July 18, 2026 A critical pre-authentication remote code execution (RCE) vulnerability dubbed “wp2shell” has been discovered in WordPress Core, putting an estimated 500 million+ websites at risk of full takeover by unauthenticated attackers. Security researcher Adam Kues of Searchlight Cyber’s …
OpenSSL “HollowByte” Vulnerability Lets Hackers Crash Servers With Just 11 Bytes
July 17, 2026 A newly disclosed vulnerability in OpenSSL, dubbed “HollowByte,” allows a remote, unauthenticated attacker to trigger a denial-of-service (DoS) condition using a malicious payload as small as 11 bytes. Discovered by the Okta Red Team, the flaw exploits …
Ransomware Attack on Coca-Cola-Owned Fairlife Halts Production Across the United States
July 17, 2026 Coca-Cola has reported a ransomware attack affecting its dairy subsidiary, Fairlife, resulting in a temporary shutdown of production operations across the United States. This incident was disclosed in a Form 8-K filing submitted to the U.S. Securities …
EY Data Breach – Hackers Gain Access to IT Support System and Download Documents
Ernst & Young LLP (EY) is notifying clients that an unauthorized third party breached a support ticket platform used by its IT staff, downloading documents containing client tax data during a roughly two-week window this spring. The Big Four accounting …
PentestCode – New AI Agent That Automates Penetration Testing with 18 Specialized Tools
July 17, 2026 A new open-source tool is bringing autonomous AI agents into offensive security workflows. PentestCode, a hard fork of OpenCode rebuilt specifically for penetration testing, runs security tools, analyzes their output, and makes tactical decisions all from a …
New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user …
AWS Cost Explorer Bug Shows Trillion-Dollar Billing Estimates
July 17, 2026 AWS customers worldwide were startled after the AWS Billing and Cost Management Console and Cost Explorer began displaying extraordinarily high projected cloud costs. Some organizations reported estimated monthly bills reaching trillions of dollars, triggering budget alerts and …
New ClickLock macOS Stealer Kills Every App to Force Password Entry
July 17, 2026 New ClickLock macOS Stealer Kills Every App to Force Password Entry A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques. According to researchers at Group-IB, …
CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks
July 17, 2026 CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems …
Top 10 Best Identity Threat Detection and Response (ITDR) Solutions in 2026
Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000 …
