entdigest

6 articles from 33 sources · Updated 2026-07-21 11:00 UTC

Top Stories

  1. Critical Palo Alto VPN bug now exploited by Qilin ransomware gangBleepingComputer
  2. Microsoft shares manual fix for WSUS sync delays and timeoutsBleepingComputer
  3. WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningThe Hacker News
  4. Windows LegacyHive zero-day flaw gets free, unofficial patchesBleepingComputer
  5. New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackThe Hacker News
  6. Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionThe Hacker News

Latest

C

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]

The big picture: Critical Palo Alto VPN bug now exploited by... — should prompt a review of your own security.

BleepingComputer Security 1 min read Read →
M

Microsoft shares manual fix for WSUS sync delays and timeouts

Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]

The big picture: Microsoft shares manual fix for WSUS sync delays... — highlights growing cyber threats.

BleepingComputer Security 1 min read Read →
W

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, hav...

Bottom line from The Hacker News: this exposes vulnerabilities that affect millions.

The Hacker News Security 1 min read Read →
W

Windows LegacyHive zero-day flaw gets free, unofficial patches

Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. [...]

BleepingComputer reports: Windows LegacyHive zero-day flaw gets free, unofficial patches — this exposes vulnerabilities that affect millions.

BleepingComputer Security 1 min read Read →
N

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model ...

Why it matters: New ENCFORGE Ransomware Targets AI Model Files in... underscores the cost of weak defenses.

The Hacker News Security 1 min read Read →
C

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sa...

Bottom line from The Hacker News: this should prompt a review of your own security.

The Hacker News Security 1 min read Read →