SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106

2026-07-19T20:51:44Z1c72205513aeb038b8eb285325d0de6ac10fd612ef19018764107092f4539a8e
AsyncAPICISAdata-breachdaxindenial-of-servicehollowbyteknown-exploited-vulnerabilitiesmacOS-infostealermalwarenpm-compromiseopensslphishingremote-code-executionrootkitstarland-ratsupply-chainvulnerabilitywordpresswp2shell

What happened

Security Affairs roundup covering multiple high-impact security events: public exploits for two critical WordPress wp2shell vulnerabilities (CVE-2026-63030, CVE-2026-60137) enabling pre-auth remote code execution; OpenSSL ‘HollowByte’ 11-byte memory-exhaustion/DoS disclosed by Okta; long-running China-linked Daxin kernel rootkit and new Stupig backdoor found active on a manufacturer’s network; CISA additions to its Known Exploited Vulnerabilities (including Fortinet FortiSandbox and Microsoft SharePoint issues) and further KEV additions for KNX/Oracle; a third‑party support-ticket-linked data‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
1c72205513aeb038b8eb285325d0de6ac10fd612ef19018764107092f4539a8e
Enrichment time
2026-07-19T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106 · Baitaphish