Today’s Briefing
CVE-2026-63030 in WordPress core permits unauthenticated remote code execution and was disclosed on 17 July with a GitHub security advisory; Rapid7 has assigned it the identifier wp2shell. Six critical Adobe vulnerabilities appeared on the watchlist today, five in ColdFusion (authentication bypass, SQL injection, code injection, and authorisation flaws enabling unauthenticated RCE) and one in Illustrator requiring user interaction, though none are yet flagged as exploited.
Top Stories
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.
Get the brief at 07:00, every weekday.
The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.