Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Mythos Didn’t Break Your Security Program. Your Exposure Window Could

The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop short of addressing the single metric that determines whether any of those vulnerabilities actually lead to a breach: the exposure window.

The exposure window — the gap between the moment a vulnerability becomes exploitable and the moment your team fixes it — is the time an attacker has to do actual damage. That window is currently open far too wide. In 2025, the average eCrime breakout time dropped to 29 minutes. Even PCI DSS — the strictest compliance framework in the industry — allows 30 days to remediate a critical vulnerability. That’s a 1,000-to-1 gap between how fast attackers move and how fast organizations are expected to respond. And the stick propping this exposure window open? Mobilization — the ownership, remediation, and organizational complexity that lowers response times and raises risk.

In this article, I’ll walk through why the exposure window is now the metric that matters most, what keeps it open, and how AI-driven discovery is forcing proactive security teams to adopt the speed-based metrics that SOC teams have used for years.

New 7Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

26.02 subtracts the bytes already written and bails out if that running total ever exceeds the buffer. The same flawed length handling appears unchanged in 7-Zip source back to at least version 21.07 (2021), though neither ZDI nor 7-Zip has said which releases are actually exploitable.

CVE-2026–14266 is the latest in a run of memory-safety bugs in 7-Zip’s archive handlers. On April 27, version 26.01 fixed a batch of them, including the higher-scored CVE-2026–48095, an NTFS-handler heap-write overflow that GitHub Security Lab detailed on May 22 with a working proof-of-concept. The XZ flaw is the quieter of the two so far, and 26.02 rolls up every one of these fixes, so one update covers them all.

So update to 7-Zip 26.02 or later on every machine that opens archives from outside. Updating is a manual install from the official site, so set-and-forget machines will not pick it up on their own. Any product that ships a vulnerable copy of 7-Zip’s XZ decoder needs its own vendor fix.

WordPress Core “wp2shell” RCE flaws get public exploits, patch now

Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.

The wp2shell attack consists of two flaws, tracked as CVE-2026–63030 and CVE-2026–60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.

The flaws were discovered by Adam Kues of Searchlight Cyber, which says an unauthenticated attacker can exploit them against a default WordPress installation.

New Windows LegacyHive zero-day gives hackers admin privileges

A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.

Nightmare Eclipse published a proof-of-concept (PoC) exploit hours after Microsoft released its July 2026 Patch Tuesday updates, saying that it abuses a security vulnerability in the Windows User Profile Service, which has yet to receive a CVE ID for easier tracking.

However, unlike previous exploits released by NightmwareEclipse, the LegacyHive PoC has been modified to require additional credentials, making it harder for attackers to weaponize the vulnerability.

Astronomers spot an extremely rare galaxy mega-merger

Scale in the universe is hard to understand from a purely human perspective. Many times, the math just doesn’t sit well with our brains, which evolved to capture and process data about the world around us rather than grok the complexities of stellar dynamics and galaxy mergers. But every once in a while, astronomers find something that, if we can wrap our heads around the numbers, gives a sense of just how big the universe is.

That is precisely what a new paper, available on the arXiv preprint server from a group of astronomers led by Z.L. Wen of the Chinese Academy of Sciences, hopes to do when it describes a merger of not one, not two, but six supermassive galaxies and the active dynamics they are subject to.

Admittedly, this paper isn’t the one that originally found the cluster. That was done back in 2018 by several all-sky surveys, including the Two Micron All Sky Survey, WISE and SuperCOSMOS. But it was the first to identify that the cluster contained a group of six merging galaxies at its heart. That tidbit was hidden away in Dark Energy Spectroscopic Instrument (DESI) Legacy Imaging Surveys data.

Scientists Find a More Precise Way to Grow Artificial Blood Vessels, Using Magnets

Science may one day give us a way to replace damaged and diseased parts of the body with artificial replacements – but reproducing organs and tissues in the lab isn’t easy.

That’s especially true for networks of blood vessels, which at the level of fine, thread-like capillaries are microscopic – these capillaries can be as small as 0.005 millimeters (34 times thinner than a human hair), and only let blood cells through in single file.

Researchers led by a team from MIT have now published a study in PNAS that details a way of engineering blood vessels in the lab with significantly greater precision than before.

Study tests chronotype’s liver link and finds no significant association

Researchers found no significant association between chronotype and FibroScan-derived liver fat or stiffness in 119 medication-naïve adults with overweight or obesity. The exploratory findings cannot exclude smaller effects, particularly for fibrosis, and require confirmation in larger longitudinal studies.

/* */