Vulnerabilities
8 storiesWordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits for the wp2shell WordPress core RCE are now circulating—this second advisory underscores the urgency for any organisation still unpatched.
BleepingComputer9/10New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Unauthenticated RCE in WordPress core ('wp2shell') now has a public exploit—given WordPress's dominance in European web infrastructure, this demands emergency patching.
THN (Feedburner)9/10Inc Ransomware Exploits SonicWall SMA Zero-Days
Inc ransomware operators are chaining two SonicWall SMA zero-days for root-level access—any European enterprise using these appliances faces an active perimeter-breach threat.
Dark Reading9/10[NEU] [kritisch] Microsoft Windows Produkte: Mehrere Schwachstellen
CERT-Bund rates multiple Windows flaws as critical — covering RCE, privilege escalation, and DoS — making this July Patch Tuesday cycle one European enterprises cannot defer.
CERT-Bund (BSI)9/10New Windows LegacyHive zero-day gives hackers admin privileges
A researcher has publicly dropped a Windows privilege-escalation zero-day — fully patched systems are affected, leaving defenders reliant on detection and compensating controls until Microsoft responds.
BleepingComputer9/10[NEU] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
BSI flags high-severity Splunk Enterprise vulnerabilities allowing security bypass and data exposure — a compromised SIEM undermines the entire detection and response capability.
CERT-Bund (BSI)8/10[UPDATE] [mittel] Argo CD: Mehrere Schwachstellen
BSI warns of medium-severity Argo CD flaws combining information disclosure with XSS that could escalate to admin privileges — a significant risk for organisations relying on GitOps-driven deployments.
CERT-Bund (BSI)8/10[NEU] [hoch] Microsoft DeveloperTools: Mehrere Schwachstellen
BSI rates multiple Microsoft developer-tool flaws as high severity, covering privilege escalation to admin and arbitrary code execution across VS Code, .NET, and Visual Studio.
CERT-Bund (BSI)8/10
Threat Intel
6 storiesUAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
Talos discloses UAT-11795, a Russian-speaking group deploying a novel Starland RAT and custom C2 implant against European and U.S. targets via trojanized collaboration apps—raising supply-chain trust questions for enterprises relying on consumer-grade installers.
Cisco Talos9/10GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
The DigiCert breach, now attributed to a GoldenEyeDog subgroup dubbed CylindricalCanine, compromised code-signing certificates — a supply-chain trust crisis that demands immediate certificate-inventory review.
THN (Feedburner)9/10Sandworm hackers have a CAPTCHA trick for Ukrainians
Russia's Sandworm group deploys fake CAPTCHA pages tricking Ukrainian users into pasting PowerShell payloads — a social-engineering vector easily portable to European targets.
The Record8/101M+ Emails Use Hidden Text to Dupe AI Security Filters
Over one million phishing emails reportedly bypass AI-driven filters by injecting invisible characters — a technique that exploits how LLMs tokenise text and could hit any organisation relying solely on AI-based email defence.
Dark Reading8/10There and Back Again: An Operators Guide on NTLM Relaying Egress
SpecterOps details how attackers revive NTLM relay via coerced SMB egress when local escalation is blocked—a reminder that legacy authentication debt still creates real lateral-movement paths.
SpecterOps8/10Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
China-linked kernel rootkit Daxin has re-emerged in a Taiwanese manufacturer after a four-year hiatus, accompanied by the newly discovered Stupig pre-login backdoor—flagging persistent espionage risk for firms with APAC supply chains.
THN (Feedburner)8/10
AI Security
3 storiesAgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems
AgentWorm shows that autonomous LLM agents in interconnected ecosystems can propagate attacks laterally without human intervention — a worm-class threat that enterprise AI governance must now account for.
arXiv Crypto & Security9/10Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents
Researchers show that AI coding agents blindly execute setup instructions from READMEs and Makefiles, enabling supply-chain compromise through poisoned project documentation — a practical threat to automated dev pipelines.
arXiv Crypto & Security9/10Stop Means Stop: Measuring and Repairing the Enforcement Gap in Agent-Framework Control Primitives
Researchers reveal that production LLM-agent frameworks' safety controls — approval gates, cancellation, timeouts — often fail to actually halt execution, creating a false sense of human oversight critical for EU AI Act compliance.
arXiv Crypto & Security9/10
DevSecOps
3 storiesSleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
Attackers hijacked two dormant RubyGems maintainer accounts to inject malware into trusted packages—a supply-chain risk pattern increasingly targeting ecosystem 'abandonware.'
Aikido9/10The Distributed Open-Source Vulnerability Ecosystem
Study quantifies how different open-source vulnerability databases diverge on the same software, meaning enterprises relying on a single scanner may harbour blind spots in their supply-chain risk posture.
arXiv Crypto & Security8/10Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis
Black Duck adds AI-driven false-positive triage and EU Cyber Resilience Act compliance checks to Coverity SAST — an early signal that CRA readiness is becoming a tooling differentiator.
IT Security Guru8/10
Regulatory
2 storiesEU sanctions Russian GRU military hackers over cyberattacks
The EU and UK issued their first joint cyber-sanctions package targeting Russian GRU operators, marking a new phase of coordinated Western cyber-deterrence that European critical-infrastructure operators must factor into risk models.
BleepingComputer9/10UK investigates TikTok for alleged age-verification lapses, exposing kids to online harms
Ofcom opens a formal investigation into TikTok's age-verification practices under the UK Online Safety Act — an early enforcement signal that may influence EU approaches to platform accountability for minors.
The Record6/10
Security
1 storyOT/IoT Security
1 storyCloud
1 storyCompliance
1 storyResearch
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- AgentWorm: Self-Propagating Attacks Across LLM Agent Ecosystems
Self-spreading attacks across interconnected AI agents represent an emerging systemic risk analogous to network worms — requiring governance and containment strategies.
- EU sanctions Russian GRU military hackers over cyberattacks
The EU and UK jointly sanctioned Russian military hackers for the first time — a signal that state-sponsored cyber risk is now a board-level regulatory concern.
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts
Attackers compromised inactive open-source maintainer accounts to poison trusted software packages—a supply-chain risk that demands governance attention.
- Setup Complete, Now You Are Compromised: Weaponizing Setup Instructions Against AI Coding Agents
AI coding assistants that automatically install dependencies from project files can be weaponised through poisoned documentation — requiring new supply-chain controls.
- UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign
A sophisticated Russian-speaking threat actor is actively targeting European organisations through trojanized business collaboration software, demanding urgent supply-chain verification.
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploit code for a critical WordPress flaw is circulating—confirmation of complete patch deployment across all web properties is needed now.
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical, publicly exploitable flaw in WordPress core threatens any organisation running the platform and requires immediate remediation.
- Inc Ransomware Exploits SonicWall SMA Zero-Days
Ransomware operators are actively exploiting unpatched SonicWall VPN appliances to gain root access—patch status must be confirmed today.
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
A state-linked group compromised a major certificate authority's code-signing keys, threatening software-supply-chain trust worldwide.
- Stop Means Stop: Measuring and Repairing the Enforcement Gap in Agent-Framework Control Primitives
Research shows that AI-agent safety controls may not actually work — a governance gap that could undermine both risk posture and EU AI Act compliance.
- Identity Attacks Overtake Exploits as Top Ransomware Cause
Ransomware attackers now favour stolen credentials over software exploits, and conventional MFA is failing—phishing-resistant authentication must become a board-level priority.
- [NEU] [kritisch] Microsoft Windows Produkte: Mehrere Schwachstellen
This month's critical Windows patches address flaws that could allow full system compromise across the entire Windows fleet.
- New Windows LegacyHive zero-day gives hackers admin privileges
A publicly available Windows zero-day gives attackers admin access on patched systems — heightened risk until Microsoft issues a fix.
- TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
AI tools are now accelerating commodity IoT malware development, expanding the attack surface for any organisation with connected devices.
- Sandworm hackers have a CAPTCHA trick for Ukrainians
Russian state hackers are using fake CAPTCHA pages to trick users into running malicious commands — a technique readily transferable to European corporate targets.
- [NEU] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
High-severity Splunk flaws could compromise the platform enterprises depend on for security monitoring and incident response.
- 1M+ Emails Use Hidden Text to Dupe AI Security Filters
AI email filters can be bypassed at scale using simple text manipulation, highlighting the need for layered defences beyond AI alone.
- There and Back Again: An Operators Guide on NTLM Relaying Egress
Legacy NTLM authentication continues to provide practical attack paths for privilege escalation, underscoring the need to accelerate protocol modernisation.
- The Distributed Open-Source Vulnerability Ecosystem
Vulnerability databases often disagree — enterprises using a single source may underestimate supply-chain exposure.
- The Risk of Exposed Cloud Functions and How to Harden
Mandiant data shows unauthenticated serverless functions are among the most common cloud misconfigurations, posing direct data-exposure risk.
- [NEU] [hoch] Microsoft DeveloperTools: Mehrere Schwachstellen
High-severity flaws in core Microsoft developer tools could enable supply-chain compromise if left unpatched.
- Black Duck Adds AI-Powered Triage and CRA-Ready Checks to Coverity Static Analysis
EU Cyber Resilience Act compliance is being embedded into developer tools — early adoption reduces future regulatory cost.
- Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
A dormant Chinese espionage implant has resurfaced in a Taiwan factory, highlighting supply-chain risk for companies with APAC manufacturing ties.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.