Hackers abuse ViPNet software to target Russian govt agencies

2026-07-20T07:23:29Zafe12e9b2f9dce3985f4442ea0a609b7aee9dfcb58132fd5c759e2b383285cae
7-ZipACR-StealerClickLockFortinetHollowByteLegacyHiveViPNetWordPressdata-breachdenial-of-serviceincident-responsemalwarepatchingprivilege-escalationransomwarerceremote-code-executionstealersupply-chainzero-day

What happened

Multiple high-impact threats and active incidents reported: an advanced actor is abusing the ViPNet product update mechanism to target Russian government organizations (supply‑chain compromise); public exploits were released for critical WordPress "wp2shell" RCEs; 7‑Zip released 26.02 to fix a remotely exploitable RCE in malicious archives; Microsoft customers are facing a surge in ACR Stealer data‑theft attacks; a Windows zero‑day named LegacyHive enables local privilege escalation to admin; CISA ordered urgent patching of actively exploited Fortinet FortiSandbox flaws; OpenSSL is vulnerable‌

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
afe12e9b2f9dce3985f4442ea0a609b7aee9dfcb58132fd5c759e2b383285cae
Enrichment time
2026-07-20T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers abuse ViPNet software to target Russian govt agencies · Baitaphish