grc-scanSecurity & governance
News digest20 July 2026Archived edition

Cybersecurity News

This edition was published on 20 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

Two threads ran through this week: the gap between a fix shipping and a working attack showing up is shrinking fast, now that AI tools can do some of that work automatically — and a growing share of the damage arrives through someone else's system, not a direct hit on the business itself.

  • Patch website software, plugins, and remote-access devices within days of a fix shipping, not weeks — the window before attackers show up keeps getting shorter.
  • Verify any change to bank details or payment instructions by phone, using a number you already had on file, never one supplied in the message itself.
  • Ask every outside company that touches your data — your accountant, host, or payroll provider — what they do to secure their own systems, since their weak point becomes yours.

Cybersecurity News — 2026-07-20

Generated: 2026-07-20 | Sources: The Hacker News, BleepingComputer, SecurityWeek, Security Affairs, Help Net Security, TechCrunch, Hunt.io


1. A New Bug Chain Lets Anyone Take Over a Default WordPress Site — No Login Needed

Researchers found a way to chain two flaws in WordPress's own core software (nicknamed "wp2shell") that lets a complete stranger take full control of a standard WordPress install — no plugins required, no account, nothing clicked by a victim. One bug confuses WordPress's built-in API into running commands it shouldn't; the other is a classic SQL injection (tricking a database into running attacker-supplied instructions instead of treating them as plain data). Chained together, they add up to remote code execution on a stock site. WordPress runs an estimated 500 million-plus websites worldwide, and public proof-of-concept exploit code is already circulating — a security firm says it has already seen real attackers using it. Fixed in WordPress 6.9.5 and 7.0.2.

Why it matters for your business: if your website runs on WordPress — a large share of small-business sites do, even ones built by an agency — check today whether it's on 7.0.2/6.9.5 or later rather than assuming automatic updates caught it. If you can't get a straight answer quickly, ask your host to block the /wp-json/batch/v1 address at their firewall as an immediate stopgap while the update lands.


2. Two "Zero-Day" Flaws in a Popular Remote-Access Device Are Being Actively Exploited

SonicWall confirmed that criminals are actively exploiting two flaws in its SMA1000 appliances — the boxes many businesses use to let staff connect securely to the office network from home or on the road (a VPN gateway). One flaw (rated the maximum 10 out of 10 for severity) lets a complete stranger, with no login at all, trick the device into fetching data from a location of the attacker's choosing; the second lets someone who's already logged in as an admin run arbitrary commands on the device. SonicWall says attackers are chaining the two together for full appliance takeover, and released emergency hotfixes; US federal agencies were given until 17 July to patch or disconnect affected devices.

Why it matters for your business: if your business or IT provider uses a SonicWall SMA appliance for remote access, this is a patch-today, not patch-this-month, situation — confirm the July hotfix is installed, and ask when the admin and VPN passwords were last changed, since a device that's been exposed to active exploitation shouldn't be trusted on old credentials.


3. A New Ransomware Gang Went From Break-In to Fully Locked Network in Under 24 Hours

Security researchers at Symantec documented a new ransomware operation, nicknamed "Spirals," that broke into an IT services firm through an internet-facing web server and, in well under a day, planted a hidden backdoor, switched off the target's security software, spread itself to more than a dozen computers, and encrypted everything — threatening to publish the stolen data within six days unless paid. It's so far a single confirmed case, so researchers can't yet say whether it's a new gang gearing up or a one-off, tailored job. Either way, the timeline is the story: attacks that used to take ransomware crews days or weeks to finish now take hours.

Why it matters for your business: if your business runs any of its own internet-facing servers — a website, a file server, anything reachable from outside your office — the old assumption that you'd "notice and respond in time" no longer holds; by the time anything looks wrong, it can already be over. Backups that are tested regularly and kept disconnected from your main network are what turn a bad day into a survivable one instead of a business-ending one.


4. AI Tools Are Now Writing Working Break-In Code — and Running Real Attacks, Not Just Chatting

Two separate reports this week show AI moving from "helpful assistant" to active participant in real intrusions. In a controlled test, researchers gave several leading AI models nothing but a public Chrome security-patch note and asked them to work backwards to a full working exploit — the same reverse-engineering a skilled hacker does by comparing the "before and after" code to figure out exactly what a fix was protecting against. One model, OpenAI's GPT-5.6, succeeded on its own, chaining several bugs into a complete exploit that broke out of Chrome's security sandbox. Separately, security firm Hunt.io says it found evidence of suspected Chinese state-linked hackers using commercially available AI coding tools — Anthropic's Claude Code and China's DeepSeek — as working parts of real break-ins into government networks in at least three countries, with the AI reportedly handling the reasoning on how to bypass defences, rewriting exploit code when it failed, and helping build fake login pages to steal credentials.

Why it matters for your business: for years, "we'll get to that patch within a month" was survivable because turning a fix into a working attack still took a skilled human real time and effort — that cushion is what's shrinking. The response doesn't change, just the urgency: install security updates as soon as they're available rather than batching them for a quiet week, because the gap between "a fix exists" and "someone is using the flaw against you" keeps getting shorter.


5. A Big Four Accounting Firm's Help-Desk Software Was the Way In to Client Tax Records

Ernst & Young (EY) is notifying clients that hackers broke into a third-party support-ticket platform used by its IT help desk, downloading documents over a roughly two-week window in the spring that included client tax filings and, for some clients, financial account details and Social Security numbers tied to investment holdings. EY says it has no evidence yet that the stolen data has been misused, and is offering two years of free identity-monitoring to those affected. The firm filed formal breach notifications in mid-July.

Why it matters for your business: you don't manage EY's help-desk software, but the lesson generalises directly — any outside firm you trust with sensitive paperwork (your accountant, bookkeeper, or payroll provider) inherits risk from its own suppliers, which you have no visibility into. When choosing or reviewing who handles your financial and tax data, it's a fair question to ask what they do to secure the systems that data passes through, and whether they'd tell you promptly if one of their own vendors were breached.


6. Hackers Took Over a Ruby Developer's Old, Unused Account to Slip Malware Into a Trusted Tool

Researchers uncovered a supply-chain attack, dubbed "SleeperGem," in which attackers hijacked at least two long-dormant maintainer accounts on RubyGems — the main library of pre-built building blocks that developers using the Ruby programming language rely on — and used them to publish poisoned updates to gems with hundreds of thousands of downloads. The malicious code specifically checked whether it was running on an automated build server or a real developer's own laptop, and only activated on the latter, to avoid being caught by automated scans.

Why it matters for your business: this is at least the third such supply-chain trick reported in recent weeks, and the pattern holds regardless of programming language — if your website or app was built with a modern toolchain, it almost certainly pulls in hundreds of small pre-built pieces automatically, any one of which could be swapped out like this. Ask whoever built or maintains your site whether they pin dependency versions and review what's changed before accepting an update, rather than always taking the newest version automatically.


7. A Third of UK Businesses Were Breached Last Year — and One Redirected Payment Cost £700,000

New UK government-backed figures show 43% of UK businesses suffered a cyber breach or attack in the past year, with phishing the single dominant cause at 38% — well ahead of any technical hacking method. Text-message scams ("smishing") are a growing part of that picture industry-wide, now making up a large and rising share of phishing attempts as criminals diversify beyond email. A concrete example from earlier this year: UK-headquartered energy firm Zephyr Energy lost £700,000 when hackers hijacked a genuine payment process and redirected a contractor payment at its US subsidiary into an account they controlled — a classic "business email compromise," where the trick isn't breaking software, it's fooling a person mid-transaction.

Why it matters for your business: train whoever approves payments to verify any change to bank details or payment instructions by phone, using a number you already had on file — never one included in the email, text, or call making the request — and treat "urgent, don't tell anyone" language as itself a warning sign, since that phrasing is a technique attackers use deliberately, not a coincidence.


8. UK Marketing and Cookie-Consent Fines Just Jumped 35-Fold — From £500,000 to £17.5 Million

Under the UK's new Data (Use and Access) Act, the maximum fine regulators can issue for breaking the rules on email/SMS marketing and cookie consent (the rules known as PECR) rose from £500,000 to £17.5 million or 4% of worldwide turnover — the same ceiling that applies to a serious GDPR breach. Lawyers note that some businesses had reportedly started treating the old, lower cap as a manageable cost of doing business; at the new level, that calculation no longer works, and the regulator has also gained stronger powers to demand documents and interviews.

Why it matters for your business: if you send marketing emails or texts, or run a website with a cookie banner, this is a good week to actually check the basics — that you have clear consent on file for who you're emailing or texting, an easy way to opt out, and a cookie banner that doesn't quietly nudge visitors into "accept all." Not because a fine is likely tomorrow, but because the cost of getting it wrong just changed by a factor of 35.


9. A Health-Diagnostics Giant's Customer Portal Was Breached Using Stolen Customer Logins

Abbott Laboratories is investigating two separate incidents at once. An extortion gang claims to have stolen data from older, inherited computer systems in Abbott's Cancer Diagnostics business — part of a company it had previously acquired — while a second attacker says they got into Abbott's LabCentral customer support portal using compromised customer login details, then quietly pulled files out over several weeks before being noticed. Abbott says its operations weren't affected and that the portal held mainly public technical documents rather than sensitive customer data, though the full picture is still being confirmed.

Why it matters for your business: two lessons apply beyond a company Abbott's size — systems inherited through a merger or acquisition often run older software and get less attention than "core" systems, so they deserve a deliberate check rather than being left as-is; and any customer-facing portal you run is only as safe as the logins used to reach it, so encourage or require customers to use unique passwords and, where you can offer it, multi-factor authentication.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.