Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 19, 2026 This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised. Microsoft’s July Patch …

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 19, 2026 A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since …

Hugging Face Confirms AI-Driven Breach: Attackers used Autonomous Agents, defenders countered with AI

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 18, 2026 Hugging Face disclosed this week that it detected and contained a production infrastructure intrusion, driven end-to-end by an autonomous AI agent system, and defended against it using …

New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 18, 2026 New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours A previously unseen ransomware family dubbed “Spirals” struck an IT …

Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 18, 2026 Cloud Software Group has disclosed two security vulnerabilities affecting Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows, with one flaw allowing low-privileged …

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 18, 2026 A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover …

OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 …

Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed …

EY Data Breach – Hackers Gain Access to IT Support System and Download Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during …

PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 17, 2026 A new open-source tool is bringing autonomous AI agents into offensive security workflows. PentestCode, a hard fork of OpenCode rebuilt specifically for penetration testing, runs security tools, …