Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Protecting Vulnerable and Poorly Configured Network Devices

On July 13, 2026, NSA, CISA, the FBI, and co-sealing partners from twelve other countries published AA26-194A, a joint Cybersecurity Advisory (CSA) warning that Center 16 of Russia's Federal Security Service (FSB) continues to exploit vulnerable and poorly configured network devices across the defense industrial base, communications, energy, financial services, government facilities, and healthcare sectors. The advisory does not reference new exploits.

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware

During June 2026, Arctic Wolf Labs investigated multiple intrusions during which threat actors exploited CVE-2026-0257 as a consistent initial access vector, rapidly transitioning from perimeter compromise to domain-wide Qilin ransomware encryption across distinct victim environments.

The First Hour of a Zero-Day: Why Preparation Must Start Before Disclosure

The window between vulnerability disclosure and exploitation is shrinking. As exploit development accelerates, organizations can no longer afford to wait for a vulnerability to be disclosed or a patch to become available before taking action. Daniel dos Santos, VP of Research, explains why effective zero-day response depends on preparation that happens before an incident occurs.

Emerging Threat: (CVE-2026-63030, CVE-2026-60137) WordPress Core Unauthenticated RCE via wp2shell

wp2shell is the name given to an unauthenticated remote code execution attack against WordPress core. It is not a single bug. It is a chain of two separately tracked flaws that, combined, let an anonymous attacker run code on a default WordPress installation with no plugins, no valid account, and no user interaction. The first flaw, CVE-2026-63030, is a REST API batch-route confusion issue in WP_REST_Server::serve_batch_request_v1().

Unauthenticated RCE in WordPress core (wp2shell)

SQL injections are still among us. On July 17, WordPress released an emergency security update. Version 7.0.2 fixes an unauthenticated remote code execution flaw in WordPress core that an anonymous attacker can trigger against a stock install with no plugins involved. If your site runs an affected version, update today. WordPress.org has turned on forced auto-updates for affected sites because of how severe this is. We are tracking this vulnerability in Aikido Intel.

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability. The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers.

Resolve: One-Click Patching from Aurora Vulnerability Management

Vulnerability discovery is only half the story; remediation is where breach potential gets reduced. Resolve, part of Arctic Wolf's Aurora Vulnerability Management, brings one-click patch deployment across Windows, Mac, and Linux so security teams can move from "we found it" to "we fixed it" without the manual overhead. In this overview, see how Resolve turns vulnerability data into action: one-click patch orchestration, flexible scheduling, and clear visibility into remediation status — all inside the Aurora platform.

Vulnerability Exploitability: Is That Critical CVE Reachable?

A high CVSS score tells you how bad a vulnerability could be in theory, and EPSS tells you how likely it’s being exploited somewhere in the world, but neither knows anything about your environment. True vulnerability exploitability depends on reachability: whether the vulnerable code is actually loaded and called at runtime, whether it’s exposed on the network, and whether existing controls already block the path.

Benchmarking 13 AI models on rediscovering known CVEs

TL;DR Every frontier model launch now comes with the same cybersecurity claim: it finds vulnerabilities. But does it work on a real bug in a real repository, or just on a curated example? Of the dozen models you could pick, which is worth trusting with code review? And since the strongest models cost ten times or more per run than the cheapest, what does that extra spend actually buy you in bugs found?

SonicWall SMA1000 vulnerabilities in active exploitation

On July 14, 2026, SonicWall disclosed two vulnerabilities in SonicWall SMA1000 appliances. Models 6210, 7210, and 8200v are affected. CVE-2026-15409 is a critical (CVSS score of 10.0) unauthenticated server-side request forgery (SSRF) flaw that allows an attacker to force the appliance to make requests to unintended destinations.