SecurityTicks

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs 2026-07-19 at 10:09 By Anamarija Pogorelec Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security […]

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 2026-07-18 at 16:16 By Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Read More »

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 2026-07-18 at 16:16 By Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP request can run

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Read More »

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens 2026-07-18 at 16:16 By A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI,

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens Read More »

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 2026-07-18 at 16:16 By Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Read More »

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft 2026-07-18 at 16:16 By Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group),

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Read More »

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code 2026-07-18 at 02:12 By An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code Read More »

FTX to distribute $900M to creditors in fifth payment round

FTX to distribute $900M to creditors in fifth payment round 2026-07-18 at 00:40 By Cointelegraph by Turner Wright The FTX Recovery Trust and company have distributed about $10 billion since the exchange filed for bankruptcy in November 2022, leaving users cut off from their funds. This article is an excerpt from Cointelegraph.com News View Original

FTX to distribute $900M to creditors in fifth payment round Read More »

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests 2026-07-17 at 23:20 By Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests Read More »

Galaxy lands 15-year Texas Tech stadium naming rights deal

Galaxy lands 15-year Texas Tech stadium naming rights deal 2026-07-17 at 23:03 By Cointelegraph by Nate Kostar Galaxy Digital will rename Texas Tech’s football stadium under a 15-year agreement, expanding its West Texas presence as the state attracts growing crypto investment. This article is an excerpt from Cointelegraph.com News View Original Source

Galaxy lands 15-year Texas Tech stadium naming rights deal Read More »

Consensys unknowingly outsourced developer work to North Korean

Consensys unknowingly outsourced developer work to North Korean 2026-07-17 at 22:33 By Cointelegraph by Turner Wright Through an introduction with a “reputable third-party service provider,“ the company took on a developer who, as part of an investigation, was revealed to be tied to North Korea. This article is an excerpt from Cointelegraph.com News View Original

Consensys unknowingly outsourced developer work to North Korean Read More »

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT 2026-07-17 at 21:54 By Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT Read More »

Judge won’t block Meta from axing workers who filed AI discrimination lawsuit

Judge won’t block Meta from axing workers who filed AI discrimination lawsuit 2026-07-17 at 21:53 By Reuters Dozens of employees claimed that they were targeted for job cuts by the company’s AI-powered tools because they have disabilities or took medical leave. This article is an excerpt from Latest Technology News | New York Post View

Judge won’t block Meta from axing workers who filed AI discrimination lawsuit Read More »

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images 2026-07-17 at 20:32 By North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. “Any user who ran the

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images Read More »

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens 2026-07-17 at 20:12 By A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI,

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens Read More »

Senator Warren requests 2026 reporting for Trump’s crypto earnings after $1.4B disclosure

Senator Warren requests 2026 reporting for Trump’s crypto earnings after $1.4B disclosure 2026-07-17 at 19:48 By Cointelegraph by Turner Wright With the Senate likely voting on a crypto bill within days, Elizabeth Warren asked for information on Donald Trump’s earnings between January and July ahead of a 2027 deadline. This article is an excerpt from

Senator Warren requests 2026 reporting for Trump’s crypto earnings after $1.4B disclosure Read More »

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft 2026-07-17 at 19:39 By Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group),

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft Read More »

Scroll to Top