Adobe Chrome extension flaw let sites access private WhatsApp chats

2026-07-22T13:23:28Zbf883e7849e52cf6d78fe886956ef267f92cdc14ce2f83d978aa5e1a7b88bb07
AI-securityCISAGitHub malwarePaloAlto GlobalProtectRCESharePointWordPressbrowser-extensioncredential-stuffingexploited-in-the-wildincident-responsephishing-as-a-serviceransomwaresupply-chainwebshells

What happened

Multiple actively exploited and high-impact vulnerabilities and incidents were reported: a critical Microsoft SharePoint RCE (CVE-2026-50522) is being exploited to steal machine keys and persist after patching; WordPress 'wp2shell' critical flaws (CVE-2026-63030, CVE-2026-60137) are being used to deploy webshells and malicious plugins; a critical PAN‑OS GlobalProtect authentication bypass is being exploited by the Qilin ransomware group. Other notable incidents include CISA ordering urgent remediation for an actively exploited Langflow RCE, an Adobe Acrobat Chrome extension flaw exposing Whats

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
bf883e7849e52cf6d78fe886956ef267f92cdc14ce2f83d978aa5e1a7b88bb07
Enrichment time
2026-07-22T13:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.