This week's threat landscape is marked by critical remote code execution vulnerabilities across widely deployed platforms, including WordPress Core 'wp2shell' flaws with public exploits, 7-Zip RCE vulnerabilities, and SonicWall SMA zero-days actively exploited by Inc Ransomware. CISA has mandated immediate patching of actively exploited Fortinet FortiSandbox vulnerabilities by government agencies. The period saw a surge in ACR Stealer campaigns targeting enterprise customers to harvest browser credentials and authentication tokens, while new macOS malware ClickLock employs process termination tactics to force password disclosure.
Ransomware activity remains aggressive with 30 new victim postings across multiple groups including Qilin, Nova, and Doommageddon, targeting sectors from healthcare (Abbott Laboratories) to critical infrastructure (Colombian oil giant Ecopetrol, Indonesian maritime ministry). A massive credential exposure affects 23+ million Paidwork users. Notable infrastructure threats include sophisticated supply chain attacks abusing ViPNet software update mechanisms to target Russian government agencies, and North Korean threat actors deploying malware via fake coding interview processes using SVG steganography that evaded all antivirus detection.
Emerging attack techniques include abuse of AI agent frameworks (Claude Chrome extension vulnerabilities, agentic AI security gaps), OpenSSL's HollowByte DoS flaw requiring only 11 bytes to trigger memory exhaustion, and a Windows LegacyHive zero-day granting admin privileges. Organizations should prioritize patching critical KEV entries, implement enhanced monitoring for ACR Stealer indicators, review AI agent security controls, and validate software supply chain integrity.
Multiple critical RCE vulnerabilities with active exploitation and public exploits demand urgent patching, including WordPress Core, 7-Zip, SonicWall, and Fortinet platforms.
CISA orders federal agencies to patch by Sunday. Unauthenticated attackers can execute arbitrary commands via crafted HTTP requests. Actively exploited in the wild.
Code injection and SSRF vulnerabilities chained together allow root-level access on mobile access appliances. Actively exploited by Inc ransomware operators.
Critical remote code execution flaws in WordPress Core now have public exploits. Administrators must patch immediately to prevent widespread compromise.
7-Zip version 26.02 fixes remote code execution vulnerability allowing attackers to execute code by convincing users to open specially crafted compressed files.
Critical CVSS 10.0 vulnerability in @fastify/http-proxy fails to rewrite request prefix when URL-encoded, potentially allowing unauthorized access to backend services.
Three chained zero-day vulnerabilities allow privilege escalation and persistent root access on Siemens ROX II OT switches used in critical infrastructure.
Security researcher releases zero-day exploit allowing attackers to escalate privileges on up-to-date Windows systems. No patch currently available.
Vulnerability allows unauthenticated attackers to trigger denial-of-service on OpenSSL servers with minimal payload, causing severe memory bloat.
Significant surge in ACR Stealer attacks targeting enterprises, new macOS information stealer, and sophisticated supply chain compromises via software updates.
Advanced threat actor abuses ViPNet private networking software update mechanism to target Russian government agencies, demonstrating sophisticated supply chain compromise.
Microsoft observes significant increase in ACR Stealer attacks using ClickFix lures to steal browser passwords, authentication tokens, and sensitive documents from enterprise environments.
New macOS information-stealing malware terminates all visible processes to force users into entering system login passwords for credential harvesting.
New malicious framework deploys over 20 payloads focused on stealing cryptocurrency wallet seed phrases, credentials, and sensitive data.
DPRK-aligned hackers hide malware inside SVG flag images to backdoor developer job interview coding tests. Zero antivirus vendors detected the threat.
FBI arrests Florida man for uploading fake video games containing malware to Steam platform. Malware designed to steal passwords and drain crypto wallets from victims.
Multiple Mirai malware download URLs detected targeting ARM, MIPS, x86 architectures. Includes infrastructure at codeinspector.ddns.net and various IP addresses.
Major credential exposure affecting 23+ million Paidwork users, healthcare giant Abbott investigates dual breaches, and 30 new ransomware victims posted including critical infrastructure targets.
Almost 11GB of data from gig economy platform Paidwork posted publicly containing 23,272,765 unique email addresses plus bank account numbers, dates of birth, passwords, phone numbers, and financial transaction data.
TheGentlemen ransomware group claims breach of Colombia's national oil company Ecopetrol, operations across center, south, east and north Colombia plus international operations.
Nova ransomware group claims breach of Indonesia's Directorate of Shipping and Maritime Affairs, critical infrastructure target.
Healthcare giant Abbott confirms unauthorized access to legacy Exact Sciences systems in Cancer Diagnostics business and investigates separate LabCentral portal breach claim by ShinyHunters and ShadowByt3$.
Coca-Cola subsidiary Fairlife discloses ransomware attack disrupting operations and temporarily suspending production across Michigan, New York, and Arizona plants.
E&Y notifies customers of data breach caused by compromise of third-party support ticket system used by IT personnel.
New York Attorney General secures settlement from 23andMe after company failed to adequately protect customers' genetic data in previous breach.
Krybit ransomware group claims breaches of two major Bulgarian financial institutions - Eurohold Bulgaria holding company and Euroins Insurance Company.
Blackout ransomware claims breach of family-owned omnichannel brand curator with deadline set for August 8, 2026.
AI agent security vulnerabilities, sophisticated evasion techniques including SVG steganography, and novel authentication bypass methods characterize this week's evolving threat landscape.
Flaw in Anthropic's Claude for Chrome allows malicious extensions to trigger predefined AI actions by simulating user clicks, potentially abusing access to Gmail, Google Docs, Calendar, and Salesforce.
WebSocket server transport in Model Context Protocol SDK lacks Host/Origin validation, enabling potential CSRF and unauthorized access attacks.
Incomplete fix for CVE-2026-50197 allows oversized request bodies to bypass Open Policy Agent deny-on-presence Rego policies in Skipper proxy.
Over one million phishing emails employ text salting techniques with hidden content to bypass AI-powered and LLM-based email security filters.
ACR Stealer campaigns successfully using ClickFix lures - fake error messages prompting users to run malicious PowerShell commands presented as fixes.
Vulnerability in Shark robot vacuums allows one compromised device to unlock remote access to many others, exposing home maps, camera feeds, and Wi-Fi passwords.
Multiple ransomware groups remain highly active with 30 new victim postings. North Korean APT continues developer-focused campaigns. Russian government agencies targeted by sophisticated supply chain attack.
TheGentlemen group claims breach of Ecopetrol, Colombia's $33.1 billion national oil company with operations across the country and abroad.
Inc ransomware operators actively exploiting chained SonicWall SMA vulnerabilities (CVE-2026-15410, CVE-2026-15409) to gain root-level access.
Qilin posts 16 new victims including healthcare (City Ambulance Service), education (The Nueva School), manufacturing (PP+K, Sicc), food service (Heartland Catfish, Don Tortaco), and critical infrastructure sectors.
Nova group targets Brazilian jewelry retailer, Turkish automotive manufacturer (meralmanisa), Indonesian maritime ministry (Dephub), and Brazilian software company FMZ Tecnologia.
DPRK-aligned actors using sophisticated SVG steganography to hide malware in fake developer job interview coding tests, evading all antivirus detection.
Regulatory enforcement actions and policy developments around data protection, age verification, and international surveillance legislation.
Italian DPA issues €1.7 million fine to telecom operator for serious data security shortcomings leading to two breaches exposing 365,000+ customers' personal information.
Ofcom launches investigation into TikTok for alleged inadequate age verification, potentially exposing children to online harms in violation of UK online safety laws.
Sen. Ron Wyden urges Trump administration to push back against Canada's proposed Lawful Access Act that would 'weaponize American technology infrastructure' for surveillance.
US prosecutors charge New York man and woman for laundering money stolen in large-scale cyber investment fraud scams totaling $43 million.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.