SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106
2026-07-19T20:51:44Z•1c72205513aeb038b8eb285325d0de6ac10fd612ef19018764107092f4539a8e
AsyncAPICISAdata-breachdaxindenial-of-servicehollowbyteknown-exploited-vulnerabilitiesmacOS-infostealermalwarenpm-compromiseopensslphishingremote-code-executionrootkitstarland-ratsupply-chainvulnerabilitywordpresswp2shell
What happened
Security Affairs roundup covering multiple high-impact security events: public exploits for two critical WordPress wp2shell vulnerabilities (CVE-2026-63030, CVE-2026-60137) enabling pre-auth remote code execution; OpenSSL ‘HollowByte’ 11-byte memory-exhaustion/DoS disclosed by Okta; long-running China-linked Daxin kernel rootkit and new Stupig backdoor found active on a manufacturer’s network; CISA additions to its Known Exploited Vulnerabilities (including Fortinet FortiSandbox and Microsoft SharePoint issues) and further KEV additions for KNX/Oracle; a third‑party support-ticket-linked data‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 1c72205513aeb038b8eb285325d0de6ac10fd612ef19018764107092f4539a8e
- Enrichment time
- 2026-07-19T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.