IT News Week 28/2026: Microsoft's Record-Breaking Patch, WordPress RCE, OpenSSL HollowByte
The week of July 18 is one of the busiest security weeks of 2026 — Microsoft Patch Tuesday with record numbers, critical WordPress and OpenSSL vulnerabilities, supply-chain attacks via GitHub/PyPI/FakeGit, and the first documented use of LLMs in botnet development.
Deep Dive: Patch Management Is Critical
Microsoft Patch Tuesday: 622 CVEs, Two Zero-Days
Microsoft closed 622 security vulnerabilities in its July update—a new record. Among them were two actively exploited zero-days: a privilege escalation bug in the Windows kernel and an RCE vulnerability in Exchange Server. Patching is urgently required for self-hosted infrastructure (Exchange, Windows Server).
WordPress Core "wp2shell": RCE with Public Exploits
Two critical RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) allow attackers to install webshells and load malicious plugins—without authentication. Public exploits have been available since July 18. Immediate patching is required.
HollowByte: OpenSSL DDoS with a Payload of Just 11 Bytes
A vulnerability (“HollowByte”) allows unauthenticated attackers, to trigger a memory overflow on OpenSSL servers using a payload of just 11 bytes, thereby causing a DoS condition. Affects all OpenSSL versions with the compression handshake enabled—relevant for anyone running TLS termination on their own servers.
7-Zip: RCE via Malicious Archives
7-Zip Version 26.02 patches an RCE vulnerability that allows attackers to execute arbitrary code via specially crafted archives. Updating to 26.02 is strongly recommended—7-Zip is in use on nearly every workstation and many servers.
Deep Dive: AI in the Crosshairs
TuxBot v3: LLM-Powered Botnet Development
The next evolution of the TuxBot IoT botnet exhibits code patterns that suggest LLM-generated development. The botnet leverages newer exploits for routers and IoT devices and demonstrates accelerated feature development—an indication that attackers are actively using AI tools.
Agent Data Injection: Tricking AI Agents into Making Erroneous Clicks
Researchers have presented a new attack vector that can trick AI agents into, to make erroneous clicks or execute attacker commands. The attack exploits data injection into the AI agent’s context—highly relevant for anyone using AI agents in production workflows.
Cursor IDE: RCE Vulnerability in "Run on Clone" (CVSS 9.8)
The AI code editor Cursor contained a critical vulnerability (CVSS 9.8): In cloned repositories, a malicious .cursor/rules command could lead to code execution on Windows. The "Run on Clone" feature automatically executed commands before the user had even seen the code. Patched in Cursor >= 1.5.x.
Digest: Other Important News
Security
- Windows LegacyHive Zero-Day: Privilege escalation on current systems — Attackers gain admin privileges on fully patched Windows systems. Unofficial patch available.
- GitHub and PyPI: Time-Based Defenses Against Supply-Chain Attacks: New packages must undergo a waiting period before they are accepted as dependencies.
- Microsoft warns of a sharp increase in ACR Stealer attacks: The malware steals browser passwords, authentication tokens, and sensitive documents from enterprise environments.
- 11 legacy Microsoft-signed Linux UEFI shims can bypass Secure Boot: Outdated shims allow attackers to bypass Secure Boot on affected systems.
- ShareFile Storage Zone Controllers: Immediate shutdown recommended: Progress has strongly advised ShareFile customers to shut down their Storage Zone Controllers immediately.
AI & Development
- OpenAI Accidentally Deletes Hugging Face Model: OpenAI admitted that its AI models accidentally deleted a Hugging Face repository during a sandbox test.
- Debian votes on LLM usage: The Debian project is discussing a general resolution on the use of LLMs within the project—ranging from a complete ban to pragmatic acceptance.
Enterprise IT
- Ernst & Young: Data breach following a hack of the support system: The auditing firm confirmed a data breach following the compromise of a third-party support system.
- Windows KB5121767: OOB update fixes shutdown bug on Dell PCs: Microsoft has released an emergency update that fixes a bug from the July 2026 security update.
- Zeiss is expanding German EUV lithography production by 25,000+ m²: The investment ensures European independence in lithography technology for semiconductor production.
Compiled on July 18, 2026. Sources: Ars Technica, The Hacker News, BleepingComputer, heise.de, Cloudflare Blog, GitHub Blog.
senn-tech