Security news, decoded.
73 stories in the last 7 days, naming 202 CVEs; 59 of those CVEs are in CISA KEV.
The wire
Tuesday, Jul 219 stories
- SecurityWeekEstée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
Cosmetics giant Estée Lauder has confirmed that sensitive employee data was stolen due to a zero-day vulnerability in Oracle E-Business Suite (CVE-2025-61882). The flaw allowed unauthenticated remote code execution and was exploited by the Cl0p cybercrime group starting in August 2025. In June 2026, the company revealed that personal and financial information of employees had been accessed, including names, Social Security numbers, and health records. Estée Lauder is offering two years of free identity monitoring to affected individuals and urging vigilance against phishing attempts.
Reported exploitedOracle E-Business Suite - Help Net SecuritySonicWall SMA zero-days were exploited weeks before disclosure
Researchers from Volexity have confirmed that two critical vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 devices—CVE-2026-15409 and CVE-2026-15410—were actively exploited as zero-day flaws weeks before being publicly disclosed. These exploits enabled attackers to gain unauthorized access, install custom malware, and maintain persistent control over vulnerable systems. The attacks started as early as June 22, 2026, with threat actors leveraging these flaws to bypass security controls and exfiltrate sensitive data. SonicWall has issued patches, but experts warn that patching alone is insufficient; organizations must also check for signs of compromise and reset credentials.
Reported exploitedSecure Mobile Access (SMA) 1000 Series - BleepingComputerCritical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN software (CVE-2026-0257) to gain unauthorized access and deploy ransomware. The flaw was patched on May 13, but attackers began using it as early as May 17, with CISA adding it to its Known Exploited Vulnerabilities list on May 29. Cybersecurity firm Arctic Wolf confirmed multiple breaches linked to this exploit, resulting in widespread encryption of victim systems. With over 170,000 exposed GlobalProtect instances tracked online, urgent remediation is advised for any unpatched deployments.
Reported exploitedGlobalProtect - Help Net SecurityEstée Lauder discloses data breach tied to Oracle EBS vulnerability
Cosmetics giant Estée Lauder has revealed a data breach linked to an unpatched vulnerability in Oracle E-Business Suite (EBS), which was used for internal HR operations. The breach occurred on or around August 9, 2025, when an unauthorized party accessed the system and stole sensitive personal and financial information from some individuals. The incident is connected to the exploitation of CVE-2025-61882, a critical flaw allowing remote code execution without authentication. Oracle issued patches for this vulnerability on October 4, 2025, but many organizations remained vulnerable during the active exploitation period. Estée Lauder has engaged cybersecurity experts, informed authorities, and is providing two years of free identity monitoring to affected individuals.
Reported exploitedOracle E-Business Suite - The Hacker NewsWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are actively exploiting two critical vulnerabilities in WordPress—CVE-2026-63030 and CVE-2026-60137—to achieve unauthenticated remote code execution (RCE) and fully compromise vulnerable sites. These flaws, collectively named wp2shell, allow attackers to execute arbitrary code on default WordPress installations without requiring authentication or plugins. Security researchers have reported widespread exploitation attempts globally, with malicious actors uploading web shells, stealing credentials, and creating backdoor admin accounts. Cloudflare and Wiz have confirmed that a significant percentage of WordPress deployments were initially exposed to these issues, though remediation efforts have reduced exposure.
Reported exploitedWordPress core - SecurityWeekExploitation of ServiceNow Vulnerability Seen Days After Disclosure
A critical remote code execution vulnerability in ServiceNow's AI platform, tracked as CVE-2026-6875, is being actively exploited just days after its disclosure. The flaw allows unauthenticated attackers to bypass sandbox protections and execute arbitrary code under specific conditions. While ServiceNow has deployed patches for hosted instances, self-hosted customers are responsible for applying them. Cybersecurity firm Searchlight Cyber published technical details on July 14, followed by reports from Defused indicating real-world exploitation using those methods. Although ServiceNow initially stated it had no evidence of active attacks, a spokesperson confirmed awareness of the exploitation but noted it appears limited to non-hosted environments.
Reported exploitedServiceNow AI platform - SecurityWeekZimbra Update Patches Critical Vulnerabilities
Zimbra has issued a new security update addressing multiple high-severity vulnerabilities, including a critical command injection flaw disclosed in late June. The bug affects the SNMP monitoring feature when specific services are active, allowing unauthenticated attackers to execute arbitrary system commands. Version 10.1.20 of the Zimbra Collaboration Suite includes a full fix for this issue, along with patches for four cross-site scripting (XSS) vulnerabilities, a mail forwarding bypass, and several other access control and integration-related flaws. While Zimbra warns users to upgrade immediately, it has not confirmed whether any of these issues have been actively exploited.
PatchZimbra Collaboration Suite - The Hacker NewsNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
A new ransomware variant called ENCFORGE has emerged, specifically targeting AI infrastructure components like model weights and training datasets. This malware is being deployed by the JADEPUFFER threat actor following exploitation of an unpatched vulnerability in Langflow versions prior to 1.3.0. The flaw, CVE-2025-3248, allows remote code execution without authentication and remains a high-risk issue with a CVSS score of 9.8. Researchers at Sysdig discovered that attackers are using this entry point to deploy ENCFORGE, which encrypts AI-specific file formats such as PyTorch checkpoints, Hugging Face models, and FAISS indexes. The ransomware avoids exfiltrating data but focuses on rendering AI assets unusable, potentially costing organizations hundreds of thousands in recovery costs. Immediate mitigation includes upgrading Langflow to version 1.9.1 or later and securing Docker socket access.
Reported exploitedLangflow - The Hacker NewsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
A critical vulnerability in ServiceNow AI Platform, identified as CVE-2026-6875, is currently being actively exploited by attackers to execute arbitrary code without authentication. The flaw, rated with a CVSS score of 9.5, enables sandbox escape and has been observed in real-world attacks targeting the "/assessmentthanks.do" endpoint. Patches have been issued for several versions including Brazil EA/GA, Australia Patch 2, Zurich Patch 7b/9, and Yokohama Patch 12 Hot Fix 1b/Patch 13. Security researchers emphasize the need for immediate patching to prevent full system compromise.
Reported exploitedServiceNow AI Platform
Monday, Jul 2016 stories
- BleepingComputerEstée Lauder discloses data breach via Oracle E-Business flaw
Cosmetics giant Estée Lauder has disclosed a data breach following an attack that exploited a vulnerability in Oracle E-Business Suite (CVE-2025-61882). Hackers gained unauthorized access on August 9, 2025, stealing personal details such as full names, Social Security numbers, health records, and financial account information. The flaw allowed remote code execution and was actively exploited by the Clop ransomware group since early 2025. Oracle issued patches for the issue in October 2025, but the breach highlights ongoing risks for organizations using unpatched systems.
IncidentOracle E-Business Suite - BleepingComputerSonicWall SMA1000 flaws exploited as zero-days to push custom malware
Threat actors have exploited two zero-day vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances—CVE-2026-15409 and CVE-2026-15410—to install custom malware on vulnerable systems. These flaws allowed attackers to bypass authentication, gain root access, and deploy malicious tools like KNUCKLEBALL, Sou5, and ORANGETAIL. Security firm Volexity uncovered the attack chain, revealing that the threat actor, tracked as UTA0533, began exploiting these issues as early as June 22, weeks before public disclosure. SonicWall has issued patches for versions 6210, 7210, and 8200v; users are urged to apply them immediately.
Reported exploitedSMA1000 Secure Mobile Access appliances - Dark Reading'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Two critical vulnerabilities in WordPress, CVE-2026-60137 and CVE-2026-63030, are being actively exploited to enable unauthenticated remote code execution (RCE) on millions of sites. When combined, these flaws allow attackers to fully compromise default installations without needing login credentials. The vulnerabilities were discovered using AI tools and have already led to widespread exploitation, including the creation of backdoor admin accounts and deployment of malware like Overlord RAT. WordPress has issued a patch in version 7.0.2, urging all users to update immediately.
PoC publicWordPress Core - BleepingComputerCursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Security researchers uncovered sandbox escape techniques affecting four popular AI-powered coding assistants: Cursor, OpenAI's Codex, Google's Gemini CLI, and Antigravity. These vulnerabilities allowed attackers to execute arbitrary code outside the sandbox by manipulating files that external tools later process. The flaws were identified by Pillar Security and categorized into multiple failure modes related to unsafe file handling and overly trusting command allowlists. Most issues have been addressed in recent software updates, though some vendors downgraded the severity due to perceived low exploitability. The findings highlight a broader design flaw in how these tools handle workspace files.
ResearchCursor - BleepingComputerJadePuffer agentic attacks now target AI model data with ransomware
A new variant of the JadePuffer ransomware, now using a custom tool named EncForge, is targeting AI infrastructure by encrypting critical assets like training datasets and model checkpoints. The threat actor exploited a vulnerability in Langflow (CVE-2025-3248) to gain access and deploy ransomware designed specifically for AI environments. This development highlights the growing risk of ransomware tailored to disrupt machine learning operations.
IncidentJadePuffer - Dark ReadingRemediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
Ivanti is leveraging large language models (LLMs) to enhance its vulnerability detection and remediation efforts. Recently, an LLM identified a critical vulnerability, CVE-2026-10520, in Ivanti’s Sentry mobile gateway, which was rated as maximum severity with a CVSS score of 10 out of 10. The company has begun integrating advanced AI models into its security red teams to uncover and fix flaws that traditional tools miss. Ivanti’s CISO, Daniel Spicer, shared insights on how the initiative is progressing, highlighting successes in both identifying and resolving vulnerabilities using models from Anthropic and OpenAI.
AdvisorySentry mobile gateway - SANS Internet Storm CenterWordPress Exploitation Underway (CVE-2026-63030) - SANS ISC
A critical SQL injection vulnerability in WordPress Core, tracked as CVE-2026-63030, is currently being actively exploited. Dubbed 'wp2shell' by researchers, this flaw allows unauthenticated attackers to achieve remote code execution through the REST API. Attackers are already probing systems using crafted requests that attempt to inject malicious payloads into database queries. If you're running WordPress, check your exposure at https://wp2shell.com and assume compromise if vulnerable. Immediate patching is strongly recommended.
Reported exploitedWordPress Core - The Hacker NewsExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A server used by a malware operator was left unsecured, allowing researchers at Rapid7 to recover a full toolkit containing lure templates, test files, and documentation. The data reveals an AI-assisted approach to crafting phishing attacks that exploit CVE-2025-33053 (CVSS 8.8), a WebDAV vulnerability patched in June 2025. The campaign targeted Mexican users via a fake government ID lookup site, delivering infostealers through malicious .scr files disguised as PDFs. Researchers found evidence suggesting the attackers used open-source AI coding tools to automate parts of their workflow, including generating phishing content and testing multiple signed binaries for potential hijack opportunities.
Incident - Help Net SecurityServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Threat intelligence firm Defused has confirmed that attackers are actively exploiting CVE-2026-6875, a severe pre-authentication remote code execution flaw in ServiceNow's AI Platform. This vulnerability allows unauthenticated users to bypass the script sandbox and execute arbitrary code on affected systems. Discovered by Searchlight Cyber researchers, the flaw was patched by ServiceNow in late June 2026, but exploitation in the wild began shortly after the public disclosure on July 13. Attackers are using payloads targeting the /assessmentthanks.do endpoint, employing a novel method for sandbox escape compared to the original proof-of-concept. Organizations running self-hosted instances should apply the latest security updates immediately.
Reported exploitedServiceNow AI Platform - SecurityWeekSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
Two critical zero-day vulnerabilities in SonicWall secure remote access appliances were actively exploited by a threat actor for several weeks before being patched. According to Volexity, attackers used CVE-2026-15409 and CVE-2026-15410 to deploy custom malware like KnuckleBall and gain unauthorized access to systems. SonicWall issued hotfixes on July 14 after the exploitation was discovered as early as June 22. CISA has also added these flaws to its Known Exploited Vulnerabilities catalog.
Reported exploitedSMA1000 secure remote access appliances - The Hacker News⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A critical remote code execution vulnerability in WordPress Core has been actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary code on vulnerable installations. The flaw, known as wp2shell, combines two issues—CVE-2026-63030 and CVE-2026-60137—to enable full system compromise without authentication or plugins. Proof-of-concept exploits are already circulating, and early signs of real-world attacks have emerged. Meanwhile, SonicWall Secure Mobile Access (SMA) appliances were targeted with zero-day exploits before patches were publicly available. Two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, allowed attackers to achieve arbitrary command execution. Both flaws have now been addressed by SonicWall. Organizations running these products should prioritize patching immediately to mitigate risks.
RoundupWordPress Core - Check Point Research20th July – Threat Intelligence Report
This week saw multiple major cybersecurity incidents and patches. Ernst & Young disclosed a data breach via a compromised third-party IT support platform, potentially exposing sensitive client and employee data. Jscrambler suffered a supply chain attack where stolen credentials led to the distribution of malicious npm packages. Meanwhile, Coca-Cola's subsidiary Fairlife confirmed a ransomware attack that disrupted U.S. dairy production. In terms of vulnerabilities, Microsoft addressed 622 flaws in its largest-ever Patch Tuesday update, including two actively exploited issues (CVE-2026-56164 and CVE-2026-56155). WordPress issued emergency fixes for two critical RCE flaws (CVE-2026-63030 and CVE-2026-60137), while SonicWall released hotfixes for two zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) being exploited by ransomware groups.
Reported exploitedJavaScript code-protection package - The Hacker NewsRussian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Russian intelligence services are actively exploiting internet-connected IP cameras to monitor military logistics, troop movements, and weapons shipments in NATO countries and Ukraine. According to a cybersecurity advisory from the Netherlands' AIVD and MIVD, these attacks are ongoing and involve using exposed devices with weak or default credentials. The compromised cameras provide real-time surveillance capabilities, including targeting assistance in active conflict zones. Cybersecurity firm Censys estimates over 87,000 vulnerable cameras are accessible online in Europe and Ukraine, many running outdated software with known exploits like CVE-2016-7407 and CVE-2021-39275. Defenders are urged to secure their networks by disabling public access, updating firmware, changing default passwords, and limiting camera visibility.
ResearchRussian intelligence service - BleepingComputerCritical ServiceNow code execution flaw now exploited in attacks
A critical vulnerability in ServiceNow's AI Platform, CVE-2026-6875, is now being actively exploited by attackers, according to threat intelligence firm Defused. The flaw allows unauthenticated users to break out of a sandbox and execute arbitrary code remotely. Despite patches being issued on July 13, real-world attacks were detected just days later. ServiceNow urges all users to apply the latest security updates immediately.
Reported exploitedServiceNow AI Platform - The Hacker NewsNew 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
A new vulnerability in 7-Zip, tracked as CVE-2026-14266, allows attackers to execute arbitrary code during the extraction of specially crafted XZ files. The flaw stems from a heap-based buffer overflow in the way 7-Zip handles XZ chunked data. Trend Micro’s Zero Day Initiative disclosed the issue on July 15, and a fix was included in version 26.02, released on June 25. The vulnerability requires user interaction—specifically, opening a malicious file—but does not allow remote exploitation over the network. While no public exploits or proof-of-concepts have been observed yet, users are strongly advised to update to 7-Zip 26.02 or later to mitigate the risk.
PatchXZ decoder in 7-Zip - SecurityWeekWP2Shell WordPress Vulnerabilities Exploited in the Wild
Two recently patched WordPress vulnerabilities, known as WP2Shell (CVE-2026-60137 and CVE-2026-63030), are currently being actively exploited in the wild. These flaws allow attackers to execute arbitrary code without authentication on affected installations. The vulnerabilities impact WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Patches were released in versions 6.9.5 and 7.0.2, and automatic updates have been enabled for affected sites. Cybersecurity firms including Hexastrike and WatchTowr have confirmed real-world exploitation attempts, with proof-of-concept exploits appearing soon after disclosure.
Reported exploitedWordPress Core
Sunday, Jul 194 stories
- The Hacker NewsCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has issued patches for a severe vulnerability in NGINX that could allow remote code execution under certain conditions. The flaw, tracked as CVE-2026-42533, was addressed on July 15 in nginx versions 1.30.4 (stable) and 1.31.3 (mainline), along with NGINX Plus 37.0.3.1. Attackers can exploit this by sending specially crafted HTTP requests to trigger a heap buffer overflow in the worker process. While primarily a denial-of-service vector, the vulnerability may enable remote code execution if address space layout randomization (ASLR) is disabled or bypassed. This occurs due to a misalignment in the script engine’s two-pass evaluation of regex-based map directives used in string expressions. A researcher named Stan Shaw argues that the flaw provides a method to bypass ASLR itself, potentially making it more dangerous than F5 acknowledges. F5 rates the vulnerability as high severity, with a CVSS v4 score of 9.2. All versions from 0.9.6 up to 1.31.2 are affected, spanning over a decade of NGINX usage. While mitigation options exist—like using named captures instead of numbered ones—Shaw warns these do not fully resolve the issue. He recommends upgrading immediately to the latest stable or mainline releases.
PatchNGINX Ingress Controller - The Hacker NewsSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A new threat actor, tracked as UTA0533, has been actively exploiting two undisclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series devices since June 22, 2026. These zero-days—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—were used to gain root access and deploy custom malware on compromised appliances. Researchers from Volexity discovered the attacks during an incident response investigation and confirmed that the vulnerabilities were chained together to allow arbitrary command execution. SonicWall has since released patches for both issues. Attackers leveraged these flaws to install persistent backdoors, steal credentials, and maintain long-term access to vulnerable systems.
Reported exploitedSecure Mobile Access (SMA) 1000 series - OX SecurityCVE-2026-3602: SQL Injection in IBM App Connect Enterprise Leads to Code Execution
Researchers at OX Security discovered a SQL injection flaw in IBM App Connect Enterprise and IBM Integration Bus for z/OS, tracked as CVE-2026-3602. This vulnerability enables attackers to create arbitrary files on a victim's system through a maliciously crafted SQL file. If exploited successfully, it can lead to remote command execution and full system compromise. The flaw requires user interaction, typically via social engineering tactics to lure victims into importing the malicious file. IBM has released patches for affected versions of its software.
PoC publicIBM App Connect Enterprise - Help Net SecurityWeek in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
This week's security highlights include two actively exploited zero-day vulnerabilities in SonicWall Secure Mobile Access appliances (CVE-2026-15409, CVE-2026-15410), which have been patched and require immediate firmware upgrades. Additionally, the latest WordPress 7.0.2 update resolves one critical and one high-severity flaw, both labeled as urgent for remediation. Other notable developments include new AI-driven attack methods, phishing trends, and a surge in ransomware activity via email vectors.
Roundup
Saturday, Jul 183 stories
- BleepingComputerUpdate now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip has issued version 26.02 to resolve a high-risk remote code execution (RCE) vulnerability that could let attackers run malicious code through specially crafted XZ-compressed files. The flaw, identified by researcher Landon Peng and detailed in ZDI-26-444, stems from improper handling of available space during decompression, leading to potential heap-based buffer overflows. While no active exploitation has been reported yet, the lack of an automatic update mechanism means users must manually upgrade to mitigate risks. Given 7-Zip’s widespread use, unpatched systems remain exposed to targeted attacks involving malicious archives.
Patch7-Zip - BleepingComputerWordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public proof-of-concept exploits have emerged for the critical 'wp2shell' remote code execution vulnerabilities in WordPress Core, urging immediate action from site administrators. The vulnerabilities, CVE-2026-63030 and CVE-2026-60137, allow unauthenticated attackers to execute arbitrary code on affected installations running versions 6.9.x and 7.0.x. These flaws can be exploited without prior authentication and affect default setups with no additional plugins required. The WordPress security team has activated forced auto-updates to address the issue, recommending users upgrade to version 7.0.2 or 6.9.5 as soon as possible.
PoC publicWordPress Core - Help Net SecurityTwo new high severity WordPress vulnerabilities, patch immediately!
WordPress has issued a security update in version 7.0.2 to resolve two significant vulnerabilities, including one critical flaw. The issues—CVE-2026-60137 (SQL injection) and another related to REST API batch-route confusion leading to potential remote code execution—were reported by multiple researchers. Sites running WordPress 6.9 or 6.8 are impacted, with updated versions 6.9.5 and 6.8.6 available. As a temporary workaround, administrators can restrict access to the batch API via plugins or WAF rules, though full protection requires applying the latest updates.
PatchWordPress
Friday, Jul 178 stories
- Rapid7 BlogCVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
A critical remote code execution flaw, CVE-2026-63030, has been patched in WordPress Core following a GitHub Security Advisory issued on July 17, 2026. The vulnerability allowed unauthenticated attackers to execute arbitrary code via the REST API batch endpoint, potentially leading to full site compromise. It affected versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Fixes are now available in 6.9.5, 7.0.2, and 7.1 Beta 2. Although no active exploitation has been reported yet, the lack of authentication requirements and widespread use of WordPress make this a high-risk issue. Immediate patching is strongly advised.
PatchWordPress Core - The Hacker NewsNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A newly discovered vulnerability in WordPress Core allows unauthenticated attackers to execute arbitrary code on affected installations. The flaw, named wp2shell, impacts versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress addressed the issue in versions 6.9.5 and 7.0.2, which were released on July 17, 2026. The vulnerability can be triggered via the REST API’s batch endpoint and requires no authentication or specific configuration. While no exploitation attempts have been observed yet, administrators are strongly advised to update immediately to mitigate risk.
ResearchWordPress Core - The Hacker NewsOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
A critical memory exhaustion flaw in OpenSSL could allow attackers to freeze server resources using just 11 bytes of malicious TLS traffic. The issue, dubbed HollowByte, affects older versions of OpenSSL and was quietly patched in June without a CVE identifier or official advisory. Affected versions include all prior releases before OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21. The vulnerability allows attackers to exhaust server memory by tricking the software into allocating large buffers based on forged message lengths. This can lead to out-of-memory conditions even without hitting connection limits. OpenSSL classified the fix as a 'bug or hardening' change, meaning it did not receive a formal security rating or public tracking. However, Okta's Red Team warns that standard defenses like rate limiting will not prevent this attack due to how glibc manages memory. Users are advised to update to the latest stable versions immediately.
PatchOpenSSL - Rapid7 BlogCVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
A critical remote code execution vulnerability (CVE-2026-58644) in Microsoft SharePoint Server is being actively exploited in the wild. The flaw affects on-premises versions including SharePoint Enterprise Server 2016, SharePoint Server 2019, and Subscription Edition. Attackers can exploit it without authentication due to unsafe deserialization of untrusted data. Microsoft has issued urgent security updates, and CISA added the issue to its KEV list. Organizations are advised to apply the July 14, 2026 patches immediately and monitor for signs of exploitation using tools like Microsoft Defender and AMSI.
Reported exploitedSharePoint Server - The Hacker NewsNew NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A newly discovered Go-based botnet named NadMesh has emerged, actively scanning for misconfigured AI and DevOps services to extract sensitive credentials like AWS keys and Kubernetes tokens. The threat actor’s dashboard reportedly lists over 3,800 unique AWS keys harvested from vulnerable systems. QiAnXin's XLab identified the malware based on a string reference to 'n4d mesh controller' in its codebase. The botnet focuses on popular open-source tools such as ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio, Jenkins, Docker API, and Redis—services often deployed without proper firewall protections. It exploits weak configurations, default credentials, and unauthenticated endpoints to gain access. Once inside, it collects cloud credentials stored in environment files, Kubernetes service accounts, and Docker configuration files. Researchers note that while the botnet uses multiple vectors—including Docker remote code execution and Jenkins script console exploitation—the largest portion of its activity involves exploiting MCP (Model Context Protocol) servers using the executecommand tool. However, many of these services lack robust authentication mechanisms, making them easy targets. Organizations are urged to secure exposed services by enabling authentication, restricting public access, and applying available patches for known vulnerabilities like CVE-2026-39987 and CVE-2026-41176.
ResearchComfyUI - Rapid7 Blog
- SecurityWeekFresh SharePoint Vulnerability Exploited Soon After Disclosure
A critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-58644, has been actively exploited just days after its disclosure. The flaw, rated with a CVSS score of 9.8, allows authenticated attackers with Site Owner privileges to inject and execute arbitrary code on affected servers. Microsoft addressed the issue during its July 2026 Patch Tuesday release. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, urging immediate patching for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
Reported exploitedSharePoint Server Subscription Edition - BleepingComputerCISA urges immediate action on actively exploited Fortinet flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning for government agencies to address two actively exploited vulnerabilities in Fortinet’s FortiSandbox threat detection platform. These flaws, CVE-2026-39808 and CVE-2026-25089, enable unauthenticated attackers to execute arbitrary code remotely without user interaction. CISA added both to its catalog of known exploited vulnerabilities and requires federal agencies to apply patches by July 19. Threat intelligence firm Defused confirmed ongoing exploitation attempts, prompting immediate action from administrators.
Reported exploitedFortiSandbox