Daily Cybersecurity Brief — 2026-07-21
Vulnerabilities & Exploits
- WordPress wp2shell Exploitation Grows: Attackers are exploiting two critical vulnerabilities (CVE-2026-63030 and CVE-2026-60137) in WordPress to achieve unauthenticated remote code execution (RCE). (The Hacker News, 2026-07-21)
- WP2Shell Remote Takeover: High impact vulnerability affecting millions of WordPress sites. (Dark Reading, 2026-07-20)
Ransomware & Malware
- New ENCFORGE Ransomware: A new Go-based ransomware targeting AI model files, vector indexes, and training datasets in Langflow RCE attacks. (The Hacker News, 2026-07-21)
- HOLLOWGRAPH Malware: Targets Microsoft 365 calendars as an espionage channel. (Help Net Security, 2026-07-20)
Data Breaches & Leaks
- Estée Lauder Breach: A data breach at Estée Lauder has been linked to an Oracle EBS vulnerability. (Help Net Security, 2026-07-21)
- Paidwork Breach: Exposure of sensitive data belonging to 23 million users. (Help Net Security, 2026-07-20)
Infrastructure & Cloud Security
- AWS GuardDuty Enhancements: AWS announces automation for the initial steps of threat investigations using GuardDuty. (Help Net Security, 2026-07-21)
- AI/Agentic Security Risks: Emerging concerns regarding AI agents logging in as humans and the risks posed by autonomous AI agents. (Help Net Security, 2026-07-21)
Enterprise & Industry News
- CISO Pressure from AI: Approximately 26% of top security executives are considering leaving their positions due to increased pressures from rapid AI adoption. (Dark Reading, 2026-07-20)
- Open Source Funding Challenges: Sponsorship for open-source maintainers has crossed $100 million, yet many remain underfunded. (Help Net Security, 202 6-07-21)
- Android Security Updates: New features in Android aimed at protecting users from impersonation scams using AI deepfakes. (Google Security Blog, 2026-07-21)