Vulnerabilities

A close-up, macro, photoreal, news-editorial shot of a tangled cluster of worn ethernet and USB cables plugged into a dusty server strip, bathed in the cool blu
Vulnerabilities

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In

Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a server rack with a single network appliance highlighted by red status LEDs, blurred data center aisle in b
Vulnerabilities

SonicWall Security Devices Were Hacked for Weeks Before a Fix Existed

Criminals planted hidden malware inside SonicWall remote-access appliances at least three weeks before the manufacturer knew the attack routes existed. Two fresh vulnerabilities, now patched, gave intruders near-total control of the devices.

3 min read
Full-frame edge-to-edge overhead photograph of a large server room aisle at night, cool blue LED indicator lights along both rows of racks, one rack door left s
Vulnerabilities

The Real Mythos Problem Isn't New Bugs. It's How Long Yours Stay Open.

Anthropic's AI-driven vulnerability finder has flooded the pipeline since April. But the harder question for defenders is how many days a known flaw sits unpatched on their own network.

4 min read
A digital lock symbol over a network diagram, representing cybersecurity
Vulnerabilities

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In

A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

3 min read
Full-frame edge-to-edge photoreal editorial shot of a dimly lit corporate server room, rows of rack-mounted servers with amber and red status LEDs glowing, one
Vulnerabilities

Microsoft admits Windows update server sync has been broken for over a week

WSUS synchronization failures have blocked enterprise Windows updates since July 13, 2026, with only new installations fully restored so far.

4 min read
Full-frame photoreal editorial image of a modern enterprise data centre corridor at night, glowing amber server indicator lights reflecting off a polished floor
Vulnerabilities

Hackers Start Breaking Into ServiceNow AI Platform Through Critical Flaw CVE-2026-6875

Attackers are exploiting a pre-authentication bug in ServiceNow's flagship platform just days after patches shipped, researchers confirm.

4 min read
Photoreal news-editorial overhead shot of a darkened security operations center desk, multiple monitors glowing blue with abstract vulnerability dashboards and
Vulnerabilities

Google Patches Seven Memory Safety Bugs in Chrome 150, Three Rated Critical

All seven flaws were found internally or by researchers, not by criminals. But history says patch fast anyway.

3 min read
Macro photograph of tangled fiber optic cables glowing in deep blue and green light against a dark server room background, sharp focus on the glass fiber tips w
Vulnerabilities

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk

A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

3 min read
Full-frame photoreal editorial image of a dimly lit server rack in a data centre, one status light glowing red among rows of green, cool blue ambient lighting,
Vulnerabilities

Critical NGINX Flaw Lets Attackers Crash Web Servers From Afar

F5 has patched CVE-2026-42533, a memory bug in nginx that a remote attacker can trigger with a single crafted request.

3 min read
Photoreal news-editorial image, 16:9, full-frame edge to edge, close-up of a rack-mounted network security appliance in a dim server room, glowing blue and ambe
Vulnerabilities

SonicWall VPN Appliances Hit by Zero-Day Attacks Weeks Before Public Warning

A newly identified group, tracked as UTA0533, broke into SonicWall SMA 1000 devices using unknown flaws from late June 2026, gaining the highest level of access.

3 min read
Full-frame photoreal editorial shot of a laptop screen showing a generic file-archive dialog with a compressed folder icon highlighted, warm desk lamp light, ou
Vulnerabilities

7-Zip Ships Emergency Fix for Flaw That Lets Booby-Trapped Archives Run Code

Version 26.02 patches a heap buffer overflow in XZ decompression. There is no auto-update, so users have to grab it themselves.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit server room aisle at night, rows of humming rack-mounted servers with soft blue and amber
Vulnerabilities

A WordPress Bug Lets Strangers Run Code on Your Site. No Login Required.

Every WordPress 6.9 and 7.0 site was exposed until a Friday emergency patch. The fix is being force-installed.

3 min read
Photoreal editorial shot of a dimly lit server rack with a single glowing amber warning light, faint reflections of code on the metal, shallow depth of field, c
Vulnerabilities

Ransomware Gang Exploited Two SonicWall Security Flaws Before a Fix Existed

A group tied to Inc ransomware broke into enterprise networks through a pair of critical holes in SonicWall remote-access devices, stealing credentials and preparing to lock down files.

3 min read
Photoreal editorial shot of a server rack in a dim data centre, one blade glowing faintly red, cables neatly arranged, shallow depth of field, edge-to-edge comp
Vulnerabilities

An 11-byte message can knock OpenSSL servers offline, researchers warn

A newly disclosed flaw nicknamed HollowByte lets attackers exhaust memory on servers running vulnerable versions of OpenSSL, the software that secures most of the web.

4 min read
Full-frame photoreal editorial shot of a dimly lit server room with a single rack unit highlighted by a red status LED, blurred network cables in the foreground
Vulnerabilities

OnlyFans Creators Are Accidentally Fixing Government Website Security

Adult content creators filing copyright takedowns are, as a side effect, helping university and government IT teams find hacked pages on their own websites.

3 min read
© 2026 Threat Vectr