Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
North Korean Hackers Embed OTTERCOOKIE Malware in SVG Images to Backdoor Developers
July 20, 2026
US Charges Russian Trio for $62M Cybercrime Spree
July 20, 2026
Critical NGINX Vulnerability CVE-2024-35200 Allows Remote Code Execution
July 20, 2026
Home/CyberSecurity News/Notepad++ Vulnerabilities Expose Users, Wpzshell Exploited, EY Breached
CyberSecurity News

Notepad++ Vulnerabilities Expose Users, Wpzshell Exploited, EY Breached

Key Takeaways Notepad++ users should update to v8.9.7 immediately to patch a critical installer-time command injection vulnerability and four other security flaws. The “wp2shell” RCE...

Emy Elsamnoudy
Emy Elsamnoudy
July 19, 2026 5 Min Read
6 0

Key Takeaways

  • Notepad++ users should update to v8.9.7 immediately to patch a critical installer-time command injection vulnerability and four other security flaws.
  • The “wp2shell” RCE vulnerability (CVE-2026-60137, CVE-2026-63030) threatens over 500 million WordPress sites with unauthenticated takeover via SQL injection.
  • Ernst & Young (EY) confirmed a data breach affecting client tax and investment data, highlighting the persistent risk to professional services firms.
  • Microsoft’s July 2026 Patch Tuesday addressed 570 vulnerabilities, including two zero-days actively exploited in SharePoint Server and Active Directory Federation Services.
  • A malicious ModHeader Chrome extension with 1.6 million users was removed for containing dormant code capable of exfiltrating browsing history.

Widespread Cyber Threats Target Productivity Tools, Cloud, and AI Systems

The latest cybersecurity landscape reveals a broad spectrum of vulnerabilities impacting everything from widely used productivity applications and enterprise identity systems to emerging AI platforms. Attackers are demonstrating increasing speed in weaponizing disclosed flaws, while novel techniques are emerging to exploit artificial intelligence integrations.

Table Of Content

  • Key Takeaways
  • Widespread Cyber Threats Target Productivity Tools, Cloud, and AI Systems
  • Notepad++ Patches Critical Flaws, Including Command Injection
  • “Wp2shell” RCE Puts 500 Million WordPress Sites at Risk
  • EY Confirms Data Breach Exposing Client Tax and Investment Data
  • Microsoft’s Extensive July Patch Tuesday Addresses 570 Vulnerabilities
  • Malicious ModHeader Chrome Extension Removed After Data Exfiltration Discovery
  • Emerging Threats to AI Systems and Workflows
  • Additional Critical Patches and Vulnerabilities
  • What You Should Do

Notepad++ Patches Critical Flaws, Including Command Injection

Users of the popular Notepad++ text editor are urged to update to version 8.9.7 without delay. This critical update addresses a high-severity installer-time PowerShell command injection vulnerability. In addition to this significant flaw, the patch resolves four other security issues: a stack buffer overflow, a Zip Slip path traversal bug, a session-validation bypass, and a macro integrity bypass. These vulnerabilities could expose users to various risks, including arbitrary code execution and unauthorized access.

“Wp2shell” RCE Puts 500 Million WordPress Sites at Risk

A severe pre-authentication remote code execution (RCE) vulnerability, dubbed “wp2shell,” has been disclosed, threatening over half a billion WordPress websites. Tracked as CVE-2026-60137 and CVE-2026-63030, this flaw enables unauthenticated attackers to take over affected sites through a REST API batch-route SQL injection chain. The widespread adoption of WordPress makes this a particularly concerning vulnerability for a vast segment of the internet.

EY Confirms Data Breach Exposing Client Tax and Investment Data

Global professional services firm Ernst & Young (EY) has acknowledged a data breach impacting client information. The company confirmed that an unauthorized third party gained access to its IT support ticket platform between March 28 and April 12, 2026. During this period, client tax and investment-holding documents were downloaded. The breach was detected nearly three weeks after the initial compromise, underscoring the challenges even large organizations face in timely detection.

Microsoft’s Extensive July Patch Tuesday Addresses 570 Vulnerabilities

Microsoft’s July 2026 Patch Tuesday was notably extensive, addressing approximately 570 vulnerabilities across its product portfolio. Among these were two zero-day vulnerabilities (CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services) that were already being actively exploited in the wild. The update also included a fix for a publicly disclosed BitLocker bypass bug, emphasizing the ongoing efforts required to secure Microsoft’s vast ecosystem.

Malicious ModHeader Chrome Extension Removed After Data Exfiltration Discovery

The widely used ModHeader extension, boasting 1.6 million installs across Chrome and Edge browsers, has been removed from their respective stores. This action followed the discovery by researchers of dormant code within the extension capable of encrypting and uploading users’ browsing history to an external server. This incident highlights the persistent threat posed by malicious browser extensions.

Emerging Threats to AI Systems and Workflows

The cybersecurity landscape is increasingly recognizing AI systems as new attack surfaces. A vulnerability was identified in the Claude for Chrome browser integration, raising concerns about the security of AI-assistant browser extensions. Furthermore, the “GhostCommit” technique has emerged, which involves concealing malicious AI prompts within code commits to potentially manipulate AI coding assistants without the developer’s knowledge. Researchers have also detailed an exploit chain, dubbed “Sol,” that combines GPT-5/6-era AI models with Chrome browser vulnerabilities, illustrating the sophisticated AI-assisted attack techniques now being developed.

Additional Critical Patches and Vulnerabilities

  • Windows Zero-Day PoC: Researcher Nightmare-Eclipse released “LegacyHive,” a proof-of-concept exploiting the Windows User Profile Service. This allows a standard user to load another account’s registry hive, reportedly even on systems with July 2026 patches.
  • macOS Stealer: A new macOS information-stealing malware campaign is mimicking legitimate Apple crash-report dialogs to trick users into divulging credentials or granting access.
  • Active Directory Zero-Day: Active exploitation of a zero-day flaw in Active Directory-related services has been reported, posing significant risks to enterprise identity infrastructure.
  • Dell BIOS Flaw: A vulnerability in Dell BIOS firmware has been found to allow the exposure or extraction of administrator passwords, impacting enterprise device fleets.
  • 7-Zip Vulnerability: A flaw in the popular 7-Zip archiving tool could enable attackers to achieve code execution, likely through specially crafted archive files.
  • F5 Nginx Patches: F5 has released patches for multiple vulnerabilities affecting Nginx components within its product line.
  • Splunk Enterprise Fixes: Splunk has addressed several vulnerabilities in its Enterprise product, enhancing data integrity and platform security.
  • Fortinet Patches: Fortinet issued patches for seven vulnerabilities across its security product portfolio.
  • Dell Laptop Shutdowns: Separate from the BIOS flaw, some Dell laptops are experiencing unexpected shutdowns after the July 2026 update.
  • AWS Cost Explorer Bug: A bug in AWS Cost Explorer reportedly creates unintended security or data-exposure risks for cloud customers.
  • TP-Link Camera Vulnerability: A security flaw affecting TP-Link camera devices could allow attackers to compromise functionality or access video feeds.

What You Should Do

  • Update Notepad++ Immediately: All users should upgrade to Notepad++ v8.9.7 to patch critical vulnerabilities.
  • Patch WordPress: WordPress site administrators must apply available patches for the wp2shell vulnerability (CVE-2026-60137, CVE-2026-63030) as soon as possible.
  • Apply Microsoft Updates: Ensure all Microsoft systems are updated with the July 2026 Patch Tuesday releases, prioritizing patches for SharePoint Server and Active Directory Federation Services.
  • Review Browser Extensions: Regularly audit and remove unnecessary or suspicious browser extensions. Be cautious about granting extensive permissions to extensions.
  • Monitor for AI-Related Threats: Organizations using AI tools should stay informed about new attack vectors like “GhostCommit” and vulnerabilities in AI integrations.
  • General Patching: Apply all available security updates from vendors including Fortinet, F5, Splunk, Dell, and for 7-Zip.
  • Endpoint Security: Ensure robust endpoint detection and response (EDR) solutions are in place to detect and prevent malware, including information stealers.
  • Incident Response Planning: Review and update incident response plans, especially for data breaches involving client information.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVECybersecurityExploitMalwarePatchSecurityThreatVulnerabilityzero-day

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical NadMesh Vulnerability Exposes AI and MCP Infrastructure

Next Post

Critical NGINX Vulnerability CVE-2024-35200 Allows Remote Code Execution

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hugging Face Confirms AI-Driven Breach, Attackers Used Autonomous Agents
July 19, 2026
Critical Citrix Vulnerability (CVE-2023-49605) Lets Attackers Escalate Privileges
July 18, 2026
Spirals Ransomware Uses IIS Web Shell and PsExec for Rapid Encryption
July 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us