Issue #208 - July 20, 2026
- Jul 20
- 2 min read
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Source: Dark Reading
Attackers are exploiting two critical WordPress flaws chained as WP2Shell to achieve unauthenticated remote code execution on default installations. The article reports widespread exploit attempts, public proof-of-concept activity, forced security updates, and guidance to inspect sites for backdoor accounts, malicious plugins, and suspicious files even after patching.
Critical ServiceNow code execution flaw now exploited in attacks
Source: BleepingComputer
BleepingComputer reports active exploitation of CVE-2026-6875, a critical ServiceNow AI Platform flaw that can allow unauthenticated sandbox escape and remote code execution in high-complexity attacks. ServiceNow says hosted instances have been addressed and urges customers to apply relevant updates, especially for self-hosted deployments.
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
Source: SecurityWeek
Nichirei disconnected systems after a cyberattack disrupted refrigerated warehouse and shipping operations across parts of its food and logistics business. SecurityWeek reports the company is gradually restoring service, investigating whether personal information was exposed, and has submitted an initial report to Japan’s Personal Information Protection Commission.
New Check Point Zero-Day Vulnerability Exploited in the Wild
Source: SecurityWeek
Check Point warned customers that CVE-2026-16232, an authentication bypass in Security Management and Multi-Domain Management products, has been exploited against certain internet-exposed environments. The flaw can allow attackers to obtain an application login token, access SmartConsole with administrator privileges, and change security policy or configuration.
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Source: BleepingComputer
BleepingComputer details how attackers exploited SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 as zero-days before public disclosure. Volexity linked the activity to a previously unknown actor using appliance-focused custom malware, webshells, proxy tooling, and access paths that could expose credentials and internal applications.



