving demand for privacy-preserving alternatives to traditional biometric collection. On-device age estimation processes facial data locally without transmitting or storing images, allowing organizations to meet regulatory mandates while minimizing biometric privacy exposure.
Why it matters: Organizations subject to age verification requirements need compliance methods that reduce regulatory and privacy litigation risk; on-device processing shifts the risk calculus away from centralized data storage.
- regulatory
NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data
New York Attorney General Letitia James and a coalition of 42 state attorneys general secured an $18 million settlement from genetic testing company 23andMe for failing to protect customers' genetic data. The enforcement action stems from inadequate security practices that exposed sensitive information. California's Attorney General has also initiated separate litigation against the company under state privacy laws.
Why it matters: Genetic data users and companies handling sensitive health information need to understand that state attorneys general are actively enforcing data protection standards, and 23andMe's settlement signals regulatory expectations for biometric and genetic data security.
- threat intel
Your Period Tracker Is (Probably) Spying on You
The article highlights concerns that period-tracking applications may be gathering users' reproductive health data without transparent consent. It notes that Russian cyber-espionage groups have shifted focus toward critical infrastructure, points out that the Department of Homeland Security (DHS) repeatedly missed indicators of its own breaches, and states that an artificial intelligence (AI) music generator was discovered to have scraped copyrighted material.
Why it matters: Individuals who use period-tracking apps are affected because their sensitive health data may be exposed without consent, so they should verify app permissions, select stricter sharing settings, and consider alternative tools.
- ai security
Prompt Injection Attacks Are Thwarting AI Hacking Agents
Researchers have identified a technique called context bombing that can trick malicious artificial intelligence agents into disabling themselves before launching attacks. The method works by overwhelming AI systems with irrelevant or conflicting information that causes them to halt execution.
Why it matters: Security practitioners need to understand both the defensive value of context bombing and its limitations as AI-powered attack tools evolve, ensuring defensive strategies remain effective against increasingly sophisticated autonomous threats.