Threat Brief — 2026-07-21 — Double SharePoint Zero-Day Pressure
Two distinct critical SharePoint deserialization RCEs are now under active exploitation, with attackers on CVE-2026-50522KEV stealing machine keys to survive remediation. Anubis ransomware has formally claimed the Coca-Cola Fairlife breach and is threatening data publication. A new Progress ShareFile 0-day and an Apple Hide My Email privacy leak round out the day's most actionable items, while a Russian-speaking actor has productized AI jailbreaks into an offensive toolkit.
Top Items
- CVE-2026-58644KEV — Second distinct SharePoint Server deserialization RCE (Zero-Day, KEV'd): A CVSS 9.8 critical deserialization-of-untrusted-data flaw in Office SharePoint Server (Subscription Edition, 2019, 2016) was exploited as a zero-day before July 14 Patch Tuesday and is now on CISA's KEV catalog. Requires authenticated Site Member context but enables full RCE. This is separate from CVE-2026-50522KEV and compounds the SharePoint attack surface. (src: CISA)
- SharePoint CVE-2026-50522KEV attackers stealing machine keys for post-patch persistence: Continues the ongoing story first reported 2026-07-21 by RSS:thehackernews. New development: BleepingComputer reports threat actors are exfiltrating machine keys from compromised servers, allowing them to maintain access even after the CVE is patched — significantly raising the cost of remediation. (src: BleepingComputer)
- Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak: Continues the ongoing story first reported 2026-07-20 by RSS:xakep. New development: The Anubis ransomware gang has publicly claimed responsibility for the Fairlife dairy subsidiary breach and is threatening to publish stolen corporate data unless a ransom is paid, shifting the incident from suspected extortion to confirmed double-extortion. (src: BleepingComputer)
- Progress ShareFile Storage Zone Controller 0-day disclosed: Progress Software has revealed that a zero-day vulnerability in ShareFile Storage Zone Controller forced emergency server shutdowns. The flaw allows administrators to read and write arbitrary files on the controller, presenting a path to potential RCE or data exfiltration in self-hosted ShareFile deployments. (src: Xakep)
- Apple patches Hide My Email bug that exposed real addresses in mail logs: A flaw in Apple's Hide My Email relay service caused real user email addresses to appear in mail logs, defeating the feature's core privacy guarantee. Apple has shipped a fix; organizations relying on Hide My Email for alias-based workflows should audit mail-log retention and access controls. (src: The Hacker News)
- Russian-speaking actor "Trim" productizes AI jailbreaks into offensive attack platform: A threat actor has systematically dismantled publicly available frontier AI models and integrated them with offensive security tooling, creating a turnkey attack platform from jailbroken LLMs. This represents a maturation from proof-of-concept jailbreak research to operationalized offensive capability. (src: Dark Reading)
Themes
Enterprise collaboration platforms under sustained siege: SharePoint (two distinct critical deserialization RCEs), WordPress (ongoing wp2shell exploitation), and now ShareFile all share the pattern of unauthenticated or low-privilege paths to RCE in widely deployed collaboration infrastructure — a high-value target set for both initial access brokers and ransomware affiliates.
AI offensive tooling crossing from research to operations: The "Trim" platform demonstrates jailbroken frontier models being packaged into deployable attack tooling, echoing the recent Gemini CLI botnet and AI-assisted phishing toolkit leaks — a consistent trend of AI capabilities being absorbed into active threat-actor workflows.
