Cyber Alerts
Verified· Officially confirmed
Recently, the Joomla Content Editor (JCE) maintainers has released a security update in the JCE extension tracked as CVE-2026-48907, an unauthenticated remote code execution vulnerability.
Cyber Alerts
Verified· Officially confirmed
On 17 July 2026, WordPress released versions 6.9.5 and 7.0.2 to address a critical, unauthenticated Remote Code Execution (RCE) vulnerability in WordPress core, publicly referred to as "wp2shell". The flaw resides in the REST API batch-route handling and involves a route-confusion condition combined with an SQL injection weakness, allowing an anonymous attacker to execute arbitrary code on a default WordPress installation with no plugins required. The vulnerability was discovered and responsibly disclosed by a researcher at Assetnote (Searchlight Cyber) through the official WordPress HackerOne program. WordPress has enabled forced auto-updates to push the patch to affected sites, though sites with auto-updates disabled must verify and patch manually. 2.0 Technical DetailsVulnerability class: REST API batch-route confusion combined with SQL Injection, leading to Remote Code Execution. Attack vector: Unauthenticated / anonymous HTTP request — no prior access or credentials required.Affected component: WordPress REST API batch endpoint (/wp-json/batch/v1 and the rest_route=/batch/v1 query-string equivalent).Files modified in the fix: wp-includes/rest-api/class-wp-rest-server.php, wp-includes/class-wp-query.php, wp-includes/rest-api.php.CVE-2026-63030 — the REST API batch-route confusion / RCE chain; CVSS 7.5 per the official GitHub Security Advisory (GHSA-ff9f-jf42-662q), rated Critical severity by WordPress; some third-party exploit-tracking listings report scores as high as 9.8. Affects WordPress 6.9 and later.CVE-2026-60137 — the underlying SQL injection (in the author__not_in parameter of WP_Query), affecting WordPress 6.8 and later; fixed in 6.8.6 for the 6.8 branch.Per Cloudflare's analysis, the RCE path is reachable specifically when a persistent object cache is not enabled on the target site.The two CVEs must be chained together to achieve full remote code execution; CVE-2026-60137 alone permits blind SQL injection but not code execution. Full technical exploitation details have not been publicly released by the discovering researcher; a self-service checker has been made available to allow site owners to test their own instances. 3.0 Affected Versions Affected Branch Fixed In 6.9.0 – 6.9.4 6.9.5 7.0.0 – 7.0.1 7.0.2 7.1 (beta) 7.1 beta2 (fix included) 6.8.x (unrelated SQLi) 6.8.6
Cyber Alerts
Verified· Officially confirmed
Recently, the Cybersecurity and Infrastructure Security Agency (CISA) released a security alert warning organisations of the active exploitation of multiple vulnerabilities affecting on-premises Microsoft SharePoint Server. The vulnerabilities, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, could allow cyber threat actors to gain unauthorised access to vulnerable systems, execute arbitrary code remotely, and conduct malicious post-exploitation activities.
Cyber Alerts
Verified· Officially confirmed
Recently, Microsoft has released security updates on a high-severity local elevation-of-privilege vulnerability (CVE-2026-56155) in Microsoft Active Directory Federation Services (AD FS).
Cyber Alerts
Verified· Officially confirmed
Recently, Microsoft has released security updates on a missing authentication for critical function vulnerability in on-premises Microsoft SharePoint Server.
Cyber Alerts
Verified· Officially confirmed
Recently, Zoom has released a security update to address a critical vulnerability (CVE-2026-53412) affecting the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and the Zoom Meeting SDK for Windows.
Cyber Alerts
Verified· Officially confirmed
Recently, Oracle has released a security update to address a vulnerability in the Oracle E-Business Suite Improper Privilege Management vulnerability.
Cyber Alerts
Verified· Officially confirmed
Recently, Adobe has released security updates for ColdFusion versions 2023 and 2025 in its product.
Cyber Alerts
Verified· Officially confirmed
Published date: 26 July 2026, 3:31 pm
Cyber Alerts
Verified· Officially confirmed
Recently, the Cyber999 Incident Response Centre has been observing a notable increase in ransomware-related incidents targeting organisations across Malaysia. These attacks have affected a wide range of sectors, including businesses, hence highlighting the growing threat posed by ransomware threat actors. Ransomware activity continued at a significant pace into 2026. Building on the 51 incidents recorded throughout 2025, the first two quarters of 2026 alone accounted for 29 incidents (17 in Q1, 12 in Q2), signalling that ransomware remains a sustained operational risk rather than a diminishing one. Active Threat Groups identified across Q1 and Q2 2026 include LockBit, The DragonHorse, Qilin, Akira, Lynx Group, Black Shatrac, Thegentlemen, CrySiS, Obscura, Skynet, Ransom24 Group, DeadLock, and INC Ransom, alongside several unidentified variants. Threat actors continue to leverage compromised credentials (often harvested via Infostealers), unpatched vulnerabilities, and social engineering to gain initial entry. Organisations must reinforce infrastructure defences and ensure rapid incident reporting to mitigate nationwide impact. 2.0 Impacts Below is the list of ransomware impacts that could be devastating to organisations: Service Interruption: Customer-facing services may go offline, damaging trust and reputation.System and network infrastructure compromised.Files on the infected computer are encrypted, and the owner cannot access the files until a ransom (usually in a cryptocurrency such as Bitcoin) is paid.System Downtime: Ransomware often encrypts critical data and systems, halting business operations.Business operations are disrupted due to permanent or temporary loss of sensitive or proprietary data belonging to an organisation.Aside from financial gain, it exploits sensitive data and uses it as a levy. If the ransom is not paid within time, organisations’ confidential data are exposed, and trade secrets are compromised.Financial loss: Some organisations may feel pressured to pay the ransom, which can be substantial. Restoring systems, conducting forensics, and improving security can be very expensive. A data breach can result in reputational harm to the government and diminish trust in government digital transformation programmes.
Cyber Alerts
Verified· Officially confirmed
Recently, Fortinet has released security updates to address multiple vulnerabilities in Fortinet products.
Cyber Alerts
Verified· Officially confirmed
Recently, Cisco has released security updates to address an arbitrary file write vulnerability (CVE-2026-20262) affecting Cisco Catalyst SD-WAN Manager.