CyberSecurityNews

Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories


This week’s cybersecurity situation shows a clear reality: every part of technology, from identity systems to common productivity tools, can be hacked or compromised.

Microsoft’s July Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already being exploited in the wild against SharePoint Server and Active Directory Federation Services, signaling that attackers are moving faster than ever from disclosure to weaponization.

Meanwhile, the wp2shell RCE vulnerability puts more than 500 million WordPress sites at risk of unauthenticated takeover, and Ernst & Young’s disclosure of a breach affecting client tax and investment data reminds us that even the largest professional services firms remain attractive targets.

Beyond traditional vulnerabilities, this issue also captures a growing trend: AI systems themselves are becoming attack surfaces. From a flaw in Claude for Chrome to the novel GhostCommit technique hiding malicious prompts inside code commits, and an exploit chain pairing GPT-5/6 models with Chrome, adversaries are actively probing AI-integrated workflows.

Rounding out this edition are critical patches from Fortinet, F5, Splunk, and Dell, plus a malicious Chrome extension caught exfiltrating browsing data from over a million users. Here’s your complete rundown of this week’s 20+ stories shaping the threat landscape.

Massive Microsoft Patch Tuesday: 570 Vulnerabilities Fixed

Microsoft’s July 2026 Patch Tuesday addressed roughly 570 vulnerabilities, including two actively exploited zero-days — CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services — plus a publicly disclosed BitLocker bypass bug.

New wp2shell RCE Vulnerability Hits WordPress

A critical pre-authentication RCE flaw dubbed “wp2shell,” tracked as CVE-2026-60137 and CVE-2026-63030, exposes over 500 million WordPress sites to unauthenticated takeover via a REST API batch-route SQL injection chain.

LegacyHive Windows Zero-Day PoC Released

Researcher Nightmare-Eclipse released a proof-of-concept called LegacyHive that exploits the Windows User Profile Service to let a standard user load another account’s registry hive, working even on systems with July 2026 patches applied.

macOS Stealer Mimics Apple Crash Reports

This story details a new macOS information-stealing malware campaign that disguises its payload as legitimate Apple crash-report dialogs to trick users into granting access or credentials.

EY Data Breach Exposes Client Tax Data

Ernst & Young confirmed an unauthorized third party accessed its IT support ticket platform between March 28 and April 12, 2026, downloading client tax and investment-holding documents before detection nearly three weeks later .

The popular ModHeader extension, with 1.6 million installs, was removed from Chrome and Edge stores after researchers found dormant code capable of encrypting and uploading users’ browsing history to an external server .

Notepad++ Patches Command Injection and Four Other Flaws

Notepad++ v8.9.7 fixes a high-risk installer-time PowerShell command injection bug alongside a stack buffer overflow, a Zip Slip path traversal issue, a session-validation bypass, and a macro integrity bypass .

Active Directory Zero-Day Exploited in the Wild

This report covers active exploitation of a zero-day flaw in Active Directory-related services, highlighting risks to enterprise identity infrastructure.

Dell BIOS Flaw Exposes Admin Passwords

A vulnerability in Dell BIOS firmware reportedly allows exposure or extraction of administrator passwords, raising concerns for enterprise device fleets.

7-Zip Vulnerability Enables Code Execution

A flaw in the widely used 7-Zip archiving tool allows attackers to achieve code execution, likely through crafted archive files.

F5 Patches Multiple Nginx Vulnerabilities

F5 has issued patches addressing several vulnerabilities affecting Nginx components within its product line, closing off potential exploitation vectors.

Claude for Chrome Vulnerability Disclosed

A security flaw was identified in the Claude for Chrome browser integration, raising concerns about AI-assistant browser extensions and their attack surface.

GhostCommit Attack Hides Malicious Prompts

The “GhostCommit” technique conceals malicious AI prompts within code commits, potentially manipulating AI coding assistants without developer awareness.

GPT-5/6 “Sol” Chrome Exploit Chain Uncovered

Researchers detail an exploit chain combining GPT-5/6-era AI models (“Sol”) with Chrome browser vulnerabilities, illustrating emerging AI-assisted attack techniques.

Multiple Splunk Enterprise Vulnerabilities Patched

Splunk has released fixes for several vulnerabilities in its Enterprise product, addressing issues that could affect data integrity and platform security.

Fortinet Patches Seven Vulnerabilities

Fortinet issued patches for seven vulnerabilities across its security product portfolio, part of its routine advisory cycle.

Dell Laptops Shutting Down After July Update

A separate Dell issue is causing laptops to unexpectedly shut down following the July 2026 update, distinct from the BIOS password flaw reported elsewhere this week.

AWS Cost Explorer Bug Raises Security Concerns

A bug discovered in AWS Cost Explorer reportedly creates unintended security or data-exposure risks for cloud customers monitoring billing data.

A security flaw affecting TP-Link camera devices could allow attackers to compromise device functionality or access video feeds.



Source link