Tag: expectations

soc

CVE-2026-14266: 7-Zip Heap Overflow Flaw Can Lead to Remote Code Execution

A newly disclosed flaw in 7-Zip has raised fresh concerns about malicious archive handling and user-driven exploitation. CVE-2026-14266 is a heap-based buffer overflow tied to the way 7-Zip processes XZ chunked data, and successful exploitation may allow arbitrary code execution in the context of the current user. The issue is especially important because 7-Zip remains […]

Mehr lesen →
security

SANS Stormcast Tuesday, July 21st, 2026: More WordPress Details; HOLLOWGRAPH MSFT Calendar Abuse; Gitea Vulnerability

WordPress Exploitation Underway (CVE-2026-63030) https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168 HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels https://www.group-ib.com/blog/hollowgraph-microsoft-365/ Gitea Vulnerablity CVE-2026-58443 https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich

Mehr lesen →
security

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

Last week, Searchlight Cyber released details about a vulnerability they are calling „wp2shell“. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can […]

Mehr lesen →