Hackers abuse ViPNet software to target Russian govt agencies

2026-07-19T19:23:24Zf37eea47f9d7f4441b69f61d7f1ace7c167e92002544a401642460910eb5cd65
7-ZipACR StealerCISAClickLockFortinet FortiSandboxLegacyHiveOpenSSLViPNetWordPresscredential theftdata breachdenial-of-serviceexploitationincident responsemalwarepatchingransomwareremote code executionsupply-chain attackzero-day

What happened

A Bleeping Computer roundup reports multiple high-impact security events and active exploitations: attackers are abusing the ViPNet update mechanism to target Russian government organizations; 7‑Zip and WordPress Core ("wp2shell") RCE vulnerabilities have fixes or public exploits and require immediate patching; Microsoft warns of a surge in ACR Stealer credential‑theft attacks; a new OpenSSL DoS (HollowByte) and an actively exploited Fortinet FortiSandbox pair are being urged for emergency patching by CISA; a Windows zero‑day (LegacyHive) for privilege escalation and macOS ClickLock credential

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f37eea47f9d7f4441b69f61d7f1ace7c167e92002544a401642460910eb5cd65
Enrichment time
2026-07-19T19:23:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.