News Security CVE-2026-18072: Backdoored ARVE plugin enables admin logins without credentials July 29, 2026 / July 29, 2026 by Alex Mira | Leave a Comment CVE-2026-18072 affects Advanced Responsive Video Embedder (ARVE) 10.8.7, where a hardcoded backdoor can grant admin access without credentials. Check your version and remove 10.8.7 immediately if present. Read more » ARVE plugin Authentication bypass CVE-2026-18072 incident response plugin supply chain WordPress security
AI News Security OpenAI testing uncovers zero-day flaws in JFrog Artifactory: what’s confirmed about the eight CVEs July 29, 2026 / July 29, 2026 by Alex Mira | Leave a Comment OpenAI’s model evaluations led to eight CVEs in JFrog Artifactory being disclosed and fixed. Here’s what’s confirmed, what’s unclear, and what admins can do now. Read more » CVE-2026-65617 JFrog Artifactory openai Privilege escalation Software supply chain SSRF Vulnerability Management
News Windows Windows 11 KB5121767 is an out-of-band fix for select Dell PCs hit by July’s update July 21, 2026 / July 21, 2026 by Alex Mira | Leave a Comment Microsoft’s out-of-band KB5121767 targets Intel-based Dell PCs affected by an Intel IPF driver issue after recent Windows updates. Here’s what it fixes, who needs it, and how to avoid installing it unnecessarily. Read more » dell Intel microsoft Out-of-band update patch tuesday Windows 11 Windows Update
News Windows Microsoft will enable Copilot compose by default in Outlook Classic; Meeting Insights retires July 21, 2026 / July 21, 2026 by Alex Mira | Leave a Comment Microsoft is making Copilot’s compose box the default in Outlook—including Outlook Classic later this year—while retiring Meeting Insights in favor of a Copilot-only alternative. Licensing and opt-in controls remain pivotal, especially for government tenants. Read more » copilot DoD GCC High Meeting Insights Microsoft 365 New Outlook Outlook
News Windows Windows 10 KB5099539: RDP security upgrade, ESU-only rollout, and what’s fixed July 21, 2026 / July 21, 2026 by Alex Mira | Leave a Comment Windows 10’s July 2026 ESU update KB5099539 tightens RDP security with SHA‑2 support, hardens networking, and fixes File Explorer, OLE Automation, and more. Read more » ESU KB5099539 patch tuesday rdp Security Update Windows 10
News Security CISA flags active RCE exploitation in Joomla extensions; separate SQLi fix lands for Quix Page Builder July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment CISA added two actively exploited Joomla extension flaws to its KEV catalog, warning of RCE via file uploads in iCagenda and Balbooa Forms. Separately, Quix Page Builder patched an unauthenticated SQL injection in version 6.2.1. Read more » CISA CMS security cve Joomla Joomla extensions Patch management Remote code execution
News Security Zoom patches critical Windows account takeover flaw (CVE-2026-53412) and related privilege escalation issue July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment Zoom fixed a critical Windows account takeover flaw (CVE-2026-53412) and a related privilege escalation issue (CVE-2026-53411). Update Windows clients, VDI deployments, and the Meeting SDK without delay. Read more » CVE-2026-53411 CVE-2026-53412 Enterprise security Patch management VDI Windows security Zoom
News Security CVE-2026-25089 in Fortinet FortiSandbox: active exploitation confirmed, patch now and lock down access July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment CISA confirmed active exploitation of CVE-2026-25089 in Fortinet FortiSandbox. Here’s what’s affected, the fixed versions, and practical steps to patch and lock down access—plus what remains uncertain. Read more » CISA KEV Command Injection CVE-2026-25089 Fortinet FortiSandbox patch tuesday Vulnerability Management
News Security Patch now: WordPress Core “wp2shell” chain (CVE-2026-60137, CVE-2026-63030) July 20, 2026 / July 20, 2026 by Alex Mira | Leave a Comment Two WordPress Core bugs—CVE-2026-60137 and CVE-2026-63030—can be chained for pre-auth RCE on specific versions. Public PoCs exist. Update to 7.0.2 or 6.9.5 now. Read more » CVE-2026-60137 CVE-2026-63030 Remote code execution Security Update SQL injection wordpress
News Security Linux kernel privilege-escalation bugs touch cloud and industrial systems: what’s confirmed June 27, 2026 / June 27, 2026 by Alex Mira | Leave a Comment Multiple Linux kernel privilege-escalation bugs now documented by Google Cloud and CISA affect cloud workloads and at least one industrial product line. Here’s what’s confirmed and what to do next based on the advisories. Read more » CISA Cloud security cve Google Cloud ICS security Linux kernel Privilege escalation