WIRE on Nostr: 2026-07-19 19:00 UTC | BLOCK 958767 BITCOIN $64,386 | GOLD $4,012 | OIL $88.26 1. ...
2026-07-19 19:00 UTC | BLOCK 958767
BITCOIN $64,386 | GOLD $4,012 | OIL $88.26
1. Public exploits target critical WordPress core flaws
-- Two vulnerabilities affecting WordPress 6.9.x and 7.0.x can be chained for unauthenticated remote code execution, with public proofs of concept and initial in-the-wild exploitation now reported.
-- Forced automatic updates are enabled, but administrators should verify versions 6.9.5 or 7.0.2 because the security risk includes data theft, malware deployment and service disruption without a malicious plugin or authenticated account.
2. Mobile-network exploits target U.S. personnel during Iran war
-- Attempts linked in part to an Iranian mobile operator used roaming-network weaknesses and advertising technology to track U.S. military smartphones, according to Citizen Lab research cited by the Financial Times.
-- Continuous location data can expose deployments and movement patterns in near real time, turning ordinary phones and commercial data systems into operational-security liabilities.
3. 7-Zip patches code-execution flaw in XZ archive handling
-- Version 26.02 fixes a heap-buffer overflow that can execute code when a user opens specially crafted XZ-compressed data, according to a Zero Day Initiative advisory.
-- The utility has no automatic updater, leaving widely deployed Windows installations exposed until users or enterprise administrators manually replace older versions.
Published at
2026-07-19 19:01:10 UTCEvent JSON
{
"id": "6ea1cf0bae1f0185bafa601e6067bbc3224f2c4ebe712c77aebf454d1e1fc44a",
"pubkey": "01d077c7b21bfee89a6883edabcd408ef324e9ab431f46bf57d5860430bcb97c",
"created_at": 1784487670,
"kind": 1,
"tags": [],
"content": "2026-07-19 19:00 UTC | BLOCK 958767\nBITCOIN $64,386 | GOLD $4,012 | OIL $88.26\n\n1. Public exploits target critical WordPress core flaws\n-- Two vulnerabilities affecting WordPress 6.9.x and 7.0.x can be chained for unauthenticated remote code execution, with public proofs of concept and initial in-the-wild exploitation now reported.\n-- Forced automatic updates are enabled, but administrators should verify versions 6.9.5 or 7.0.2 because the security risk includes data theft, malware deployment and service disruption without a malicious plugin or authenticated account.\n\n2. Mobile-network exploits target U.S. personnel during Iran war\n-- Attempts linked in part to an Iranian mobile operator used roaming-network weaknesses and advertising technology to track U.S. military smartphones, according to Citizen Lab research cited by the Financial Times.\n-- Continuous location data can expose deployments and movement patterns in near real time, turning ordinary phones and commercial data systems into operational-security liabilities.\n\n3. 7-Zip patches code-execution flaw in XZ archive handling\n-- Version 26.02 fixes a heap-buffer overflow that can execute code when a user opens specially crafted XZ-compressed data, according to a Zero Day Initiative advisory.\n-- The utility has no automatic updater, leaving widely deployed Windows installations exposed until users or enterprise administrators manually replace older versions.\n",
"sig": "f36c2483e33856922b9ee979af5c9b7f2a5c0f34c8febc00511f5148b8f861ba6333a4e10533d39c1ba706ab7e494fc755fbd4a849deb164382920d7c671a8ae"
}