Notepad++ Vulnerabilities Expose Users, Wpzshell Exploited, EY Breached
Key Takeaways Notepad++ users should update to v8.9.7 immediately to patch a critical installer-time command injection vulnerability and four other security flaws. The “wp2shell” RCE...
Key Takeaways
- Notepad++ users should update to v8.9.7 immediately to patch a critical installer-time command injection vulnerability and four other security flaws.
- The “wp2shell” RCE vulnerability (CVE-2026-60137, CVE-2026-63030) threatens over 500 million WordPress sites with unauthenticated takeover via SQL injection.
- Ernst & Young (EY) confirmed a data breach affecting client tax and investment data, highlighting the persistent risk to professional services firms.
- Microsoft’s July 2026 Patch Tuesday addressed 570 vulnerabilities, including two zero-days actively exploited in SharePoint Server and Active Directory Federation Services.
- A malicious ModHeader Chrome extension with 1.6 million users was removed for containing dormant code capable of exfiltrating browsing history.
Widespread Cyber Threats Target Productivity Tools, Cloud, and AI Systems
The latest cybersecurity landscape reveals a broad spectrum of vulnerabilities impacting everything from widely used productivity applications and enterprise identity systems to emerging AI platforms. Attackers are demonstrating increasing speed in weaponizing disclosed flaws, while novel techniques are emerging to exploit artificial intelligence integrations.
Table Of Content
- Key Takeaways
- Widespread Cyber Threats Target Productivity Tools, Cloud, and AI Systems
- Notepad++ Patches Critical Flaws, Including Command Injection
- “Wp2shell” RCE Puts 500 Million WordPress Sites at Risk
- EY Confirms Data Breach Exposing Client Tax and Investment Data
- Microsoft’s Extensive July Patch Tuesday Addresses 570 Vulnerabilities
- Malicious ModHeader Chrome Extension Removed After Data Exfiltration Discovery
- Emerging Threats to AI Systems and Workflows
- Additional Critical Patches and Vulnerabilities
- What You Should Do
Notepad++ Patches Critical Flaws, Including Command Injection
Users of the popular Notepad++ text editor are urged to update to version 8.9.7 without delay. This critical update addresses a high-severity installer-time PowerShell command injection vulnerability. In addition to this significant flaw, the patch resolves four other security issues: a stack buffer overflow, a Zip Slip path traversal bug, a session-validation bypass, and a macro integrity bypass. These vulnerabilities could expose users to various risks, including arbitrary code execution and unauthorized access.
“Wp2shell” RCE Puts 500 Million WordPress Sites at Risk
A severe pre-authentication remote code execution (RCE) vulnerability, dubbed “wp2shell,” has been disclosed, threatening over half a billion WordPress websites. Tracked as CVE-2026-60137 and CVE-2026-63030, this flaw enables unauthenticated attackers to take over affected sites through a REST API batch-route SQL injection chain. The widespread adoption of WordPress makes this a particularly concerning vulnerability for a vast segment of the internet.
EY Confirms Data Breach Exposing Client Tax and Investment Data
Global professional services firm Ernst & Young (EY) has acknowledged a data breach impacting client information. The company confirmed that an unauthorized third party gained access to its IT support ticket platform between March 28 and April 12, 2026. During this period, client tax and investment-holding documents were downloaded. The breach was detected nearly three weeks after the initial compromise, underscoring the challenges even large organizations face in timely detection.
Microsoft’s Extensive July Patch Tuesday Addresses 570 Vulnerabilities
Microsoft’s July 2026 Patch Tuesday was notably extensive, addressing approximately 570 vulnerabilities across its product portfolio. Among these were two zero-day vulnerabilities (CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services) that were already being actively exploited in the wild. The update also included a fix for a publicly disclosed BitLocker bypass bug, emphasizing the ongoing efforts required to secure Microsoft’s vast ecosystem.
Malicious ModHeader Chrome Extension Removed After Data Exfiltration Discovery
The widely used ModHeader extension, boasting 1.6 million installs across Chrome and Edge browsers, has been removed from their respective stores. This action followed the discovery by researchers of dormant code within the extension capable of encrypting and uploading users’ browsing history to an external server. This incident highlights the persistent threat posed by malicious browser extensions.
Emerging Threats to AI Systems and Workflows
The cybersecurity landscape is increasingly recognizing AI systems as new attack surfaces. A vulnerability was identified in the Claude for Chrome browser integration, raising concerns about the security of AI-assistant browser extensions. Furthermore, the “GhostCommit” technique has emerged, which involves concealing malicious AI prompts within code commits to potentially manipulate AI coding assistants without the developer’s knowledge. Researchers have also detailed an exploit chain, dubbed “Sol,” that combines GPT-5/6-era AI models with Chrome browser vulnerabilities, illustrating the sophisticated AI-assisted attack techniques now being developed.
Additional Critical Patches and Vulnerabilities
- Windows Zero-Day PoC: Researcher Nightmare-Eclipse released “LegacyHive,” a proof-of-concept exploiting the Windows User Profile Service. This allows a standard user to load another account’s registry hive, reportedly even on systems with July 2026 patches.
- macOS Stealer: A new macOS information-stealing malware campaign is mimicking legitimate Apple crash-report dialogs to trick users into divulging credentials or granting access.
- Active Directory Zero-Day: Active exploitation of a zero-day flaw in Active Directory-related services has been reported, posing significant risks to enterprise identity infrastructure.
- Dell BIOS Flaw: A vulnerability in Dell BIOS firmware has been found to allow the exposure or extraction of administrator passwords, impacting enterprise device fleets.
- 7-Zip Vulnerability: A flaw in the popular 7-Zip archiving tool could enable attackers to achieve code execution, likely through specially crafted archive files.
- F5 Nginx Patches: F5 has released patches for multiple vulnerabilities affecting Nginx components within its product line.
- Splunk Enterprise Fixes: Splunk has addressed several vulnerabilities in its Enterprise product, enhancing data integrity and platform security.
- Fortinet Patches: Fortinet issued patches for seven vulnerabilities across its security product portfolio.
- Dell Laptop Shutdowns: Separate from the BIOS flaw, some Dell laptops are experiencing unexpected shutdowns after the July 2026 update.
- AWS Cost Explorer Bug: A bug in AWS Cost Explorer reportedly creates unintended security or data-exposure risks for cloud customers.
- TP-Link Camera Vulnerability: A security flaw affecting TP-Link camera devices could allow attackers to compromise functionality or access video feeds.
What You Should Do
- Update Notepad++ Immediately: All users should upgrade to Notepad++ v8.9.7 to patch critical vulnerabilities.
- Patch WordPress: WordPress site administrators must apply available patches for the wp2shell vulnerability (CVE-2026-60137, CVE-2026-63030) as soon as possible.
- Apply Microsoft Updates: Ensure all Microsoft systems are updated with the July 2026 Patch Tuesday releases, prioritizing patches for SharePoint Server and Active Directory Federation Services.
- Review Browser Extensions: Regularly audit and remove unnecessary or suspicious browser extensions. Be cautious about granting extensive permissions to extensions.
- Monitor for AI-Related Threats: Organizations using AI tools should stay informed about new attack vectors like “GhostCommit” and vulnerabilities in AI integrations.
- General Patching: Apply all available security updates from vendors including Fortinet, F5, Splunk, Dell, and for 7-Zip.
- Endpoint Security: Ensure robust endpoint detection and response (EDR) solutions are in place to detect and prevent malware, including information stealers.
- Incident Response Planning: Review and update incident response plans, especially for data breaches involving client information.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.