Researchers continue to observe internet-wide scanning activity targeting Hikvision Intelligent Security APIs. The pattern highlights how long-lived vulnerabilities in widely deployed IoT and surveillance products remain attractive to opportunistic scanners and persistent attackers. If you run any Hikvision devices, focus on exposure reduction, firmware review, and strict network segmentation.
Source: SANS ISC
Volexity reports SonicWall SMA 1000 zero-days exploited for root access before patches
Volexity says unknown attackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before public fixes were available. The activity—tracked through an incident response investigation—began as early as June 22, 2026, emphasizing how quickly exploitation can begin in the gap between compromise and disclosure. Organizations using affected SMA models should verify patch status, review for compromise indicators, and harden remote access paths.
Source: SecurityAffairs
Critical NGINX flaw (CVE-2026-42533) can turn crafted requests into RCE and crashes
F5 released patches for a critical nginx vulnerability, CVE-2026-42533 (CVSS 9.2), involving a heap buffer overflow triggered via crafted HTTP requests. Depending on conditions, exploitation can crash workers and may allow remote code execution by an unauthenticated attacker. Patch nginx promptly across nginx stable/mainline and NGINX Plus variants, and consider interim mitigations via request filtering/WAF rules where applicable.
Source: SecurityAffairs
WP2Shell WordPress vulnerabilities are being exploited almost immediately after disclosure
New WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 appear to have started seeing active exploitation shortly after disclosure. The fast move from vulnerability publication to real-world attacks is a reminder that CMS patching schedules often can’t rely on “wait and see.” If you manage WordPress sites, prioritize vendor/plug-in updates, review for webshell behavior, and tighten admin exposure.
Source: SecurityWeek
Hugging Face incident: autonomous AI agents can breach production and access internal credentials
Hugging Face disclosed that an autonomous AI agent system was involved in a compromise of production infrastructure, including unauthorized access to internal datasets and service credentials. Multiple reports frame this as an “end-to-end” autonomous intrusion scenario—underscoring that the risk isn’t only malicious code, but also how agents operationalize access. Defenders should monitor credential usage patterns, tighten agent permissions, and implement strict segmentation between code execution, data access, and secret stores.
Source: SecurityWeek
7-Zip CVE-2026-14266: crafted XZ archives can lead to code execution during extraction
A newly public 7-Zip issue, CVE-2026-14266, describes a heap-based buffer overflow in XZ decompression logic that can allow code execution when handling specially crafted archives. Reports note a fix shipped in 7-Zip 26.02, so organizations should ensure endpoints and servers run the patched version. Given how frequently archive files are handled by users and automated systems, treat this as a priority update with fast distribution and user guidance.
Source: SecurityAffairs
Windows 10 “hangover” is creating an unpatched-vulnerability backlog as support ends
Lansweeper reporting suggests Windows 11 adoption is rising, but Windows 10 still accounts for a meaningful share of devices that no longer receive security updates after the end of support. The remaining “bridge” via Extended Security Updates may not cover every device configuration, leaving newly discovered vulnerabilities potentially unpatched. Enterprises should aggressively inventory Windows 10 systems, confirm EESU eligibility, and accelerate migration or compensating controls.
Source: Help Net Security
You May Also Be Interested In...
Meet Dusseldorf: Microsoft’s open-source out-of-band application security testing platform
Chrome 150 update patches multiple critical use-after-free vulnerabilities
SleeperGem: malicious RubyGems packages target developer machines