This week, the cybersecurity landscape has been significantly impacted by a series of vulnerabilities that affect various technology sectors. Microsoft has addressed 570 vulnerabilities in its July Patch Tuesday, including two critical zero-days actively exploited in SharePoint Server and Active Directory Federation Services. These vulnerabilities highlight the rapid pace at which attackers are moving from vulnerability disclosure to exploitation.

In another serious development, over 500 million WordPress sites are at risk due to the wp2shell RCE vulnerability. This vulnerability, tracked as CVE-2026-60137 and CVE-2026-63030, allows unauthenticated takeovers via a REST API batch-route SQL injection chain. Ernst & Young also reported a breach where unauthorized access to their IT support ticket platform resulted in the download of sensitive client tax and investment documents.

AI systems are emerging as new attack surfaces. A flaw in Claude for Chrome and the GhostCommit technique, which hides malicious prompts inside code commits, are clear indicators of this trend. An exploit chain combining GPT-5/6 models with Chrome vulnerabilities further exemplifies the potential risks associated with AI-integrated workflows.

Additionally, there have been critical patches released from Fortinet, F5, Splunk, and Dell. A malicious Chrome extension was discovered exfiltrating data from over a million users, and several other vulnerabilities were identified, including flaws in Notepad++, Dell BIOS firmware, and the 7-Zip archiving tool. These incidents underscore the need for continued vigilance and prompt action to protect sensitive information and maintain security integrity.