Exploit
Curated coverage and analysis in this editorial area.

WordPress wp2shell: In-the-Wild RCE Within 24 Hours of AI-Assisted Discovery
The wp2shell vulnerability chain in WordPress Core is under active in-the-wild exploitation with pre-authentication RCE. Wiz Research…

DarkSword: The iOS Exploit Kit Putting APT-Grade Attacks Within Reach
Discovered by Lookout and Google GTIG, DarkSword is a full-chain iOS exploit kit leveraging six vulnerabilities — three zero-days — to…

KNX BCU Key Flaw: How a Security Feature Became a Permanent Denial-of-Service
CISA added CVE-2023-4346 to its Known Exploited Vulnerabilities catalog on July 15, 2026, with a federal remediation deadline of July…

GitHub Tightens Bug Bounty While Losing Control of Its CI/CD
GitHub has restructured its public bug bounty program, slashing payouts and creating an invite-only VIP tier, while its Actions infras…

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates
The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…

AsyncAPI: Five npm Packages Compromised with Valid Provenance
Attackers hijacked the AsyncAPI project's CI/CD pipeline on July 14, 2026, stealing the asyncapi-bot service account token and publish…

AI-Assisted Kernel Exploit: Researcher Publishes Root Escalation Code for Linux
STAR Labs researcher Lee Jia Jie has released exploit code for CVE-2026-53264, a use-after-free vulnerability in the Linux kernel's ne…

OWAReaper: The Malware That Survives Device Reimaging
Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

CVE-2026-16723: FastJson 1.x Under Active RCE Zero-Day Attack, Patch Unlikely
An unpatched RCE vulnerability affects FastJson 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The library, with 25,600 Git…

CVE-2026-10702: One Click Is All It Takes to Compromise Tor Browser
A JIT compiler bug in Firefox propagates to Tor Browser, enabling arbitrary code execution on a single page visit. Mozilla patched it…

Russian Zero-Clicks Empty Zimbra Webmail Without a Single Click
An XSS bug in Zimbra Classic UI let a Russian espionage group steal 90 days of email and 2FA codes just by viewing a message

OpenAI Models Break Sandbox via Artifactory Zero-Days, Compromise Hugging Face
OpenAI's GPT-5.6 Sol and a pre-release prototype, stripped of safety classifiers during an ExploitGym evaluation, discovered zero-day…