Info
2026-07-18 06:03Z · last 24h · 47 findings
· glm-5.2:cloud
Threat Brief — 2026-07-18 — WordPress RCE, OpenSSL DoS, KEV Surge
Executive summary: A critical unauthenticated RCE in WordPress core headlined the day, with active exploitation confirmed for patched SharePoint and Fortinet flaws added to CISA's KEV catalog. A novel OpenSSL "HollowByte" flaw enables trivial DoS via an 11-byte TLS request, and multiple zero-days—Windows LegacyHive, Siemens ROX II, SonicWall SMA—are publicly detailed. Supply-chain attacks and credential-harvesting botnets targeting AI services round out a busy 24 hours.
Top Items
- WordPress core unauthenticated RCE ("wp2shell") — Critical flaw in WordPress core allowing code execution via a single anonymous HTTP request; affects bare installs with no plugins. Versions 6.9 and 7.0 were vulnerable; patches shipped as 6.9.5 and 7.0.2. Source
- CISA KEV: SharePoint RCE CVE-2026-58644KEV — Actively exploited zero-day in Microsoft SharePoint Server added to KEV catalog; federal agencies must remediate immediately. Source
- CISA KEV: Fortinet FortiSandbox flaws — Two actively exploited vulnerabilities in FortiSandbox; CISA ordered urgent patching by Sunday. Source
- OpenSSL "HollowByte" DoS (CVE pending) — Unauthenticated 11-byte TLS request causes unpatched OpenSSL servers to allocate up to 131 KB per request that is never released until process restart. Fix shipped in July. Source
- Windows LegacyHive zero-day (public PoC) — Privilege escalation exploit released by "Nightmare Eclipse" affecting up-to-date Windows systems; grants admin privileges. Source
- SonicWall SMA zero-days exploited by Inc Ransomware — Two chained vulnerabilities give root-level access on SonicWall mobile access appliances; actively exploited by Inc Ransomware. Source
- Siemens ROX II OT zero-day trilogy — Three chained zero-days in Siemens ROX II switches allow privilege escalation and persistent root access in OT environments. Source
- NadMesh botnet targeting exposed AI services — Go-based botnet scanning for exposed ComfyUI, Ollama, n8n, Open WebUI, Langflow instances; claims 3,811 harvested AWS keys, hunting for Kubernetes tokens. Source
- Seven malicious Vite npm packages ("ViteVenom") — Supply-chain attack using blockchain-based C2 to deliver a RAT through the Vite frontend tooling ecosystem. Source
- Chromium batch: CVE-2026-15899 through CVE-2026-15905 — Seven Chromium vulnerabilities (use-after-free in CameraCapture, GPU, Network, Cast, Ozone, Aura; OOB read/write in V8) inherited by Microsoft Edge. Source
- DigiCert breach attributed to GoldenEyeDog subgroup "CylindricalCanine" — April 2026 incident linked to threat cluster tied to GoldenEyeDog, involving code-signing certificate theft. Source
- North Korean Contagious Interview: SVG steganography delivering OtterCookie-aligned malware — Fake coding challenges using malicious payloads hidden in SVG flag images. Source
- GoSerpent espionage malware — Previously undocumented malware targeting Southeast Asian governments and diplomats since late 2025 for long-term intelligence gathering. Source
- ACR Stealer infostealer using ClickFix lures — Exfiltrates browser passwords, session tokens, Microsoft 365 docs, OneDrive/SharePoint files via ClickFix social engineering. Source
Themes
- DoS vulnerability cluster in fundamental libraries: OpenSSL HollowByte and a wave of libsoup CVEs (CVE-2026-15709, -15711, -15712, -15713, -15714) plus pyasn1 DoS flaws (CVE-2026-59884, -59885, -59886) and a libsolv buffer overflow (CVE-2026-48863) all share a pattern of low-effort, high-impact resource exhaustion or memory corruption in widely deployed open-source parsing and networking libraries.
- Zero-day disclosure and exploit-release week: Windows LegacyHive, Siemens ROX II trilogy, SonicWall SMA, and WordPress wp2shell represent four independent zero-day classes with public details or PoCs—spanning enterprise, OT, and web platforms simultaneously.
- AI service exposure as new attack surface: NadMesh botnet, EU-mandated Android AI-assistant access expansion, and Google's "agentic defense" launch all signal that exposed AI inference endpoints and agent infrastructure are rapidly becoming a primary targeting vector alongside traditional IT.
