All issues
Tech & Security Intelligence Issue 010 · 27 Jul 2026

The Weekly
Brief

If your website runs WordPress, stop and patch it. Ransomware gangs multiply and settle on mid-sized firms, Microsoft moves two Exchange Online deadlines that break old scripts and scanners, and NZ's biometric rules bite on 3 August.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 6 min read

In this issue

01 Patch Now

If your website runs WordPress, patch it today — "wp2shell" is being exploited now

On 17 July, WordPress disclosed two flaws in WordPress Core itself — not a plugin, not a theme — that can be chained together by an attacker with no account and no password to run their own code on your web server. Researchers named the chain "wp2shell". It combines CVE-2026-63030, a REST API batch-route confusion bug introduced in WordPress 6.9, with CVE-2026-60137, a SQL injection flaw in the author__not_in parameter of WP_Query present since 6.8.

Working proof-of-concept code appeared publicly within hours of disclosure, and on 21 July CISA added both flaws to its Known Exploited Vulnerabilities catalogue — the formal confirmation that they're being used in real attacks. The SQL injection affects 6.8.0–6.8.5, 6.9.0–6.9.4 and 7.0.0–7.0.1; the full remote-code-execution chain works on 6.9 and 7.0. Fixes are in 6.8.6, 6.9.5 and 7.0.2.

02 Threat Report

146 ransomware gangs and counting — and mid-sized businesses are the sweet spot

Security firm Black Kite published its 2026 Ransomware Report this week, and the headline finding is that the ransomware world has fragmented rather than shrunk. 61 new ransomware groups appeared between April 2025 and March 2026, taking the count of active groups to 146 by June 2026. The report tracked 7,551 victims over the period, with disclosures up 60% in the second half compared with the first.

The detail worth pausing on is who gets hit. The largest single share of victims were organisations turning over between USD 50 million and USD 100 million — not the giants, and not the corner dairy, but the established mid-sized firm with real revenue and a small IT team. Manufacturing was the most-targeted sector, followed by professional services, and 84.1% of victim postings landed on weekdays.

03 Business IT

Two Microsoft 365 deadlines that quietly break old scripts and office scanners

Microsoft has given administrators some breathing room on one deadline and is pressing ahead with another. On 17 July it confirmed that removing the -Credential parameter from Exchange Online PowerShell — the old way of connecting with a stored username and password — has been pushed back from July 2026 to December 2026. Microsoft's warning is blunt: scripts still using it "will break when you update to an Exchange Online PowerShell module version released beginning December 2026", and organisations should move now rather than wait.

Running alongside it is a change with a wider blast radius. Exchange Online is retiring legacy TLS 1.0 and 1.1 for POP3 and IMAP4 connections across 2026. Anything still connecting on those old protocols simply stops working; TLS 1.2 or later is required.

04 NZ Compliance

NZ's biometric privacy rules stop being optional on 3 August

New Zealand's Biometric Processing Privacy Code, issued by the Privacy Commissioner in July 2025, came into force on 3 November 2025 — but organisations already using biometrics were given a nine-month grace period to get compliant. That transition period ends on 3 August 2026: next Monday.

The Code sits under the Privacy Act and sets the rules for any organisation that collects or uses people's biometric information — face, fingerprint, voice or iris data used to identify or categorise someone. It covers collection, use, disclosure, responding to access and correction requests, and storage, security, retention and disposal. An amendment in March 2026 folded in privacy principle IPP3A, effective 1 May 2026.

Tip of the week

Put your website on the patching list, not just your PCs

Almost every business we talk to can tell us who looks after their laptops. Far fewer can say who updates their website. That gap is exactly what story 01 exploits — and it's not only WordPress: the same blind spot covers plugins, themes, e-commerce add-ons, the hosting control panel and the domain itself. Three things worth writing down this week, one line each: who hosts the site, who has admin logins to it, and who is responsible for applying updates. Then turn on automatic updates for WordPress core (and keep automatic backups so you can roll back if an update misbehaves), remove plugins and themes you no longer use, and make sure every admin account has multi-factor authentication and belongs to someone who still works with you. It's a half-hour job that closes off a category of incident that is genuinely nasty to clean up — attackers who own your site can email your customers from your own domain. If you'd like us to look at yours and tell you what version it's on and what's out of date, just ask.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup