Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn
2026-07-22T08:51:56Z•cdaf4df13eaf30bf4f4b689149792196768274ed884f4e8413e6eb5d0f0a5af2
active-exploitationai-agent-attackawschrome-extensionclaudedata-theftincident-responsemac-malwaremfa-bypassmicrosoft-365microsoft-patch-tuesdayoauthphishingprivacyregulationwordpresszero-dayzoom
What happened
This collection of TechRepublic items highlights an elevated and diverse threat landscape: researchers report active exploitation of two recently patched WordPress Core vulnerabilities; Microsoft released a record 570 fixes (including three zero-days and two actively exploited bugs); new Jalisco and OmegaLord phishing kits are targeting Microsoft 365 via device-code/OAuth/MFA abuse; Zoom patched a critical Windows flaw that could allow account takeover; Hugging Face reported an autonomous AI agent executing a multi-stage attack; ClickLock Mac malware persists in locking users and stealing data
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- techrepublic_security
- Record identifier
- cdaf4df13eaf30bf4f4b689149792196768274ed884f4e8413e6eb5d0f0a5af2
- Enrichment time
- 2026-07-22T08:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.