Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn

2026-07-22T08:51:56Zcdaf4df13eaf30bf4f4b689149792196768274ed884f4e8413e6eb5d0f0a5af2
active-exploitationai-agent-attackawschrome-extensionclaudedata-theftincident-responsemac-malwaremfa-bypassmicrosoft-365microsoft-patch-tuesdayoauthphishingprivacyregulationwordpresszero-dayzoom

What happened

This collection of TechRepublic items highlights an elevated and diverse threat landscape: researchers report active exploitation of two recently patched WordPress Core vulnerabilities; Microsoft released a record 570 fixes (including three zero-days and two actively exploited bugs); new Jalisco and OmegaLord phishing kits are targeting Microsoft 365 via device-code/OAuth/MFA abuse; Zoom patched a critical Windows flaw that could allow account takeover; Hugging Face reported an autonomous AI agent executing a multi-stage attack; ClickLock Mac malware persists in locking users and stealing data

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
techrepublic_security
Record identifier
cdaf4df13eaf30bf4f4b689149792196768274ed884f4e8413e6eb5d0f0a5af2
Enrichment time
2026-07-22T08:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn · Baitaphish