HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of July 18, 2026.
-
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
— The Hacker News
An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.… -
Abbott probes two cyber incidents amid extortion claims
— Bleeping Computer
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Scie… -
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
— The Hacker News
Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems O… -
Inc Ransomware Exploits SonicWall SMA Zero-Days
— Dark Reading
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances. -
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
— The Hacker News
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of… -
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
— Bleeping Computer
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a … -
The Real AI Threat Is Blind Trust
— Dark Reading
AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. -
Ernst & Young discloses data breach after support system hack
— Bleeping Computer
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personn… -
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
— Dark Reading
The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's bein… -
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
— Unit 42
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent … -
ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
— Unit 42
Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, …
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (7909 in last 30 days).
Critical: 2 · High: 8 · Medium: 8 · Low: 2. View full dashboard →
-
CVE-2026-57980
— CVSS 5.4 (MEDIUM)
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. -
CVE-2026-56741
— CVSS 7.5 (HIGH)
JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS opt⦠-
CVE-2026-56740
— CVSS 7.5 (HIGH)
JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet⦠-
CVE-2026-56171
— CVSS 7.1 (HIGH)
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. -
CVE-2026-54335
— CVSS 3.7 (LOW)
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and earlier, the _.merge(target, source) utility exported by @feathersjs/commons recursively merges sour⦠-
CVE-2026-49485
— CVSS 7.5 (HIGH)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluat⦠-
CVE-2026-48049
— CVSS 5.3 (MEDIUM)
@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured with path in the directory or file handlers or relativeTo for h.file()⦠-
CVE-2026-48022
— CVSS 6.5 (MEDIUM)
@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hos⦠-
CVE-2026-55518
— CVSS 9.6 (CRITICAL)
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new ⦠-
CVE-2026-54498
— CVSS 8.7 (HIGH)
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the ⦠-
CVE-2026-54497
— CVSS 6.8 (MEDIUM)
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects across calls to render⦠-
CVE-2026-54244
— CVSS 3.5 (LOW)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked vi⦠-
CVE-2026-54243
— CVSS 6.1 (MEDIUM)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters wh⦠-
CVE-2026-54242
— CVSS 4.9 (MEDIUM)
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php and src/Imaging/GuzzleAdapter.php could be ⦠-
CVE-2026-54163
— CVSS 4.7 (MEDIUM)
secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_di⦠-
CVE-2026-54159
— CVSS 10.0 (CRITICAL)
PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, p⦠-
CVE-2026-50274
— CVSS 7.5 (HIGH)
Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incomi⦠-
CVE-2026-50272
— CVSS 7.5 (HIGH)
dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP hea⦠-
CVE-2026-50271
— CVSS 7.5 (HIGH)
Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or D⦠-
CVE-2026-49977
— CVSS 4.3 (MEDIUM)
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteaucâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · July 18, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com