A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
In brief

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

The AWS Kiro flaw highlights a serious new class of risk in agentic development tools: untrusted web content can become executable influenc…

Jul 22, 2026

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

The growing exploitation of WP2Shell shows how quickly a critical WordPress core vulnerability can move from disclosure to mass scanning an…

Jul 21, 2026

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The exploitation of the Palo Alto Networks GlobalProtect VPN flaw by the Qilin ransomware group highlights why remote-access systems must b…

Jul 21, 2026

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

The research on open-source Android AI agents highlights a new and uncomfortable security problem: AI agents can be manipulated by what the…

Jul 21, 2026

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

The EncForge ransomware campaign shows that AI and machine-learning infrastructure is now being targeted as a distinct and valuable attack …

Jul 21, 2026

Critical ServiceNow code execution flaw now exploited in attacks

The active exploitation of a critical ServiceNow code execution vulnerability highlights the growing risk around workflow platforms that si…

Jul 21, 2026

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

The FakeGit campaign shows how attackers are industrializing abuse of GitHub to distribute malware through fake open-source projects.Resear…

Jul 21, 2026

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

The reported Hugging Face breach highlights a new and uncomfortable reality: AI infrastructure is now part of the software supply chain, an…

Jul 21, 2026

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

The SonicWall SMA1000 zero-day exploitation shows how dangerous it becomes when attackers compromise remote-access appliances before organi…

Jul 21, 2026

Estée Lauder discloses data breach via Oracle E-Business flaw

The Estée Lauder breach linked to an Oracle E-Business Suite flaw highlights the serious risk created when enterprise business applications…

Jul 21, 2026

Hugging Face discloses breach linked to autonomous AI agent

The Hugging Face breach is an important warning that AI infrastructure has become part of the modern software supply chain, and attackers a…

Jul 20, 2026