daily cyber × ai intelligence

index

July 19, 2026

WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation

63 of 68 sources 375 gathered 375 triaged 45 clustered 45 written

The pre-auth WordPress RCE disclosed last week now has working public exploits and is being treated as actively exploited — patch and assume compromise. A jailbroken Kimi K3 spitting out injection code and a fresh crop of APT tradecraft round out a busy day.

Vulnerabilities & Exploits

  • WordPress “wp2shell” (CVE-2026-63030) is now weaponized. Multiple researchers — including Assetnote’s hash_kitten and teams at calif.io and FullHunt — have reproduced the unauthenticated REST API batch-route confusion chain that yields RCE against default installs, and public PoCs are circulating. Advice has shifted from “patch” to “patch and consider vulnerable systems compromised.” Fixed in WordPress 6.8.6, 6.9.5 and 7.0.2 (BleepingComputer, FullHunt analysis + scanner, NCSC-NL) (earlier coverage) (discussion).
  • Siemens ROX II OT switches hit by a three-bug zero-day chain. Unit 42 detailed a trilogy of flaws that chain from initial access to privilege escalation and persistent root on the industrial switches; Siemens is pushing firmware updates and mitigations (Unit 42).
  • Two Windows kernel write-ups drop with technical detail. A deep dive covers CVE-2026-58532, an unsigned 64-bit integer overflow during deserialization in tcpip.sys patched in July (write-up); separately, a PoC and write-up for CVE-2026-50416 exploits a win32k desktop-heap info leak to disclose stable kernel pointers and bypass KASLR from an unprivileged process (PoC/write-up).
  • Local privilege escalation in the Windows Cloud Files Mini Filter Driver. Cisco Talos disclosed CVE-2026-58613, a use-after-free reachable via crafted API calls that grants LPE, patched in July (Talos).
  • Android lock-screen bug lets Gemini send SMS without a PIN. A physical attacker can invoke Google Gemini from the Android 16 lock screen to send messages, bypassing the device PIN; a fix is rolling out this week (The Register).

New Tools & Releases

  • WallBreaker v2 ships a substantial update to the open-source LLM red-teaming CLI, claiming ~30% higher attack success across models and 20% lower token cost. New capabilities include a “swarm mode” multi-model attacker that adapts framing to the target’s measured defenses, a persona_forge that evolves a system-prompt “genome” module by module, and a vault that curates successful breaks per model (@VittoStack).

AI & Model Security

  • Kimi K3 jailbroken within hours of release. Researchers including Elder Plinius report a single persona/reframing jailbreak coaxes the new Chinese frontier open-weight model into producing DLL-injection code, a full ARP-spoofing/MITM framework, disinformation-botnet designs and CBRN detail — with guardrails described as “basically optional.” Weights are due July 27; note skeptics flag a ~51% hallucination rate versus 39% for the prior series (@0x0SojalSec, @elder_plinius).
  • Hugging Face publishes a post-intrusion transparency report. The AI platform disclosed details of a recent security incident, earning praise from responders for the openness of the writeup (via @Kostastsale).
  • Claude Code adds an EndConversation tool. Version 2.1.214 lets the agent terminate sessions with abusive users or jailbreak attempts and halt further interaction, alongside new permission prompts for Docker/Podman daemon-redirect flags (Claude Code changelog).

Threat Activity

  • Scattered Spider duo sentenced to 5.5 years each. Thalha Jubair, 20, and Owen Flowers, 18, were sentenced at Woolwich Crown Court over the 2024 Transport for London attack, which left 148 TfL systems inoperable, forced in-person password resets for 27,000 staff and caused ~£29 million in damages — the UK’s largest cybercrime prosecution (The Hacker News, Intel 471).
  • APT41’s “Calendarwalk” uses Google Calendar events as its C2 channel, reading operator commands from calendar entries to blend in with legitimate cloud traffic (via @0xpwnie).
  • Unit 42 flags an Equation Group-style implant in the wild, initially resembling a known NSA TAO sample by reusing an exported function name — worth watching as analysis develops (via @0xpwnie).
  • GoldenEyeDog subgroup linked to the DigiCert breach and code-signing certificate theft, tying stolen signing material back to an APT cluster (The Hacker News).
  • TAG-150 tradecraft continues to evolve across the DinDoor, DenoRAT and NightshadeC2 families in a new technical breakdown (via @YungBinary).
  • HelloNet campaign abuses the ViPNet update system for DLL sideloadingitcsrvup64.exe side-loading a malicious wtsapi32.dll to establish an SSH tunnel (@blackorbird).
  • Microsoft warns of a surge in ACR Stealer attacks against customer systems (BleepingComputer); Blind Eagle’s toolkit also continues its steady evolution per SpiderLabs (LevelBlue).
  • Ransomware roundup: Qilin claimed eight new victims including a Bay Area private school and a Mississippi catfish processor (DarkWebInformer); The Gentlemen listed Colombian oil-and-gas firm Ecopetrol and the U.S. Navy’s Military Sealift Command (FalconFeeds); LockBit 5.0 added six victims across India, Singapore, Argentina and the UK (FalconFeeds).

Cloud, Identity & Supply Chain

  • 251 Vercel personal access tokens allegedly leaked on an underground forum, with sample vcp_-prefixed tokens and a download link posted; if valid and live they’d grant access to deployments, serverless functions and project configuration (DailyDarkWeb).
  • npm supply-chain attackers exploited a gap in the CI/CD pipeline itself, with Unit 42 also observing an attacker leveraging GitHub Copilot to trigger infection (Unit 42).

Privacy & Surveillance

  • Flock Safety breach fallout widens. Cleveland City Council disclosed unauthorized access to data through Flock’s ALPR software, feeding a growing backlash — including reporting that the license-plate-reader platform leaked police officers’ own plate searches — as agencies pause or cancel contracts (Malwarebytes, pwnhackers AMA).