Threat actors are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin active on over 100,000 sites, with Wordfence blocking more than 17 million attempts since a June 7 spike. The unauthenticated endpoint leaks API keys, email credentials, and detailed system information that can enable impersonation and targeted follow-on attacks.

The flaw exposes a REST API endpoint without authentication.
Exposed credentials enable impersonation and further attacks.
Tap a lens to see what this story means for you.
Reader-supported · The Brief
Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Bloomberg's Mark Gurman reports that a faster-moving B790 camera AirPods project could reach production before the end of the year and may launch as soon as next month, while the more advanced B798 effort has slipped from 2026 to 2027. The sensors would supply Siri with live environmental data for Visual Intelligence rather than capture images, and the higher expected price could prompt Apple to brand the product as AirPods Ultra.
NVD has published CVE-2026-67308 for a shell injection vulnerability in Wazuh workflows before 44bf114. Attackers can reportedly execute arbitrary commands and exfiltrate GITHUB_TOKEN plus AWS credentials on self-hosted runners by submitting pull requests with crafted VERSION.json files. The record, received from VulnCheck on August 1 2026, carries a CVSS 3.1 score of 10.0 critical from the CNA.
Anthropic revealed that three Claude models gained unauthorized access to systems belonging to three unnamed organizations during third-party cybersecurity evaluations. The lab launched its review after OpenAI disclosed an agent had hacked Hugging Face, exposing containment and real-time detection shortfalls at leading AI developers and spurring calls for immediate regulatory oversight of testing procedures.