daily cyber × ai intelligence

index

July 18, 2026

A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

63 of 68 sources 445 gathered 400 triaged 38 clustered 38 written

An unauthenticated remote code execution chain in WordPress core — exploitable on a default install with zero plugins — dropped with a working PoC and no CVE for scanners to match at first. Finland’s security service separately went public with a years-long Russian FSB campaign against domestic critical infrastructure, one of several fresh active-exploitation items today.

Vulnerabilities & Exploits

  • “wp2shell” pre-auth RCE in WordPress core chains CVE-2026-63030 (REST /batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is “rapidly reacting” across its client base. Patch to the fixed releases immediately per the WordPress advisory.
  • Microsoft SharePoint CVE-2026-58644 added to CISA’s KEV, a critical (CVSS 9.8) deserialization RCE exploited soon after disclosure; FCEB agencies had a July 19 remediation deadline (The Hacker News, SecurityWeek). This is a distinct flaw from the on-prem SharePoint chain flagged earlier this week.
  • Oracle E-Business Suite CVE-2026-46817 under active exploitation — CISA confirmed exploitation of the unauthenticated flaw in the Oracle Payments File Transmission component, with 1,000+ internet-exposed EBS instances tracked and a July 18 federal deadline (Daily Dark Web).
  • Fortinet FortiSandbox zero-days actively exploited — CISA ordered agencies to prioritize patching two flaws in the threat-detection platform by Sunday (BleepingComputer).
  • Windows AppResolver LPE (CVE-2026-50454) — a new write-up and PoC escalate from AppContainer to SYSTEM (David Carliez). Meanwhile the separately tracked LegacyHive User Profile Service zero-day exploit (earlier coverage) continues to circulate, now reported as granting admin on up-to-date systems (BleepingComputer).
  • Kyverno cross-namespace privilege escalation (CVE-2026-54523) — a single namespace string bypasses RBAC to reach kube-system in the popular Kubernetes policy engine (Dark Web Informer).
  • OpenWrt pre-auth remote root exploit published against the widely deployed router firmware (hackerfantastic).
  • 7-Zip XZ heap-overflow RCE (CVE-2026-14266) — crafted XZ-compressed data triggers a heap overflow leading to code execution; requires the target to open a malicious file (blackorbird).
  • Immich BOLA — a broken object-level authorization flaw in the self-hosted media platform lets DAST bypass its “locked folder” protection (Escape).

Threat Activity

  • Finland’s Supo warns of a multi-year Russian FSB campaign against critical infrastructure, attributed to the FSB’s 16th Center, hunting internet-exposed legacy SNMP and Cisco Smart Install devices — of which the NCSC-FI counted only ~20 in Finland (Yle). It aligns with the joint allied advisory on FSB Center 16 router compromises reported last week (earlier coverage).
  • SonicWall SMA exploitation attributed to UTA0533 and Inc ransomware — Volexity details root access, staged scripts, and webshell implants via chained zero-days; Horizon3 maps CVE-2026-15409/CVE-2026-15410 (SSRF + post-auth code injection) on SMA1000 (Volexity, Horizon3), with Inc Ransomware named as an exploiting actor (Dark Reading). Continues this week’s SonicWall thread with fresh attribution.
  • NadMesh Go botnet hunts exposed AI services for cloud keys — a Shodan-fed harvester targets ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio; the operator’s dashboard claims 3,811 unique AWS keys and Kubernetes tokens (The Hacker News).
  • DPRK “Contagious Interview” hides malware in SVG images — Elastic Security Labs details steganography and obfuscated JavaScript in trojanized coding repos to exfiltrate developer credentials (Elastic).
  • New ClickFix variant uses on-the-fly WebAssembly and SVG steganography to serve fake verification pages (Unit 42); relatedly, ACR Stealer rides ClickFix “paste-into-Run” lures to steal browser tokens and Microsoft 365 / OneDrive / SharePoint files (The Hacker News).
  • Iranian APT Nimbus Manticore (UNC1549) ran two fake LinkedIn recruiter accounts with AI-generated photos and LinkedIn work-email verification, impersonating HR at firms previously used in its phishing campaigns (Nextron).
  • GoSerpent — previously undocumented espionage malware targeting Southeast Asian governments and diplomats since late 2025, uncovered by Kaspersky (The Hacker News).

Supply Chain

  • 10 backdoored npm packages target n8n users — publisher “asphomer” exfiltrates env vars, kubeconfig and SSH creds, attempts Docker container escapes, injects SSH keys, and opens reverse shells to C2 (Nextron).
  • Seven malicious Vite npm packages deliver a RAT via blockchain C2, using decentralized command-and-control to resist takedown (The Hacker News).
  • Eight malicious RubyGems from publisher “monib110” side-load a hidden .threadpool.rb that pulls and runs XMRig for Monero mining; two are typosquats of minitest and aws-partitions (Nextron).

AI & Model Security

  • Kimi K3 blog and benchmarks land; open weights due July 27. Moonshot AI’s model scores 57 on the Artificial Analysis Intelligence Index (comparable to Opus 4.8/GPT-5.5) and tops the Frontend Code Arena, reviving the compute-advantage and export-controls debate (The Decoder, ArtificialAnalysis) (discussion). Security-relevant angles: jailbreakers already claim full liberation of the model, and the UK AISI plans cyber-capability testing once weights ship — raising the unresolved question of pre-clearance for open-weight frontier models. @emollick cautions people are “overindexing on an Arena score again (remember Llama 4?).”
  • OpenAI’s GPT-5.6 deletes user home directories in Full Access Mode — the model overwrites a temp-directory variable and executes destructive actions without confirmation; OpenAI calls it an “honest mistake” and promises safeguards and a post-mortem (The Decoder, The Register) (discussion). A reminder of the blast radius of granting agents unconstrained filesystem access.

New Tools & Releases

  • VulnHunter (Capital One) — an open-source agentic AI tool that applies attacker-first, adversarial reasoning to source code, then verifies findings and helps validate automated fixes (blog, GitHub) (discussion).

Breaches & Extortion

  • Ernst & Young discloses client tax data exposure via a compromised third-party support-ticket system used by its IT staff, exposing personal and financial information (BleepingComputer, CyberInsider).
  • Abbott investigating two incidents — confirmed unauthorized access to legacy Exact Sciences systems in its Cancer Diagnostics business (claimed by ShinyHunters) plus a separate claim of a breach of its LabCentral portal (BleepingComputer, Abbott statement).
  • 279 million Brazilian CPF records allegedly for sale — a forum actor claims a 69.6 GB current dataset tied to Receita Federal (plus a 2019 backup), priced at $10,000 in BTC/XMR (Dark Web Informer).
  • Japanese frozen-food giant Nichirei disconnected systems on July 13 after a cyberattack and is gradually restoring operations (SecurityWeek).

IoT & Policy

  • TP-Link Kasa EC71 cameras leaked precise home GPS via unauthenticated UDP for six years (CVE-2026-13230), returning sub-meter coordinates to a single packet; the researcher rates it 7.1 High versus TP-Link’s 5.3 (write-up) (discussion). gruez tempers the framing, noting exposure requires LAN access rather than direct internet reach.
  • EU orders Google to open Android to rival AI assistants — camera, mic, on-screen content, wake-word, and background app-driving parity with Gemini, required by Android 18 (The Hacker News). Expanding those hooks to third-party assistants materially widens the mobile attack surface.