♡ Follow 0
Critical CVEs
A high-severity path traversal vulnerability in the open-source developer platform Windmill, tracked as CVE-2026-29059 (CVSS 7.5), is under active exploitation. The flaw…
active exploitation
CISA
CISA KEV
CVE-2021-27137
July 22, 2026
♡ Follow 0
Critical CVEs
WordPress Core Interpretation Conflict Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based…
CISA KEV
Core
CVE-2026-63030
WordPress
July 21, 2026
♡ Follow 0
Critical CVEs
WordPress Core SQL Injection Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based…
CISA KEV
Core
CVE-2026-60137
WordPress
July 21, 2026
♡ Follow 0
Attack Groups
A solo Russian-speaking threat actor known as "bandcampro" has been observed using Google's open-source Gemini CLI AI to control a botnet of…
AI-assisted cybercrime
AntiPublic
bandcampro
botnet
July 20, 2026
♡ Follow 0
Critical CVEs
A critical unauthenticated remote code execution vulnerability has been discovered in WordPress core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.…
Assetnote
batch-route confusion
core vulnerability
CVE-2026-XXXX
July 17, 2026
♡ Follow 0
Cyber News
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
AI
Android
backdoor
BlackFile
July 13, 2026
♡ Follow 0
Attack Groups
SHELLSTORM is a large-scale operation that exploited 27 CVEs in WordPress plugins to deploy web shells on over 1.4 million domains. The…
Chinese threat actor
SHELLSTORM
SNOWLIGHT
VShell
July 13, 2026
♡ Follow 0
Critical CVEs
A vulnerability in the Gravity Forms WordPress plugin exploited in a global CMS campaign for web shell deployment.
CMS
CVE-2025-12352
Gravity Forms
web shell
July 13, 2026
♡ Follow 0
Cyber Products
A WordPress plugin targeted in a global CMS exploitation campaign for web shell deployment.
plugin
vulnerability
WordPress
WPBookit
July 13, 2026
♡ Follow 0
Cyber Products
A WordPress plugin for form building, targeted in a global CMS exploitation campaign for web shell deployment.
Gravity Forms
plugin
vulnerability
WordPress
July 13, 2026