0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Hard-coded credential in Cisco Secure FMC enables unauthenticated login
Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.
Microsoft MSHTML security feature bypass
Protection mechanism failure in Microsoft MSHTML lets unauthenticated attackers bypass a security feature over the network. CVSS 8.8, patched in Microsoft's February 2026 Patch Tuesday.
Arista VeloCloud Orchestrator OS Command Injection
CVSS 10.0 critical. Remote attackers can inject OS commands into Arista VeloCloud Orchestrator On-Prem, compromising the SD-WAN management plane.
Check Point SmartConsole improper authentication
CVE-2026-16232 lets unauthenticated attackers grab an admin token from SmartConsole. CISA KEV addition July 22; Check Point confirms active exploitation.
WordPress WP_Query author__not_in SQL injection (wp2shell companion)
A medium-severity SQL injection in WordPress WP_Query's author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.
WordPress Core unauthenticated RCE (wp2shell)
A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.
From the desk

Midnight Blizzard Uses Hotel Wi-Fi to Deploy CornFlake RAT
Microsoft attributes CaptiveCrunch to Storm-2945, a Midnight Blizzard sub-cluster delivering CornFlake RAT via fake browser updates on hijacked hotel Wi-Fi.

HollowFrame and Matryoshka: Backdoor Chain Targets Law Firm
Blackpoint Cyber documents HollowFrame, a Go-based loader, and Matryoshka, a Rust backdoor, deployed against a law firm via spear-phishing and an encrypted LNK archive.

Chinese APT Deploys OctLurk and SilkLurk in Central Asia
Kaspersky details OctLurk and SilkLurk, new backdoors in a suspected Chinese espionage campaign targeting Central Asian governments since January 2025.

Amgen Says Breach Exposed Patient Health Data
Amgen confirmed threat actors stole patient health information and proprietary corporate data from third-party cloud systems operated by outside service providers.

Arch Linux Locks Down AUR After Malware Takeover Surge
Arch Linux disabled AUR package adoption after a surge of malicious takeovers by threat actors who exploited the mechanism to push backdoored updates to users.

Adform Ad Script Hijacked in Supply-Chain Crypto Attack
Adform's ad script was backdoored to swap crypto wallet addresses in visitor clipboards, silently stealing funds on sites running the compromised tag.




