← All threat briefs

Daily Cybersecurity Brief — 2026-07-21

SECURITY // 2026-07-21

Daily Cybersecurity Brief — 2026-07-21

Vulnerabilities & Exploits

  • WordPress wp2shell Exploitation Grows: Attackers are exploiting two critical vulnerabilities (CVE-2026-63030 and CVE-2026-60137) in WordPress to achieve unauthenticated remote code execution (RCE). (The Hacker News, 2026-07-21)
  • WP2Shell Remote Takeover: High impact vulnerability affecting millions of WordPress sites. (Dark Reading, 2026-07-20)

Ransomware & Malware

  • New ENCFORGE Ransomware: A new Go-based ransomware targeting AI model files, vector indexes, and training datasets in Langflow RCE attacks. (The Hacker News, 2026-07-21)
  • HOLLOWGRAPH Malware: Targets Microsoft 365 calendars as an espionage channel. (Help Net Security, 2026-07-20)

Data Breaches & Leaks

  • Estée Lauder Breach: A data breach at Estée Lauder has been linked to an Oracle EBS vulnerability. (Help Net Security, 2026-07-21)
  • Paidwork Breach: Exposure of sensitive data belonging to 23 million users. (Help Net Security, 2026-07-20)

Infrastructure & Cloud Security

  • AWS GuardDuty Enhancements: AWS announces automation for the initial steps of threat investigations using GuardDuty. (Help Net Security, 2026-07-21)
  • AI/Agentic Security Risks: Emerging concerns regarding AI agents logging in as humans and the risks posed by autonomous AI agents. (Help Net Security, 2026-07-21)

Enterprise & Industry News

  • CISO Pressure from AI: Approximately 26% of top security executives are considering leaving their positions due to increased pressures from rapid AI adoption. (Dark Reading, 2026-07-20)
  • Open Source Funding Challenges: Sponsorship for open-source maintainers has crossed $100 million, yet many remain underfunded. (Help Net Security, 202 6-07-21)
  • Android Security Updates: New features in Android aimed at protecting users from impersonation scams using AI deepfakes. (Google Security Blog, 2026-07-21)