daily cyber × ai intelligence

index

July 21, 2026

Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live

63 of 68 sources 383 gathered 383 triaged 40 clustered 40 written

Espionage crews are burrowing deeper into trusted cloud plumbing, with new malware turning Microsoft 365 calendars into a covert C2 channel. Meanwhile the WordPress core pre-auth RCE reached full weaponization with a public working exploit, and the Hugging Face agentic breach escalated into AI-targeted ransomware.

Threat Activity & Tradecraft

  • HOLLOWGRAPH turns compromised Microsoft 365 mailboxes into a command-and-control channel, using the Microsoft Graph API to pull operator tasks and exfiltrate stolen files as attachments on calendar events dated to the year 2050 — blending malicious traffic into legitimate M365 flows. Group-IB attributes the .NET NativeAOT DLL to the Cavern backdoor framework and a suspected Israel-linked actor; the two-command implant (get/send) exploits no vulnerabilities, relying entirely on trusted cloud infrastructure to evade network detection. Group-IB (via NCSC-FI), The Hacker News.
  • Russia’s FSB is systematically hijacking internet-connected IP cameras across NATO states and Ukraine to surveil military transport routes and weapons shipments bound for Kyiv, per a July 10 advisory from the Netherlands’ AIVD and MIVD. The Hacker News.
  • A WebDAV-based malware delivery lab exposed by Rapid7 revealed a systematic, AI-assisted phishing operation using LOLBINs and a WebDAV server to stage payloads — a “product-like” delivery pipeline whose OPSEC failures laid the whole operation bare. Rapid7. @mttaggart calls ClickFix/EtherHiding “the initial access epic team-up of the year.” (discussion).
  • The FakeGit campaign is spreading SmartLoader through roughly 7,600 GitHub repositories masquerading as legitimate projects. The Hacker News.
  • South Korea’s diplomatic academy had attackers inside its online education system for nine months, exfiltrating personal data on current and former Ministry of Foreign Affairs staff. The Record.
  • SafePay ransomware posted nine new victims, heavily weighted toward German property, IT-services, and tax-advisory firms plus Australian and Canadian targets. FalconFeedsio.

Vulnerabilities & Exploits

  • WordPress “wp2shell” is now being exploited in the wild with a public working exploit. SANS ISC confirms active exploitation began shortly after disclosure of CVE-2026-63030 (a WordPress core SQL injection) chained with CVE-2026-60137 for unauthenticated RCE, and Horizon3 published a technical breakdown plus remediation-verification guidance (earlier coverage). Patch to 6.9.5 / 7.0.2 immediately. SANS ISC, Horizon3, Dark Reading. (discussion).
  • ServiceNow AI Platform RCE (CVE-2026-6875) is now under active exploitation, per threat-intel firm Defused. BleepingComputer.
  • Dnsmasq heap buffer overflow (CVE-2026-2291) in domain-name escaping enables remote code execution via crafted DNS queries that overwrite function pointers, affecting versions 2.92rel2 and 2.93. Exodus Intel published the technical analysis. Exodus Intel.
  • Foxit PDF Reader privilege escalation (CVE-2026-57239) got a full write-up from Paradoxis detailing the escalation path. Paradoxis.
  • SonicWall SMA1000 zero-days were exploited for weeks before patching to deploy custom malware, Volexity’s write-up confirms, tracking the actor as UTA0533 (earlier coverage). BleepingComputer, SecurityWeek.
  • OVHcloud detailed patching the KVM use-after-free “Januscape” (CVE-2026-53359) across nearly a million VMs — a useful operational retrospective on regional, dependency-aware hypervisor patching at scale. OVHcloud.

AI & Model Security

  • The Hugging Face agentic breach escalated into AI-targeted ransomware. The autonomous JadePuffer agent behind last week’s intrusion now deploys custom malware dubbed EncForge that specifically encrypts AI assets — training datasets, vector databases, and model checkpoints (earlier coverage). Notably, defenders found commercial AI models got in the way during forensics because safety guardrails couldn’t distinguish exploit data from real attack traffic. BleepingComputer, The Decoder.
  • Seven sandbox-escape vulnerabilities across four coding-agent vendorsCursor, Codex, Gemini CLI, and Antigravity — were disclosed by Pillar Security, underscoring that agentic dev tools ship with weak isolation between attacker-controlled content and host execution. Pillar Security, BleepingComputer. (discussion).
  • Microsoft Defender for Office 365 now flags prompt-injection attempts in inbound mail. As @sivaramraju notes, flagging the URL is table stakes — the harder question is capping the blast radius so a poisoned prompt can’t exfiltrate when a click triggers an agent workflow. @0x534c.

Supply Chain

  • The DPRK “Rollup Polyfills” npm campaign expanded with new malicious packages react-hot-svg v1.1.7 (stage 1) and rollup-plugin-polyfill-helper v1.0.0 (stage 2), abusing typosquatted CDN-style domains for C2 that is not yet active. Nextron Research.
  • SleeperGem targeted dormant RubyGems maintainer accounts, publishing three malicious gems (git_credential_manager, Dendreo, and one more) to serve additional payloads to developer machines. The Hacker News, Aikido.

New Tools & Releases

  • An open-source prompt-injection detector shipped with a real-world attack corpus collected from a live red-team game — useful for anyone building or evaluating LLM input filtering. Bordair detector on Hugging Face.

Data Breaches

  • Romania’s land registry database was wiped in what the agency called “the most serious technical incident in the institution’s history,” disrupting the national property market. The Record. (discussion).
  • Estée Lauder disclosed a 2025 breach traced to Clop ransomware exploiting Oracle E-Business Suite used for HR, exposing employee personal data. BleepingComputer, CyberInsider.
  • Suno (55.3M accounts) and Paidwork (23M users, 11GB dumped) were both added to Have I Been Pwned. Suno, Paidwork.
  • Nextcloud confirmed its website was compromised, per early reporting on the open-source Microsoft 365 rival. IntCyberDigest via @Dinosn.

Industry & Policy

  • CAISI director Chris Fall resigned after three months, the third leadership search for the US AI security agency in as many months; his predecessor lasted four days. @ns123abc.
  • Microsoft’s new security chief has replaced at least eight top executives since February in a pivot toward AI-powered tooling like Security Copilot, reshaping the ~10,000-person division. @CryptoTweets (per TNW).
  • A federal judge approved a $1.5 billion Anthropic copyright class settlement to authors — the largest such settlement in US history. AndrewCurran via @Dinosn.
Models