The 48-hour period from July 21-22, 2026 revealed a highly active threat landscape dominated by widespread exploitation of critical vulnerabilities and sustained ransomware operations. Most concerning are active exploits of CVE-2026-50522 (SharePoint RCE) being used to steal machine keys for persistence, and the wp2shell vulnerability chain (CVE-2026-63030/CVE-2026-60137) enabling remote code execution on WordPress sites. The Qilin ransomware group has escalated attacks by exploiting a critical Palo Alto GlobalProtect VPN flaw, while 19 organizations across healthcare, financial services, manufacturing, and education sectors were publicly listed by various ransomware groups. Infrastructure disruption efforts showed limited success with the takedown of the Kratos phishing-as-a-service platform, though large-scale malware distribution continues via the FakeGit campaign leveraging 7,600 compromised GitHub repositories. Notable data breach disclosures include South Korea's entire diplomatic corps (10,000 records), Seoul's bike-sharing service (4.62 million users), and a delayed notification from Suno affecting millions from a November 2025 breach—highlighting persistent notification failures.
Multiple critical vulnerabilities are being actively exploited in the wild, including SharePoint RCE, WordPress core flaws, and VPN authentication bypasses
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain persistent access even after patching. This represents a severe threat to SharePoint deployments as attackers can maintain control post-remediation.
Hackers are exploiting the critical wp2shell vulnerability suite affecting WordPress Core to deploy persistent webshells and install malicious plugins. This chain allows unauthenticated attackers to achieve remote code execution on default WordPress installations through SQL injection and interpretation conflicts.
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks. This represents a significant escalation in ransomware tactics targeting VPN infrastructure.
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. Now added to CISA KEV catalog.
DD-WRT contains a stack-based buffer overflow vulnerability in UPnP that allows unauthenticated attackers to trigger code execution. Legacy vulnerability now actively exploited.
Large-scale malware campaigns continue with FakeGit operation, SmartLoader distribution, and Mozi botnet activity alongside macOS-targeting infostealers
A massive operation dubbed 'FakeGit' is distributing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that have accumulated over 14 million downloads. This represents significant abuse of trusted software development infrastructure.
A new macOS infostealer tricks victims into revealing their system password by locking the Mac and installs a persistent backdoor for future access. Represents evolving threats to macOS enterprise environments.
Kali365 phishing kit is targeting US organizations with device code phishing attacks that abuse legitimate Microsoft authentication. Instead of fake forms, victims are directed to real Microsoft pages where they authorize malicious access.
Kimsuky APT group infrastructure identified hosting malware at curl-shell-teal.vercel.app, leveraging legitimate Vercel hosting for malware delivery targeting Windows systems.
Multiple Mozi botnet C2 servers and malware distribution URLs detected across Asian IP ranges, distributing 32-bit MIPS/ARM ELF payloads. Over 20 active malware distribution endpoints identified in 24-hour period.
Nineteen organizations publicly listed by ransomware groups including Qilin, Akira, Play, and emerging groups. Healthcare, manufacturing, financial services, and education sectors heavily targeted.
German and U.S. authorities dismantled the central infrastructure of Kratos, a phishing-as-a-service platform with global reach. The developer was arrested in Indonesia. This represents a significant disruption to commoditized phishing infrastructure.
The Anubis ransomware gang has claimed responsibility for a cyberattack on Coca-Cola's Fairlife dairy subsidiary, threatening to publish stolen corporate data unless ransom is paid.
RansomHouse ransomware gang targeted Nichirei Corporation, a premier Japanese frozen food and logistics company. This attack impacts a major supply chain player in the food industry.
RehaVital Gesundheitsservice GmbH (Germany) and Pertinent Healthcare Business Solutions (India) both publicly listed by ransomware groups, indicating continued targeting of healthcare sector infrastructure.
BiesSse Group (adhesive tape manufacturer), Argonaut Manufacturing Services (295GB stolen), Downies Collectables, and Kyowa Singapore all targeted. Manufacturing sector under sustained ransomware pressure.
Major breach notifications include South Korea's entire diplomatic corps, millions of Seoul residents, and delayed disclosures from 2025 incidents. Spain fines 23andMe for cybersecurity failures.
Personal information of nearly all South Korean diplomatic personnel compromised in an 'unprecedented' cyberattack. Up to 10,000 administrative and intelligence records exposed, affecting the entire diplomatic corps.
Seoul Metropolitan Government notifying 4.62 million citizens affected by data breach of Ttareungyi public bike-sharing service membership information. Offering free passes as compensation.
Suno experienced a data breach in November 2025 affecting millions, but disclosure only occurred in July 2026. This 8-month notification delay raises significant compliance concerns.
Spain's data protection agency fined 23andMe nearly $3 million for cybersecurity failings that enabled the 2023 hack affecting 2,600 Spaniards as part of a 6.9 million person global breach.
Cyberattack against Maine telecommunications firm disrupted municipal internet service across 23 towns along the state's midcoastal region, affecting local government operations.
Security researchers highlight AI-based attack tools, application security challenges with LLM-generated code, and continued abuse of legitimate platforms for malicious purposes
Russian-speaking actor 'Trim' has dismantled publicly available frontier AI models and integrated them with offensive security tools to create an attack platform. Demonstrates increasing sophistication in AI weaponization.
Research shows AI-generated code introduces an average of 15 vulnerabilities per codebase, with actual risk depending more on framework pairing than the model used. LLMs show high false-positive rates in vulnerability detection.
FBI warns that fraudsters are using fake IC3 accounts and direct messages to target people who've already been scammed, impersonating federal agents to extract additional funds or information.
LG Electronics will suspend apps that turn smart TVs into always-on residential proxy nodes, following research showing 42% of available apps contained such functionality. Addresses IoT device abuse for proxy networks.
Regulatory actions include major fines, domain seizures for FIFA piracy, and AI app store revenue scrutiny alongside national security exercises
Kenya's government probing hack of President Ruto's website where attackers replaced homepage with cryptocurrency wallet address and ransom threat to publish unspecified information.
U.S. Justice Department seized more than 1,000 websites and blocked 1,970 domains used to illegally stream FIFA World Cup 2026 matches without authorization.
New York Department of Financial Services announced $50 million penalty against Swedbank for withholding information from investigators during Panama Papers-related probe.
San Francisco City Attorney targeting how Apple and Google profit from AI nudify apps rather than just hosting decisions, representing new legal approach to app store responsibility.
Taiwan will temporarily reduce 5G and 4G network speeds to 1% capacity during annual Han Kuang civilian and military exercises to test national resilience.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.