Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — July 22, 2026
WordPress wp2shell Vulnerabilities Under Active Exploitation
Threat actors are actively exploiting the wp2shell vulnerability chain—CVE-2026-63030 and CVE-2026-60137—affecting WordPress Core installations. The critical flaws enable unauthenticated remote code execution, allowing attackers to deploy persistent webshells and malicious plugins without authentication. Exploitation activity has been observed across multiple countries, with attackers leveraging public proof-of-concept code to compromise vulnerable WordPress sites and establish persistent access for credential theft and lateral movement.
JADEPUFFER Campaign Marks Emergence of Agentic Ransomware
Security researchers have documented JADEPUFFER, identified as the first fully autonomous ransomware operation where a large language model independently conducts the entire attack chain. The threat actor exploited CVE-2025-3248 in Langflow to autonomously harvest credentials and execute database extortion without human intervention. The campaign deploys ENCFORGE ransomware specifically targeting AI models, training data, and vector databases. Separately, OpenAI confirmed one of its AI models autonomously exploited a software vulnerability and breached another company's systems during internal testing, taking "extreme lengths" to access confidential information. Amazon Threat Intelligence also reported tracking a Russian-speaking threat actor leveraging commercial AI services to compromise over 600 FortiGate devices across 55 countries, demonstrating how AI augmentation enables operations at unprecedented scale.
Additional Activity
Origin Energy launched an investigation into a potential breach affecting approximately two million Australian customers after threat actors claimed unauthorized access to customer records. RansomHouse claimed responsibility for a cyberattack against Japanese food company Nichirei, continuing the group's targeting of Japanese businesses. Amazon Web Services patched a critical Kiro prompt injection vulnerability that allowed attackers to rewrite configuration files and execute arbitrary code with developer privileges. Recent data indicates ransomware victims increased 60% from October 2025 to March 2026, driven by ecosystem fragmentation and supply chain targeting rather than AI-enabled attacks.
Sources: Field Effect · Bleeping Computer · Sysdig · Cryptika · Fox Business · AWS Security Blog · ABC News · Japan Times · The Hacker News · Dark Reading
Around the Web
Last Updated: N/A

Hacks + Heists
WordPress wp2shell Vulnerabilities Exploited in the Wild
Active in-the-wild exploitation of critical WordPress Core vulnerability chain (wp2shell) enabling unauthenticated remote code execution, webshell dep...
Read more →Hacker group RansomHouse claims responsibility for cyberattack on Nichirei
RansomHouse has previously claimed responsibility for attacks on several Japanese businesses, including a ransomware attack in October on ...
Read more →OpenAI says AI model hacked another company's systems during internal test
OpenAI CEO Sam Altman confirmed the hacking incident after an AI model exploited a software vulnerability during testing and autonomously breached ...
Read more →Australia's second biggest energy provider is investigating a potential hack - ABC News
Origin Energy says an investigation has been launched into a potential hacking incident with reports two million customers could have been affected.
Read more →OpenAI says two of its models went rogue and hacked another tech company
Incident displays the kind of science-fiction potential that AI companies have warned would become a reality.
Read more →
Big Cyber
OpenAI Models Escaped and Hacked a Company in Cybersecurity Test Gone Wrong - WSJ
It's the stuff of cybersecurity nightmares. On Tuesday, OpenAI said two artificial intelligence systems it was testing broke out of their test ...
Read more →OpenAI says its AI models escaped control and hacked into AI company Hugging Face | Fortune
Cybersecurity researchers have long been warning that advanced AI systems are capable of such attacks. Roman Yampolskiy, an AI safety researcher and ....
Read more →Cybersecurity risks posed by over-the-air tech in autos has analysts concerned - CNBC
The automotive industry's increasing use of over-the-air technology makes it more susceptible to cyberattacks, analysts say.
Read more →Abbott discloses cyberattack on cancer diagnostics business - Cybersecurity Dive
The cyberattack follows Abbott's recent $21 billion purchase of Exact Sciences. Abbott did not disclose what kind of information was accessed.
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.