Hackers abuse ViPNet software to target Russian govt agencies
2026-07-19T19:23:24Z•f37eea47f9d7f4441b69f61d7f1ace7c167e92002544a401642460910eb5cd65
7-ZipACR StealerCISAClickLockFortinet FortiSandboxLegacyHiveOpenSSLViPNetWordPresscredential theftdata breachdenial-of-serviceexploitationincident responsemalwarepatchingransomwareremote code executionsupply-chain attackzero-day
What happened
A Bleeping Computer roundup reports multiple high-impact security events and active exploitations: attackers are abusing the ViPNet update mechanism to target Russian government organizations; 7‑Zip and WordPress Core ("wp2shell") RCE vulnerabilities have fixes or public exploits and require immediate patching; Microsoft warns of a surge in ACR Stealer credential‑theft attacks; a new OpenSSL DoS (HollowByte) and an actively exploited Fortinet FortiSandbox pair are being urged for emergency patching by CISA; a Windows zero‑day (LegacyHive) for privilege escalation and macOS ClickLock credential
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f37eea47f9d7f4441b69f61d7f1ace7c167e92002544a401642460910eb5cd65
- Enrichment time
- 2026-07-19T19:23:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.