This 24-hour period (2026-07-18 to 2026-07-19) saw significant vulnerability disclosures across multiple enterprise platforms and a substantial surge in ransomware activity targeting diverse sectors. Critical remote code execution vulnerabilities were disclosed in VMware Avi Load Balancer (CVE-2026-47865, CVE-2026-47867) and Fastify HTTP Proxy (CVE-2026-16117), with CVSS scores ranging from 8.7 to 9.8. Multiple authentication bypass and privilege escalation flaws in VMware Avi Load Balancer pose serious risks to organizations using this load balancing solution.
The malware landscape shows continued activity from established botnets including Mozi and Mirai, with 49 malicious URLs identified by abuse.ch. Microsoft issued warnings about a surge in ACR Stealer attacks targeting enterprise customers for credential theft. The ransomware ecosystem remains highly active with 21 new victim organizations posted across multiple leak sites, led by the Qilin group (11 victims) and IncRansom (9 victims). Sectors impacted include education, healthcare, logistics, manufacturing, and critical infrastructure.
Immediate action is required for organizations using 7-Zip (update to 26.02), WordPress Core (wp2shell RCE patches), VMware Avi Load Balancer, and Fastify components. The 23andMe settlement ($18M) for failing to protect genetic data highlights ongoing regulatory and legal consequences for inadequate data protection practices.
Multiple critical and high-severity vulnerabilities disclosed affecting widely-deployed enterprise systems including VMware Avi Load Balancer, Fastify components, 7-Zip, and WordPress Core.
Critical authentication bypass vulnerability allowing network-based attackers to access Avi Control Plane without proper credentials. Affects versions 31.1.1 through 31.2.2 and 30.1.1 through 30.2.6. Fixed in 31.2.2-2p3 and 30.2.7.
Critical vulnerability in @fastify/http-proxy (up to 11.5.0) allows URL-encoded prefix bypass, potentially enabling unauthorized access to backend services. CVSS 10.0. Affects request rewriting when prefix segments are URL-encoded.
Critical remote code execution vulnerabilities in WordPress Core now have publicly available exploits. Immediate patching imperative for all WordPress administrators to prevent compromise.
Multiple RCE vulnerabilities in VMware Avi Load Balancer allow authenticated attackers with network access to execute arbitrary code. CVE-2026-47867 and CVE-2026-47869 both rated CVSS 8.7. Affects versions 32.1.1, 31.1.1-31.2.2, 30.1.1-30.2.6, and 22.1.1-22.1.9.
7-Zip version 26.02 released to address remote code execution vulnerability allowing attackers to execute malicious code when users open specially crafted compressed files. Public exploits available, immediate patching recommended.
Directory traversal vulnerability in VMware Avi Load Balancer allows authenticated network users to perform path traversal attacks. CVSS 8.8. Affects versions 32.1.1, 31.1.1-31.2.2, 30.1.1-30.2.6, and 22.1.1-22.1.9.
Multiple vulnerabilities in SurrealDB including authentication bypass (CVE-2024-58362 CVSS 8.8), format string vulnerability (CVE-2024-58366 CVSS 8.5), and DoS via malformed headers (CVE-2024-58368). Affects versions before 1.1.0-1.5.5 and 2.0.0-beta series.
Heap-based buffer overflow in ProFTPD mod_sftp reachable by authenticated SFTP users. Improper validation of attacker-supplied packet length values allows memory corruption. CVSS 7.5.
Heap-based buffer overflow in OpenPLC_v3 webserver modbus_master.cpp getData() function. No bounds checking on caller-supplied buffer allows memory corruption. CVSS 8.8.
Server-side request forgery vulnerabilities identified in rt-claw (CVE-2026-16125, CVE-2026-16127, CVE-2026-16128) and Sipeed PicoClaw (CVE-2026-16084), allowing remote attackers to perform unauthorized requests. CVSS 7.3.
Microsoft warns of significant increase in ACR Stealer targeting enterprise customers while Mozi, Mirai, and ClearFake malware families maintain active distribution campaigns.
Microsoft observes surge in ACR Stealer malware attacks against enterprise customers, stealing browser-stored passwords, authentication tokens, and sensitive documents. Targets credential stores and session tokens for lateral movement and persistent access.
Distribution of Stealc and Vidar information-stealing malware observed via 62.60.226.198. Both families specialize in credential theft, browser data extraction, and cryptocurrency wallet targeting.
Malicious ScreenConnect MSI installer distributed via rtsinternationals.screenconnect.com. Abuse of legitimate RMM tool for unauthorized remote access and potential post-exploitation activity.
Multiple malicious URLs identified distributing Mozi and Mirai botnet variants targeting MIPS and ARM-based IoT devices. 49 total malware distribution URLs detected including ELF binaries for various architectures.
ClearFake malware distributed through compromised domains (nfghq.kmmits.com, kqgn.fg777jbg.net) delivering Windows executables. Social engineering campaign likely targeting users with fake update prompts.
17 malicious URLs on 91.92.242.236 distributing payloads dropped by Amadey botnet loader. Infrastructure hosting multiple executable files suggesting active C2 operations and payload distribution campaign.
21 organizations posted to ransomware leak sites across multiple threat actor groups, with Qilin and IncRansom leading activity. 23andMe settles for $18M over genetic data protection failures.
Qilin ransomware group posted 11 organizations including The Nueva School (education), St Martha Catholic Church (religious), Heartland Catfish (food industry), Salina Supply (industrial), healthcare providers, and international targets. Diverse sector targeting indicates broad opportunistic campaign.
IncRansom group disclosed breaches of manufacturing (D.MAG/Taiwan Giant, V-Silicon semiconductor), logistics (FAST.COM.PH Philippines), food production (Vedan Corp, Pokka), energy (Reatile Group South Africa), and agriculture (V&P Nurseries). Targets span Asia-Pacific and Africa with focus on supply chain entities.
DragonForce ransomware group posted NewNet S.A., Colombian company specializing in IT risk management, information security, and cybersecurity services. Breach of security provider represents high-value target with potential exposure of client data and security configurations.
Krybit posted Euroins Insurance (Bulgaria) and ThreeAM posted tws-tac.net (65+ year manufacturing/industrial company). Insurance sector breach poses risk of policyholder PII exposure.
Nova ransomware group posted FMZ Tecnologia em Sistemas, Brazilian software company developing HORUS ERP system for book publishing industry. Breach of ERP provider risks exposure of multiple client organizations' data.
New York Attorney General secures $18 million settlement from 23andMe for failing to adequately protect customers' genetic and personal data. Bipartisan coalition of 43 attorneys general involved. California AG has also filed separate lawsuit under state privacy laws.
Multiple code injection and insecure authentication vulnerabilities demonstrate common attack patterns including SQL injection, SSRF, and buffer overflow exploitation.
SQL injection flaws identified in SourceCodester Class and Exam Timetabling System (CVE-2026-16154, CVE-2026-16152) and Shibby Tomato firmware. Remote exploitation possible through manipulated ID parameters. CVSS 7.3.
uproot library dynamically generates and executes Python code from ROOT TStreamerInfo records without proper sanitization. File-controlled metadata interpolated into source code enables arbitrary code execution. CVSS 7.8.
urwid web display backend generates session identifiers using cryptographically weak Mersenne Twister PRNG. Predictable session tokens enable session hijacking attacks. CVSS 8.1.
Authentication bypass in QueryWeaver allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting signup requests with victim email addresses. CVSS 8.2.
Emerging privacy-preserving technologies for age verification and ongoing regulatory enforcement actions highlight evolving compliance landscape.
As age verification laws expand globally, organizations explore privacy-preserving technologies. Incode's on-device age estimation performs verification without transmitting or storing facial images, addressing biometric privacy concerns while meeting regulatory requirements.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.