Info
2026-07-21 06:45Z · last 24h · 10 findings
· glm-5.2:cloud
Threat Brief — 2026-07-21 — WordPress WP2Shell exploitation surges
Active exploitation of WordPress core RCE flaws has crossed into mass-attack territory just three days after disclosure, with attackers chaining CVE-2026-60137KEV and CVE-2026-63030KEV against millions of sites. SonicWall SMA1000 zero-days now confirmed to have delivered custom malware during weeks of pre-disclosure exploitation. Estée Lauder disclosed a customer data breach stemming from an Oracle E-Business Suite flaw used for HR operations.
Top items
- WP2Shell exploitation now at Internet scale — Attackers are widely chaining CVE-2026-60137KEV and CVE-2026-63030KEV to attempt remote takeover against one of the largest attack surfaces online, only three days after initial disclosure. This is a genuine escalation from the July 18 reporting of public exploit release; mass exploitation attempts are now confirmed in the wild. Patch any unpatched WordPress instances immediately. (src: Dark Reading) — Developing: first reported 2026-07-18 by BleepingComputer.
- SonicWall SMA1000 zero-days delivered custom malware — Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited as zero-days for weeks before disclosure, with threat actors installing purpose-built malware on vulnerable VPN appliances. This confirms the earlier reporting of weeks-long pre-disclosure compromise and adds the detail of custom malware payloads. (src: BleepingComputer) — Developing: first reported 2026-07-19 by The Hacker News.
- Estée Lauder data breach via Oracle E-Business Suite — Cosmetics giant Estée Lauder is notifying customers of a data breach after attackers exploited a flaw in Oracle E-Business Suite used for the company's HR operations. No CVE or specific flaw identifier has been published yet; the attack vector suggests a known or unpatched E-Business Suite vulnerability. Organisations running Oracle E-Business Suite for HR or customer-facing systems should audit patch levels. (src: BleepingComputer)
- Ostium crypto theft figure revised to $23.7M — The Ostium trading platform confirmed an attacker stole $23.75 million from its liquidity provider vault after compromising off-chain price-feed infrastructure. This revises the earlier-reported $18M figure upward and adds detail that the compromise targeted off-chain infrastructure feeding prices into the protocol. (src: BleepingComputer) — Developing: first reported 2026-07-20 by SecurityLab.
- Six .NET CVEs receive informational-only updates — Microsoft pushed product-table updates (no technical change) for CVE-2026-50648, CVE-2026-50649, CVE-2026-50646, CVE-2026-50525, CVE-2026-50527, and CVE-2026-47304 covering .NET Framework DoS, RCE, and security-bypass vulnerabilities. No new severity ratings or exploitation details. (src: MSRC)
Themes
- Off-chain and edge-infrastructure compromise — Both the Ostium theft and the Estée Lauder breach illustrate attackers targeting supporting infrastructure (price feeds, HR applications) rather than the core system, exploiting trust boundaries between tiers.
- Disclosure-to-mass-exploitation window collapsing — WP2Shell moved from public exploit release to Internet-scale attack attempts in three days, reinforcing the need for same-day patching of core CMS vulnerabilities.
