📰 DAILY THREAT BRIEFING
Saturday, July 18, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 18, 2026.

  1. New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
    — The Hacker News

    An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.…
  2. Abbott probes two cyber incidents amid extortion claims
    — Bleeping Computer

    Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Scie…
  3. OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
    — The Hacker News

    Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems O…
  4. Inc Ransomware Exploits SonicWall SMA Zero-Days
    — Dark Reading

    When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.
  5. Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
    — The Hacker News

    Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
  6. HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
    — Bleeping Computer

    A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a …
  7. The Real AI Threat Is Blind Trust
    — Dark Reading

    AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.
  8. Ernst & Young discloses data breach after support system hack
    — Bleeping Computer

    Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personn…
  9. Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
    — Dark Reading

    The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's bein…
  10. Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
    — Unit 42

    A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent …
  11. ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
    — Unit 42

    Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, …

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (7909 in last 30 days).
Critical: 2 · High: 8 · Medium: 8 · Low: 2. View full dashboard →

  1. CVE-2026-57980
    — CVSS 5.4 (MEDIUM)

    Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
  2. CVE-2026-56741
    — CVSS 7.5 (HIGH)

    JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS opt…
  3. CVE-2026-56740
    — CVSS 7.5 (HIGH)

    JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet…
  4. CVE-2026-56171
    — CVSS 7.1 (HIGH)

    Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
  5. CVE-2026-54335
    — CVSS 3.7 (LOW)

    Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and earlier, the _.merge(target, source) utility exported by @feathersjs/commons recursively merges sour…
  6. CVE-2026-49485
    — CVSS 7.5 (HIGH)

    HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluat…
  7. CVE-2026-48049
    — CVSS 5.3 (MEDIUM)

    @hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static files from a directory configured with path in the directory or file handlers or relativeTo for h.file()…
  8. CVE-2026-48022
    — CVSS 6.5 (MEDIUM)

    @hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hos…
  9. CVE-2026-55518
    — CVSS 9.6 (CRITICAL)

    Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association attach workflow checks attach_<association>? in the UI and GET /resources/:resource/:id/:related/new …
  10. CVE-2026-54498
    — CVSS 8.7 (HIGH)

    view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base#around_render can return HTML-unsafe strings that bypass the …
  11. CVE-2026-54497
    — CVSS 6.8 (MEDIUM)

    view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain render-scoped objects across calls to render…
  12. CVE-2026-54244
    — CVSS 3.5 (LOW)

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked vi…
  13. CVE-2026-54243
    — CVSS 6.1 (MEDIUM)

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters wh…
  14. CVE-2026-54242
    — CVSS 4.9 (MEDIUM)

    Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php and src/Imaging/GuzzleAdapter.php could be …
  15. CVE-2026-54163
    — CVSS 4.7 (MEDIUM)

    secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_di…
  16. CVE-2026-54159
    — CVSS 10.0 (CRITICAL)

    PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsearch module rebuilds selected search filters from the request URL, and the value of a slider filter, p…
  17. CVE-2026-50274
    — CVSS 7.5 (HIGH)

    Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incomi…
  18. CVE-2026-50272
    — CVSS 7.5 (HIGH)

    dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP hea…
  19. CVE-2026-50271
    — CVSS 7.5 (HIGH)

    Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or D…
  20. CVE-2026-49977
    — CVSS 4.3 (MEDIUM)

    tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check whether the element is a legitimate tarteauc…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 18, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com