Crit  2026-07-19 06:01Z · last 24h · 30 findings · glm-5.2:cloud

Threat Brief — 2026-07-19 — Patch Windows, WordPress, and 7-Zip Now

Executive summary: Three critical RCE vulnerabilities demand immediate patching — 7-Zip, WordPress Core, and the already-KEV'd SharePoint zero-day continues to be exploited. Meanwhile, Microsoft warns of a surge in ACR Stealer attacks against enterprise customers, and two APT campaigns (ToddyCat and Armored Likho) are actively compromising corporate email and stealing data using novel toolsets. Device Code Phishing via Microsoft OAuth is gaining traction as a credential-theft vector that bypasses traditional URL-checking controls.

Top items

Themes

OAuth and token abuse across the board — ToddyCat's Umbrij tool, Microsoft Device Code Phishing, and ACR Stealer all target OAuth tokens and browser-stored credentials rather than passwords. The shift from credential theft to token hijacking means traditional MFA alone is insufficient; conditional access and token lifecycle controls are essential.

AI weaponisation maturing — Armored Likho's AI-generated loaders, OpenClaw's exploitable agent architecture, and the demonstrated $100 AI-model poisoning experiment all point to adversarial AI moving from theory to operational deployment.

ICS supply-chain exposure — Schneider Electric's FlexNet vulnerability and the ViPNet HelloNet campaign both demonstrate that trust relationships in industrial software supply chains remain a persistent gap.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb