Artificial IntelligenceCybersecurityNewswireTechnologyWhat's Buzzing

Week in review: WordPress flaws, fake OAuth IDs bypass sign-in logs

Originally published on: July 20, 2026
▼ Summary

– Two high severity WordPress vulnerabilities were patched in version 7.0.2, requiring immediate action.
– Cynative is an open-source security research agent that prevents accidental damage by refusing to write changes by default.
– Attackers are spoofing OAuth client IDs to evade detection in Microsoft Entra ID sign-in logs during account enumeration.
– The 2026 SANS AI Survey found that 78% of cybersecurity practitioners actively use generative AI, up from 50% the previous year.
– ESET discovered 11 outdated Shim versions with vulnerabilities that could bypass UEFI Secure Boot, leading Microsoft to revoke trust in them on June 9, 2026.

Two critical WordPress security flaws have been disclosed, demanding immediate patching. The 7.0.2 security release addresses one critical and one high severity vulnerability, making it essential for site administrators to update without delay.

Cynative, a new open-source security research agent, tackles the inherent risks of running LLMs against live cloud accounts. Its key safeguard: the agent refuses to write any data by default and verifies this refusal on every call, preventing accidental deletions or permission changes.

Attackers are bypassing Microsoft sign-in logs by spoofing OAuth client IDs. During account enumeration, they fake the globally unique identifier passed as `client_id` in authentication requests. Microsoft Entra ID records this value as the application ID, and its handling of unfamiliar identifiers creates a blind spot that operators now exploit.

The 2026 SANS AI Survey reveals that 78% of security practitioners actively use generative AI, up from 50% last year. Yet the best defense against AI-driven attacks remains a skeptical human, underscoring that AI tools require careful oversight.

UEFI Secure Boot faces a lingering threat from outdated Shim bootloaders. ESET found that 11 old versions (0.9 and earlier) contain vulnerabilities that could bypass Secure Boot. Microsoft revoked trust in these versions during its June 2026 Patch Tuesday update.

Tracebit researchers have developed a defense against AI agents called “context bombs.” This prompt injection technique is aimed not at hijacking AI but at protecting environments from autonomous attacks, proving highly effective at stopping full compromise.

GPT-Red, OpenAI’s automated red-teaming model, outperformed human testers in finding prompt injection weaknesses. It operates like a human attacker, iterating prompts and responses to achieve goals like data exfiltration.

A Vicarius survey highlights a persistent gap: organizations discover more vulnerabilities than ever, but many are breached by flaws they already knew about. The bottleneck lies in assigning, approving, deploying, and confirming fixes.

Email remains the top attack vector, accounting for half of all ransomware incidents. A stolen password from a phishing email gives attackers network access, leading to file encryption and ransom demands that are now trending downward.

Open-source software underpins 96% of codebases, yet most is written by unpaid volunteers. The question of how public money impacts these projects grows more urgent as reliance on volunteer-built code expands.

Cyber insurance premiums reached $16 billion globally in 2024, but payouts have become less predictable. Enterprises in regulated industries often carry policies for compliance, yet coverage terms require careful reading.

In a Help Net Security video, Penetrify’s CTO Viktor Bulanek outlines a five-step plan to cut security budget waste. He identifies two major leaks: overlapping tools that flag the same issues and shelfware covering only a third of the estate at full cost.

Coca-Cola’s Fairlife milk production was halted by a ransomware attack, disclosed in an SEC filing on July 16, 2026. The dairy brand’s high-protein milk and protein shakes are affected.

1Password launched a beta integration for Claude, allowing Anthropic’s AI assistant to log into websites without exposing user credentials. The feature keeps passwords and other secrets secure.

Apple warns iPhone and iPad users about FaceTime scams designed to drain bank accounts. Scammers trick victims into handing over money and account details during calls.

Symantec’s Threat Hunter Team uncovered Spirals ransomware, a new strain that locked down an IT services company in South Asia within 24 hours of initial access, achieving data theft and encryption rapidly.

Progress Software disabled ShareFile accounts using on-premises Storage Zone Controllers due to a “credible external security threat.” Customers were urged to shut down servers hosting these components.

SonicWall fixed two zero-day vulnerabilities (CVE-2026-15409, CVE-2026-15410) in its SMA 1000 Series appliances, urging upgrades and compromise checks.

Microsoft’s July 2026 Patch Tuesday addressed over 570 vulnerabilities, including two actively exploited (CVE-2026-56155, CVE-2026-56164) and one previously disclosed (CVE-2026-50661). A proof-of-concept exploit for an unpatched Windows privilege escalation flaw, dubbed LegacyHive, followed.

Arctic Wolf researchers warn of a threat actor impersonating hundreds of brands on GitHub to distribute infostealer malware disguised as legitimate software downloads.

Software supply chain security has improved with SBOMs, signing, and provenance, but a critical gap remains: these measures do not reveal what software does once it runs, leaving organizations blind to runtime behavior.

MDR decisions are evolving as AI handles more alerts. The old choice between staffing a 24/7 SOC or outsourcing is being replaced by questions about how AI changes detection and response workflows.

Trust Chain by Strike Graph replaces vendor security questionnaires with validated evidence. Vendors submit proof of compliance, which is evaluated by AI, eliminating self-reported assessments.

Attackers target subcontractors behind trusted vendors, as explained by Zero Networks’ Chris Boehm. A compromised credential at an unknown company can open access to your systems through your vendor’s vendor.

VeriChat, an AI assistant from the University of Florida, helps hardware security engineers detect hidden backdoors in chip designs by answering security questions and running verification tools.

A former ransomware negotiator at DigitalMint was sentenced to 70 months in prison for sharing client information with the BlackCat ransomware group and later participating in attacks.

The EU and UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targeting Europe and its partners.

Lidl notified customers in Germany, Belgium, and the Netherlands that data was stolen after attackers breached one of its IT service providers.

Underground hacking forums are producing more original tutorials, with a focus on carding and cash-out techniques. Radware analyzed 8,870 posts, finding 3,034 unique guides after removing reposts.

Five people were charged in the UK following an NCA investigation into Russian Coms, a caller ID spoofing service linked to over a million scam calls.

CrashStealer, a new macOS infostealer, disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. First spotted in May, it was actively detected by early July.

ClickFix has evolved from a one-off social engineering trick into an industrialized attack ecosystem outpacing conventional antivirus and endpoint defenses, according to ReversingLabs.

Spanish police dismantled a cybercrime network accused of stealing and laundering €140 million through fake investment platforms, CEO fraud, and invoice fraud.

LabubaRAT, a Rust-based remote access tool, masquerades as NVIDIA software to infiltrate Windows systems, enabling post-compromise operations.

Dutch police, with Belgian authorities and Europol, dismantled a criminal network behind a global investment fraud scheme operating through dozens of fraudulent call centers.

Anthropic extended a promotion offering 50% higher limits for Claude Code users through July 19, 2026, after which limits return to standard levels.

Debian 13.6 (“trixie”) patches over a hundred advisories, including fixes related to an expired UEFI Secure Boot certificate authority installed by default since 2013.

Enterprises are rethinking where AI applications run, driven by demand for compute capacity, power, cooling, and low-latency connectivity, according to CoreSite.

Orca Security’s 2026 State of AI Security Report finds that 99.9% of fixable AI vulnerabilities remain unpatched, as organizations prioritize speed over basic cybersecurity hygiene.

Microsoft published a guide explaining the Windows servicing model, covering monthly security updates, optional preview releases, hotpatch updates, and feature delivery mechanisms.

Chatto, an open-source team messenger, offers self-hosted group chats with message data on infrastructure the operator controls, aiming at the same ground as commercial services.

Smart home security research could benefit from fake residents that simulate real usage, addressing the scarcity of datasets that require invasive, long-term monitoring of actual homes.

Microsoft will begin rolling out passkeys as the default authentication for Entra ID on September 1, 2026. Organizations with SMS or voice authentication enabled will be automatically enabled, prompting users to register passkeys during MFA.

Google is rolling out FIDO2 physical security key support as a second factor for Windows login via Google Credential Provider for Windows (GCPW) to all Workspace customers.

Check Point’s AI Security Report 2026 documents intrusions where AI autonomously ran exploitation workflows, generating thousands of commands with minimal human direction.

Researchers at Michigan Technological University discovered an “overthinking attack” that can tie up a robot for over a minute by exploiting how vision-language models read text in camera frames, such as signs or stickers.

SingGuard-NSFA, an open-source guardrail framework for agentic AI, ships four models (0.8B to 9B parameters) built on Qwen3.5 backbones, targeting operational threats in agent workflows.

FreeRDP 3.29.0 resolves 22 advisories in a security, bugfix, and maintenance update for the open-source Remote Desktop Protocol implementation.

AWS retooled Security Hub to include AI workload protection and Microsoft Azure security monitoring, with additional cloud platform support to follow.

Finance phishing succeeds because it sounds boringly normal, mimicking invoices and payment notices to bypass AI-based secure email gateways, according to Cofense.

VS Code 1.129 introduces a dedicated agent host for developers using AI coding agents, allowing multiple sessions to run in separate processes.

Microsoft introduced a registry-based policy for IT administrators to automatically accept Windows SSO permissions on Windows 11 24H2 and 25H2 devices managed with Entra ID.

A new guide on network operations management explores how intelligent workflows reduce manual work, improve visibility, and accelerate response across growing network complexity.

A weekly selection of cybersecurity jobs is available, spanning various skill levels.

New infosec products from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI were released this week.

(Source: Help Net Security)

Topics

ai defense strategies 90% ai application security 89% ai security agents 88% Supply Chain Attacks 87% ransomware trends 86% wordpress vulnerabilities 85% ai bug hunting 84% social engineering 83% oauth spoofing 82% authentication overhaul 81%