📰 DAILY THREAT BRIEFING
Sunday, July 19, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of July 19, 2026.

  1. Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
    — Bleeping Computer

    7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convin…
  2. WordPress Core "wp2shell" RCE flaws get public exploits, patch now
    — Bleeping Computer

    Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imp…
  3. Microsoft warns of surge in ACR Stealer attacks on customers
    — Bleeping Computer

    Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensit…
  4. New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
    — The Hacker News

    Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfa…
  5. OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
    — The Hacker News

    Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems O…
  6. Inc Ransomware Exploits SonicWall SMA Zero-Days
    — Dark Reading

    When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.
  7. Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
    — The Hacker News

    Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of…
  8. The Real AI Threat Is Blind Trust
    — Dark Reading

    AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.
  9. Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
    — Dark Reading

    The White House launched Gold Eagle to coordinate vulnerability response in a new AI world, but multiple questions linger over how it's bein…
  10. Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
    — Unit 42

    A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent …
  11. ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report
    — Unit 42

    Explore Unit 42's perspectives on AI's impact on cybersecurity, including key updates since the 2026 Incident Response Report. The post AI, …

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (7835 in last 30 days).
Critical: 0 · High: 5 · Medium: 13 · Low: 2. View full dashboard →

  1. CVE-2026-16199
    — CVSS 6.3 (MEDIUM)

    A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper autho…
  2. CVE-2026-16198
    — CVSS 5.6 (MEDIUM)

    A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of…
  3. CVE-2026-16197
    — CVSS 6.3 (MEDIUM)

    A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Su…
  4. CVE-2026-16196
    — CVSS 6.3 (MEDIUM)

    A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side re…
  5. CVE-2026-16195
    — CVSS 6.3 (MEDIUM)

    A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation result…
  6. CVE-2026-10130
    — CVSS 8.2 (HIGH)

    QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The…
  7. CVE-2026-16194
    — CVSS 6.3 (MEDIUM)

    A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-…
  8. CVE-2026-16156
    — CVSS 3.5 (LOW)

    A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It…
  9. CVE-2026-57857
    — CVSS 4.3 (MEDIUM)

    The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET paramet…
  10. CVE-2026-16155
    — CVSS 3.5 (LOW)

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross s…
  11. CVE-2026-16154
    — CVSS 7.3 (HIGH)

    A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argume…
  12. CVE-2026-16152
    — CVSS 7.3 (HIGH)

    A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The a…
  13. CVE-2026-12228
    — CVSS 8.7 (HIGH)

    A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.conte…
  14. CVE-2026-57848
    — CVSS 5.5 (MEDIUM)

    Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through…
  15. CVE-2026-53994
    — CVSS 7.5 (HIGH)

    ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity c…
  16. CVE-2026-16151
    — CVSS 6.3 (MEDIUM)

    A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads to improperly controlled modification of o…
  17. CVE-2026-16150
    — CVSS 6.3 (MEDIUM)

    A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal…
  18. CVE-2026-16133
    — CVSS 5.0 (MEDIUM)

    A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be laun…
  19. CVE-2026-16131
    — CVSS 6.3 (MEDIUM)

    A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is pos…
  20. CVE-2026-16130
    — CVSS 4.4 (MEDIUM)

    A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link f…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · July 19, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com