wp2shell: WordPress Patches a Pre-Auth RCE That Needed No Plugins
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution.
Latest Hacking News is the one-stop destination to find all the latest cyber security news, articles on hacking, network security, and more.
WordPress 6.9.5 and 7.0.2 fix wp2shell, a core REST API bug chaining route confusion and SQL injection into unauthenticated remote code execution.
A heap-based buffer overflow in 7-Zip’s XZ decoder, patched in version 26.02, let a crafted archive run code on extraction and had gone unnoticed for five years.
An AI-driven threat actor called JADEPUFFER built ransomware that hunts AI model files specifically, entering through a known Langflow RCE and pivoting via an exposed Docker socket.
A practical checklist for the Azure DevOps MCP flaw that lets hidden PR comments hijack AI coding agents, plus the configuration changes to make right now.
Cisco Talos has detailed msaRAT, a Rust-based RAT used by the Chaos ransomware crew that drives a headless Chrome or Edge session over CDP to smuggle C2 traffic through Cloudflare and Twilio infrastructure.
A three-line SVG gave XBOW SYSTEM access on Bing’s servers through a default ImageMagick setting. Here’s the exploit chain and a checklist for anyone running a similar image pipeline.
A practical checklist for the Fastjson RCE vulnerability (CVE-2026-16723): how the exploit chain works, four questions to answer this week, and how to mitigate it before a patch exists.
CISA added CVE-2026-48939 and CVE-2026-56291 to its Known Exploited Vulnerabilities catalog after automated attackers exploited file upload flaws in iCagenda and Balbooa Forms weeks before either bug had a CVE number.
ESET found 11 Microsoft-signed UEFI shims, some over a decade old, that let attackers bypass Secure Boot without a single new exploit.
GodDamn ransomware’s PoisonX driver is a textbook EDR bypass driver: a Microsoft-signed kernel driver that kills security tools instead of exploiting them.