WordPress wp2shell RCE Flaw: Patch Now, Public Exploits Active

Wordpress-wp2shell

WordPress Core “wp2shell” RCE Flaw: Public Exploits Now Circulating; Patch Immediately A critical pre-authentication remote code execution vulnerability in WordPress Core, dubbed wp2shell, is now under active exploitation after proof-of-concept code surfaced publicly. The flaw, tracked as CVE-2026-63030, allows an unauthenticated attacker to take complete control of a WordPress site with no login credentials, no … Read more

Microsoft June 2026 Patch Tuesday: 6 Zero-Days, 200 Flaws

Microsoft June 2026 Patch Tuesday: 6 Zero-Days and 200 Vulnerabilities Demand Immediate Action Microsoft has released its June 2026 Patch Tuesday security updates, closing 200 vulnerabilities across its product ecosystem, including six zero-day flaws, one of which is confirmed to be actively exploited in live attacks. This is one of the heaviest Patch Tuesday releases … Read more

Microsoft enforces registered-only authentication for Entra ID

Microsoft-Entra-ID-Changes-auth

Microsoft Entra ID SSPR Will Only Accept Registered Authentication Methods Starting September 2026 Microsoft has formally notified customers that a significant shift is coming to how Microsoft Entra ID handles identity verification during Self-Service Password Reset (SSPR). Under Message Center update MC1325414, the company is moving to a model where only explicitly registered authentication methods … Read more

PAN-OS GlobalProtect Auth Bypass CVE-2026-0257 Exploited

PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Is Being Actively Exploited Right Now A confirmed, in-progress attack campaign is targeting enterprise VPN infrastructure globally, and Canadian organizations are directly in the line of fire. Palo Alto Networks has confirmed that CVE-2026-0257, a PAN-OS GlobalProtect authentication bypass flaw carrying a CVSS score of 7.8, is under active exploitation. … Read more

Zero-Click WhatsApp Attack Hijacks iOS 16 Accounts Silently

Silent Threat: Zero-Click WhatsApp Attack Is Hijacking iOS 16 Accounts Without Warning A newly documented zero-click WhatsApp account takeover attack is compromising iPhones running iOS 16 without any interaction from the device owner. Victims have had unauthorized messages sent from their accounts, including fraudulent money transfer requests, while their WhatsApp app showed no sign of … Read more