Hackers abuse ViPNet software to target Russian govt agencies
2026-07-20T01:23:32Z•eef04b046e01019a76fccd1fd7dd8600df05674f0bc71c70ea4d8415877a1af4
7-zipacr-stealercisadata-breachdenial-of-serviceexploitsfortinetmacos-malwareopensslpatchingprivilege-escalationransomwarercesoftware-update-abusesupply-chainthreat-actorvipnetwordpresszero-day
What happened
Multiple high-impact threats and active exploitation trends were reported: a threat actor is abusing the ViPNet update mechanism to target Russian government organizations; public exploits were released for the critical WordPress “wp2shell” RCE making immediate patching essential; 7-Zip 26.02 fixes an RCE in malicious archives and should be updated; CISA ordered urgent patching for two actively exploited Fortinet FortiSandbox flaws; a Windows zero-day (“LegacyHive”) enabling local privilege escalation was disclosed; OpenSSL suffers a small-payload DoS (HollowByte); Microsoft observed a surge в
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- eef04b046e01019a76fccd1fd7dd8600df05674f0bc71c70ea4d8415877a1af4
- Enrichment time
- 2026-07-20T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.