<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CISO Intelligence]]></title><description><![CDATA[Intelligent ideas. Actionable advice. ]]></description><link>https://www.cisointelligence.co</link><image><url>https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png</url><title>CISO Intelligence</title><link>https://www.cisointelligence.co</link></image><generator>Substack</generator><lastBuildDate>Thu, 06 Aug 2026 10:08:07 GMT</lastBuildDate><atom:link href="https://www.cisointelligence.co/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jonathan Care]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cisointelligence@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cisointelligence@substack.com]]></itunes:email><itunes:name><![CDATA[Jonathan Care]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jonathan Care]]></itunes:author><googleplay:owner><![CDATA[cisointelligence@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cisointelligence@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jonathan Care]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Breaking: JetBrains TeamCity RCE Under Active Exploitation — 6 August 2026]]></title><description><![CDATA[JetBrains TeamCity RCE Under Active Exploitation: CISA Adds CVE-2026-63077 to KEV]]></description><link>https://www.cisointelligence.co/p/breaking-jetbrains-teamcity-rce-under</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-jetbrains-teamcity-rce-under</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Thu, 06 Aug 2026 08:02:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>JetBrains TeamCity RCE Under Active Exploitation: CISA Adds CVE-2026-63077 to KEV</h2><p>CISA has added CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to the Known Exploited Vulnerabilities catalog with confirmed active exploitation. The vulnerability carries a maximum CVSS 3.1 score of 9.8 and a CVSS 2.0 score of 10.0. Federal agencies have until August 8 to remediate under BOD 26-04.</p><p>The flaw is a deserialization of untrusted data vulnerability (CWE-502) in TeamCity's agent polling protocol, the channel distributed build agents use to check in with the central server. An attacker with HTTP or HTTPS network access to a TeamCity server can bypass authentication entirely and execute arbitrary operating system commands with the privileges of the TeamCity server process. No credentials are required. No user interaction is needed. The vulnerability affects every TeamCity On-Premises version ever shipped.</p><h2>From Disclosure to Active Exploitation in Nine Days</h2><p>Security researcher Antoni Tremblay privately reported the issue to JetBrains on July 10, 2026. JetBrains publicly disclosed it on July 27, stating there was no evidence of active exploitation at that time. CISA's KEV addition on August 5, with its exploitation assessment upgraded from "none" to "active" and both automatable and total-impact ratings confirmed, means threat actors moved from awareness to weaponisation within nine days of public disclosure. Censys identified roughly 4,500 TeamCity web properties reachable from the internet shortly after disclosure.</p><p>This is the second time in 2026 that TeamCity has been in the exploitation spotlight. Storm-1175, the operator behind Medusa ransomware, previously weaponised a different TeamCity vulnerability (CVE-2023-42793) as an initial access vector for ransomware deployment. The product's central role in CI/CD pipelines makes it a high-value target: compromise of a TeamCity server exposes build configurations, stored credentials, and enables supply-chain-style attacks against any software built through the affected instance.</p><h2>Mitigation</h2><p>JetBrains has released fixes in TeamCity 2026.1.3 (build 222742) and TeamCity 2025.11.7 (build 208264). An interim security patch plugin covers versions 2017.1 and later. Servers running 2017.1 through 2018.1 must restart after installing the patch; 2018.2 and later can apply it without a restart. Organisations unable to upgrade immediately should restrict network access to TeamCity servers and treat any internet-facing instance as potentially compromised.</p><h2>So What / Action</h2><p>If you run TeamCity On-Premises, patch immediately. The 9.8 CVSS score combined with confirmed active exploitation and the 4,500-instance internet exposure makes this a matter of hours, not days. If you cannot patch today, remove TeamCity from internet-facing positions and audit build artefacts and credentials for signs of compromise. This is not a theoretical risk: the same product class was instrumental in Medusa ransomware operations earlier this year, and CISA's rapid escalation from "no evidence of exploitation" to "actively exploited" within nine days indicates determined, capable threat actors are already operational.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: CISA Emergency Directive — N-able N-central Auth Bypass + Langflow RCE + AI-Powered Attack Campaign — 5 August 2026]]></title><description><![CDATA[CISA Emergency Directive: N-able N-central Auth Bypass Under Active Exploit]]></description><link>https://www.cisointelligence.co/p/breaking-cisa-emergency-directive-168</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-cisa-emergency-directive-168</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 05 Aug 2026 17:01:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>CISA Emergency Directive: N-able N-central Auth Bypass Under Active Exploit</h2><p>CISA has issued an Emergency Directive requiring all Federal Civilian Executive Branch agencies to patch CVE-2026-18577, a critical authentication bypass in N-able's N-central remote monitoring and management platform, by August 6, 2026. The three-day remediation window, invoked under Binding Operational Directive 26-04, signals the severity of active exploitation already observed in the wild.</p><p>The vulnerability is the result of an incomplete fix for CVE-2026-18556, an earlier authentication bypass. Attackers found an alternative exploitation path and began abusing it in late July. A successful attack grants full administrative control of the N-central console, the same access level reserved for NOC and engineering staff. From there, attackers have been observed pivoting into managed endpoints using N-central's built-in Take Control feature and establishing persistent Cloudflare tunnels via the legitimate "cloudflared" utility.</p><p>Huntress, which analyzed logs from affected MSP partners, reports that threat actors connected using a default account named "MSP Support" from IP 173.249.252.200, then conducted domain controller reconnaissance, enumerated running processes, and moved laterally through victim environments. Connections were routed through NordVPN and Mullvad VPN exit nodes. Four IPs are associated with the campaign: 173.249.252.200, 87.249.138.34, 37.19.210.32, and 68.235.46.214.</p><p>As of August 3, nearly all cloud-hosted N-central instances had been patched, but 28.6% of self-hosted servers remained exposed and internet-accessible. The UK's NHS and Belgium's Centre for Cybersecurity have both issued urgent advisories. The complete fix is in N-central version 2026.3 HF1. Organizations that cannot patch immediately should consider disabling N-central entirely until remediation is possible.</p><h2>Langflow RCE Added to KEV as AI-Powered Attack Campaign Emerges</h2><p>CISA simultaneously added CVE-2026-9198 (CVSS 9.8) to the Known Exploited Vulnerabilities catalog, a code injection flaw in Langflow that allows unauthenticated remote code execution on default deployments. The fix shipped in version 1.10.1 last month, but Langflow has been repeatedly weaponized by threat actors since June.</p><p>The context makes this more urgent than a routine KEV addition. Palo Alto Networks Unit 42 has documented a Chinese-speaking threat actor, tracked as knaithe/KnYuan and based in Zhuhai, China, conducting an AI-powered autonomous hacking campaign using DeepSeek via the Hermes Agent framework. When initial exploitation attempts against a Langflow flaw (CVE-2026-33017, also CVSS 9.8) failed due to restrictive target configurations, the AI agent autonomously researched and identified alternative higher-value vulnerabilities, including n8n flaws, to find an entry point. The actor attempted over 460 targets, combining autonomous and manual techniques against Citrix NetScaler, Marimo, Apache Tomcat, and IKE VPN endpoints.</p><p>Separately, the Apache Tomcat flaw CVE-2026-34486, also added to KEV today, is being exploited by a China-nexus threat actor targeting government and commercial infrastructure across more than 100 countries. SOCRadar discovered the campaign after analyzing an exposed staging server containing reconnaissance lists, nine weaponized CVEs, a cracked Chinese Cobalt Strike variant, and the SNOWLIGHT Linux loader.</p><h2>So What / Action</h2><p>Three immediate actions:</p><p>1. N-able N-central: If you run it, patch to 2026.3 HF1 now. Hunt for indicators: files named svchost.exe in user Documents folders, registered Cloudflared services, and the four IPs listed above. Check Take Control logs for unusual sessions. If patching is impossible, disable N-central until you can.</p><p>2. Langflow: If any instance is internet-facing, treat it as potentially compromised. Upgrade to 1.10.1 or remove from external access. The AI-powered attack dimension means passive exploitation is no longer theoretical: autonomous agents can now adapt in real time when initial exploit attempts fail.</p><p>3. Apache Tomcat: Ensure EncryptInterceptor configurations are current. Versions 11.0.21, 10.1.54, and 9.0.117 fix CVE-2026-34486. If you are running Tomcat clustering with inter-node communication, this is not optional.</p><p>The convergence of an Emergency Directive, a CVSS 9.8 KEV addition, and confirmed AI-driven autonomous attack campaigns in the same 24-hour window is not coincidence. The barrier to entry for sophisticated exploitation is dropping. RMM platforms remain high-value targets. Patch cycles matter more than they did last quarter.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Langflow RCE (CVSS 9.8) and AI-Driven Tomcat Exploitation Added to CISA KEV — 5 August 2026]]></title><description><![CDATA[IBM Langflow RCE (CVSS 9.8) and Apache Tomcat Under Active Exploitation: CISA Adds Three to KEV]]></description><link>https://www.cisointelligence.co/p/breaking-langflow-rce-cvss-98-and</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-langflow-rce-cvss-98-and</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 05 Aug 2026 12:02:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>IBM Langflow RCE (CVSS 9.8) and Apache Tomcat Under Active Exploitation: CISA Adds Three to KEV</h2><h2>Langflow Code Injection: CVE-2026-9198</h2><p>CISA has added CVE-2026-9198 (CVSS 9.8) to the Known Exploited Vulnerabilities catalog with a three-day remediation deadline of August 7. This is a code injection vulnerability in IBM Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. Langflow is an open-source AI application development platform, and this is not the first time it has been targeted. Security defects in Langflow have been repeatedly weaponised over recent months, including for Monero cryptomining deployment and by the EncForge ransomware group.</p><p>A public proof-of-concept exploit is available, and a Metasploit module has emerged. The flaw affects Langflow OSS versions 1.0.0 through 1.10.0, exploiting default configurations that expose auto-login and code-validation endpoints. IBM patched the vulnerability in version 1.10.1, released in July 2026. The combination of unauthenticated RCE, default-config exploitation, and available weaponised exploit code makes this immediately dangerous for any internet-facing Langflow instance.</p><p>If you run Langflow in any environment, assume it is being scanned. Upgrade to 1.10.1 or later immediately. If upgrading is not possible today, take the instance offline or restrict network access to trusted sources only. There is no credible workaround beyond patching.</p><h2>Apache Tomcat Encryption Bypass: CVE-2026-34486</h2><p>CISA also added CVE-2026-34486 (CVSS 7.5) to the KEV catalog, a missing encryption of sensitive data vulnerability in Apache Tomcat that allows bypass of the EncryptInterceptor cluster component. This vulnerability has been attributed to a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan, who leveraged DeepSeek via the Hermes Agent framework as an autonomous offensive operator.</p><p>Palo Alto Networks Unit 42 reported that this actor attempted to exploit over 460 targets, blending autonomous and manual techniques. When initial exploitation attempts against a Langflow flaw failed, the AI agent conducted autonomous research to identify alternative higher-value vulnerabilities, including flaws in n8n, to find a way in. The actor also manually exploited Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), and IKE VPN (CVE-2026-33824) endpoints. The autonomous process executed hundreds of hours of manual targeting analysis in minutes while managing its own compute resources.</p><p>This is one of the first documented cases of an AI-driven autonomous hacking campaign with confirmed exploitation attributed to a nation-state aligned actor. The targeting scope included European and global infrastructure. Patched versions are Apache Tomcat 11.0.21, 10.1.54, and 9.0.117.</p><h2>N-able N-central: Escalation</h2><p>CISA has now added CVE-2026-18556 to the KEV catalog alongside the previously tracked CVE-2026-18577. Both authentication bypass vulnerabilities in N-able N-central are under active exploitation. The BOD 26-04 deadline for federal agencies is August 6. As of August 3, approximately 28.6% of self-hosted N-central servers remained unpatched. NHS England has assessed that further exploitation is likely. Belgium's Centre for Cybersecurity has issued its own advisory urging immediate action.</p><p>This story was covered in yesterday's breaking alert. The key update: if you are running N-central, you must be on build 2026.3.1.7 specifically. Builds 2026.2 and 2026.3 are both insufficient. Check Take Control session logs for unrecognised MSP Support connections, and hunt for Cloudflared services and svchost.exe in user Documents folders on managed endpoints.</p><h2>So What / Action</h2><p>Two of the three new KEV entries involve CVSS 9.8 unauthenticated RCE in infrastructure products. The third involves a Chinese AI-driven campaign that autonomously identified and exploited vulnerabilities across 460 targets. Langflow administrators should treat this as an active incident: patch to 1.10.1 immediately or take instances offline. Apache Tomcat administrators should verify they are on 11.0.21, 10.1.54, or 9.0.117 and audit EncryptInterceptor configurations. The knaithe/KnYuan campaign is a signal that autonomous AI-driven exploitation is no longer theoretical. It is operational, and it scales.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Three Actively Exploited Infrastructure Vulnerabilities — Arista VeloCloud (CVSS 10.0), N-able N-central, and Check Point SmartConsole — 4 August 2026]]></title><description><![CDATA[Arista VeloCloud Command Injection (CVSS 10.0), N-able N-central Auth Bypass, and Check Point SmartConsole Zero-Day: Three Actively Exploited Infrastructure Vulnerabilities]]></description><link>https://www.cisointelligence.co/p/breaking-three-actively-exploited</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-three-actively-exploited</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Tue, 04 Aug 2026 17:01:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Arista VeloCloud Command Injection (CVSS 10.0), N-able N-central Auth Bypass, and Check Point SmartConsole Zero-Day: Three Actively Exploited Infrastructure Vulnerabilities</h2><h2>Arista VeloCloud Orchestrator &#8212; CVE-2026-16812</h2><p>Arista has disclosed a maximum-severity OS command injection vulnerability in VeloCloud Orchestrator (VCO) on-premises deployments. CVE-2026-16812 carries a CVSS score of 10.0 and is confirmed as actively exploited in the wild. The flaw allows an unauthenticated remote attacker to execute arbitrary OS commands, gaining access to privileged internal functions on the VCO host. Successful exploitation can compromise the confidentiality, integrity, and availability of the orchestrator and all data it manages, including SD-WAN configuration for every edge device in the fleet.</p><p>CISA added the vulnerability to the KEV catalog on July 27 with a three-day remediation deadline of July 30 under BOD 26-04. Arista's advisory (Security Advisory 0144) confirms active exploitation. Any organisation running VeloCloud Orchestrator on-premises should verify patch status immediately.</p><h2>N-able N-central &#8212; CVE-2026-18577</h2><p>N-able has confirmed active exploitation of an authentication bypass in its N-central remote monitoring and management platform. CVE-2026-18577 (CVSS 8.2) is the result of an incomplete fix for CVE-2026-18556. An unauthenticated attacker can bypass authentication and gain administrative access to the N-central server, then use the built-in Take Control feature to reach managed downstream endpoints.</p><p>Huntress has observed exploitation across multiple organisations. Attackers enumerated running processes on domain controllers and other key servers, moved laterally across multiple hosts, and in some cases installed Cloudflare tunnels as persistent services that survive reboots and need no inbound firewall rules. N-able has released build 2026.3.1.7 as the first fully patched version. Build 2026.3 alone is insufficient. The 2026.2 fix for the original CVE-2026-18556 is also insufficient.</p><p>Every N-central customer, whether hosted or self-hosted, should upgrade to 2026.3.1.7 immediately, audit Take Control session logs for unrecognised MSP Support connections, and hunt for Cloudflared services and svchost.exe in user Documents folders on managed endpoints. Self-hosted servers are particularly at risk, with 28.6% still unpatched as of August 3.</p><h2>Check Point SmartConsole &#8212; CVE-2026-16232</h2><p>CISA added CVE-2026-16232 (CVSS 9.3) to the KEV catalog on July 22 with a three-day remediation deadline of July 25. This is an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server in releases R81.20, R82, and R82.10. An unauthenticated remote attacker with network access can obtain a login token and authenticate with full administrative privileges, potentially taking over the entire security management infrastructure, altering firewall policies, creating privileged accounts, and pivoting into managed environments.</p><p>Check Point has released Jumbo Hotfix Accumulator patches. Smart-1 Cloud customers are already protected. Until patches are deployed, restrict Trusted Clients in SmartConsole to approved administrative IP addresses and subnets, and ensure management interfaces are never exposed to untrusted networks.</p><h2>So What / Action</h2><p>Three actively exploited vulnerabilities targeting security and management infrastructure within a single week is unusual and concerning. Each of these products sits at a control-plane choke point: SD-WAN orchestration, endpoint management, and firewall policy management. A compromise at any of these layers gives an attacker leverage over the entire downstream environment.</p><p>Patch immediately if you run any of these products. For N-central specifically, the incomplete first patch means you must verify you are on build 2026.3.1.7, not just 2026.3. For Check Point, restrict management access to trusted IPs now and apply the Jumbo Hotfix. For Arista VeloCloud, check your on-prem orchestrator version against Arista's advisory and patch if you have not already passed the July 30 KEV deadline.</p><p>Beyond patching, audit for indicators of compromise. Each of these vulnerabilities has been exploited in the wild, and the window between initial exploitation and discovery may have been days or weeks.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Cl0p Exploiting PTC Windchill RCE in Manufacturing Campaign — 4 Aug 2026]]></title><description><![CDATA[Cl0p Ransomware Exploiting PTC Windchill RCE in Manufacturing Campaign]]></description><link>https://www.cisointelligence.co/p/breaking-cl0p-exploiting-ptc-windchill</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-cl0p-exploiting-ptc-windchill</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Tue, 04 Aug 2026 12:01:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Cl0p Ransomware Exploiting PTC Windchill RCE in Manufacturing Campaign</h2><h3>Unauthenticated RCE in PTC Windchill and FlexPLM Under Active Cl0p Exploitation</h3><p>Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a data extortion campaign targeting manufacturing, automotive, aerospace, and retail organisations. The attack chains CVE-2026-12569 (CVSS 9.3), a critical unauthenticated remote code execution vulnerability in PTC Windchill, with a separate pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint (CVSS 7.5) to achieve full compromise without any credentials.</p><p>CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog in late July. PTC has since issued continued warnings about heightened threat activity and confirmed that attackers are deploying hex-named JSP web shells under /Windchill/login/ for persistent remote command execution. Ransom-ISAC, eCrime.ch, and DEFUSED published a coordinated advisory on August 3 with full indicators of compromise.</p><h3>Attack Pattern: From Initial Access to Double Extortion</h3><p>The tradecraft follows Cl0p's established playbook: gain initial access through the RCE vulnerability, enumerate file systems for engineering and design data, then exfiltrate and extort. Extortion emails are sent from previously compromised accounts to hundreds of users within each target organisation, directing victims to contact the Cl0p crew. JSP web shells provide persistent command execution even after the initial vulnerability is patched, meaning remediation without forensic sweeps leaves backdoors in place.</p><p>ReliaQuest confirmed active exploitation of CVE-2026-12569 for unauthenticated RCE and JSP web shell deployment for remote command execution and sensitive product data exfiltration. The observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories, including MOVEit Transfer, GoAnywhere MFT, Cleo, and Accellion FTA.</p><h3>Why This Matters for Critical Infrastructure</h3><p>PTC Windchill is product lifecycle management software used pervasively in manufacturing, defence, aerospace, and automotive supply chains. The data it holds &#8212; CAD files, engineering designs, bill of materials, supplier information &#8212; represents the intellectual property crown jewels of its users. An RCE vulnerability in this software, actively exploited by a ransomware group with 885 claimed victims, poses a direct threat to the manufacturing sector's confidentiality and operational continuity. Fewer than 100 instances were internet-exposed as of June, but that number has been declining as organisations respond to the threat, meaning the remaining exposed instances are disproportionately valuable targets.</p><h3>So What / Action</h3><p>If you run PTC Windchill or FlexPLM, treat this as an active incident. Patch immediately if any instance is internet-facing &#8212; check PTC's security advisories for the latest hotfixes. Audit web application logs for POST requests to /Windchill/login/ containing JSP filenames, and search for hex-named JSP files in that directory. Hunt for the four published IOC IPs (216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35) in firewall and proxy logs. If your organisation is in manufacturing, aerospace, or automotive, verify with your PLM and engineering teams that Windchill is not exposed to the internet and that patching is current. Assume that a successful RCE leaves persistent web shells &#8212; patching alone is not remediation without a thorough forensic review.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: N-able N-central RMM Compromised — Active Exploitation with Customer Impact — 3 August 2026]]></title><description><![CDATA[N-able N-central RMM Compromised &#8212; Active Exploitation with Downstream Customer Impact]]></description><link>https://www.cisointelligence.co/p/breaking-n-able-n-central-rmm-compromised</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-n-able-n-central-rmm-compromised</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 03 Aug 2026 08:02:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>N-able N-central RMM Compromised &#8212; Active Exploitation with Downstream Customer Impact</h2><h3>N-able N-central Authentication Bypass Under Active Exploitation</h3><p>N-able disclosed on August 1 that its N-central remote monitoring and management (RMM) platform is under active exploitation. The vulnerability, CVE-2026-18577, is an authentication bypass that allows unauthenticated remote attackers to gain full administrative access to N-central servers. The original flaw (CVE-2026-18556) was supposedly patched in version 2026.2, but N-able discovered an alternate exploitation path that the initial fix did not block &#8212; making this an incomplete patch scenario that extends the affected range to all builds prior to 2026.3.1.7, released August 2.</p><h3>Attack Chain: From RMM Takeover to Persistent Endpoint Access</h3><p>The attack sequence is straightforward and dangerous. An attacker authenticates to the N-central web console using the authentication bypass, escalates to full administrative privileges, then uses the built-in Take Control feature to pivot into managed endpoints. From there, they register Cloudflare tunnels (cloudflared) as persistent services on compromised machines, establishing outbound connections that survive reboots and require no inbound firewall rules. N-able confirmed attackers reached downstream customer systems through compromised N-central servers.</p><p>Huntress, which published its rapid response analysis on August 3, confirmed exploitation within at least one partner environment, where attackers accessed nine organisations and enumerated processes on endpoints. The initial patch was insufficient; any N-central server not running build 2026.3.1.7 remains vulnerable.</p><h3>Incomplete Patch, Incomplete Disclosure</h3><p>N-able has not disclosed the number of affected customers, how many downstream devices were reached, when exploitation began, or who is behind it. The four IP addresses initially published as indicators of compromise turned out to be VPN exit nodes (Mullvad and NordVPN), though two additional addresses were later added. N-able began investigating after an unusual volume of licensing errors from on-premises customers on July 31. Finland's national cyber security centre issued its own advisory on August 2 stating all versions available before the emergency hotfix were vulnerable.</p><h3>MSP Supply Chain Risk</h3><p>This is a supply-chain compromise by another name. N-central is the central management platform MSPs use to monitor, patch, and remotely access every customer endpoint. A compromised N-central server gives an attacker the same control as a trusted NOC engineer &#8212; the ability to push scripts, deploy tools, initiate remote sessions to domain controllers, and modify security configurations across every customer simultaneously. More than 55% of Huntress's partner N-central cloud servers were still unpatched as of August 3.</p><h3>So What / Action</h3><p>If you run N-able N-central or are an MSP customer whose provider uses it, treat this as an active incident, not a patching exercise. Upgrade to build 2026.3.1.7 immediately &#8212; versions 2026.3 and earlier are insufficient. Restrict N-central console access to known IP ranges and enforce MFA on all accounts. Audit Take Control session logs for connections from unexpected IPs, unusual hours, or support accounts (e.g., mspsupport@n-able.com). Hunt for Cloudflare tunnel services (cloudflared.exe) on managed endpoints, svchost.exe in user Documents folders, and traffic from the published IOC IPs. If your MSP uses N-central, ask them directly whether they've applied the 2026.3.1.7 hotfix and what their compromise assessment shows &#8212; because a compromised RMM server gives an attacker the keys to every downstream customer's environment.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Cisco Secure FMC Hardcoded Credentials Exploited — 31 July 2026]]></title><description><![CDATA[Cisco Secure FMC Hardcoded Credentials Under Active Attack]]></description><link>https://www.cisointelligence.co/p/breaking-cisco-secure-fmc-hardcoded</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-cisco-secure-fmc-hardcoded</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 31 Jul 2026 17:00:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Cisco Secure FMC Hardcoded Credentials Under Active Attack</h2><p>Cisco has disclosed that CVE-2026-20316, a hardcoded credential vulnerability in Secure Firewall Management Center (FMC), is being actively exploited by attackers in the wild. The flaw allows unauthenticated remote attackers to log in using a low-privilege built-in account and access sensitive system data.</p><h3>Vulnerability Details</h3><p>Cisco assigned this a High severity rating despite a CVSS score of 5.3 because the credentials enable access that can be chained with additional FMC vulnerabilities to escalate privileges. Cisco reports awareness of active exploitation beginning in July 2026, though the company has not disclosed when attacks started, who is behind them, or which organizations have been targeted. The reporting researcher is Jimi Sebree of Horizon3.ai.</p><p>The vulnerability affects all on-premises Secure FMC deployments (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) regardless of configuration. Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, and Security Cloud Control are not impacted.</p><h3>What This Means</h3><p>No workarounds exist. FMC instances exposed to the internet are immediately at risk. Even internal-only deployments are vulnerable if any administrator's workstation is compromised. The hardcoded credentials mean every FMC installation is equally exposed &#8212; this is not a misconfiguration issue.</p><p>Attack surface is reduced if the FMC management interface is not internet-facing, but this provides only a speed bump, not genuine protection against insiders or compromised internal systems.</p><h3>Recommended Actions for CISOs</h3><p>1. Immediate: Verify whether your FMC instances are internet-exposed. If yes, apply patches now or isolate systems until patches are deployed. 2. Forensics: Search /var/log/messages for "license" entries. Unauthorized logins using the hardcoded account are the primary detection method. 3. Patching: Cisco has released hot fixes for all supported versions. Schedule deployment within the next 48 hours. 4. Privilege audit: Review what the compromised low-privilege account can access in your environment. If it reaches critical assets (routing, logging, policy data), elevation risk is immediate.</p><p>The fact that Cisco is not disclosing attack scope suggests widespread exploitation. Treat this as active threat, not routine vulnerability management.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Iranian Cyberattack Disables Water Systems Across Minnesota — 30 July 2026]]></title><description><![CDATA[Iranian-Attributed Cyberattack Disables Water Systems Across Minnesota]]></description><link>https://www.cisointelligence.co/p/breaking-iranian-cyberattack-disables</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-iranian-cyberattack-disables</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Thu, 30 Jul 2026 17:00:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Iranian-Attributed Cyberattack Disables Water Systems Across Minnesota</h2><p>A coordinated attack targeting over 30 water and wastewater utilities across Minnesota (July 26-27, 2026) has been publicly attributed to Iranian-affiliated threat actors by U.S. government officials (per New York Times, July 30). This represents the first confirmed nation-state attack against critical infrastructure in the U.S. water sector in 2026. At least one treatment plant went offline; multiple facilities reported disrupted automated controls and cellular communications.</p><h2>Attribution and Timing</h2><p>U.S. intelligence officials did not initially comment on attribution, but CISA had released a cybersecurity advisory just days before the Minnesota attack began, specifically warning that "Iranian-affiliated cyberactors" were targeting operational technology (OT) devices in water and wastewater systems. The timing of the advisory followed by immediate active exploitation suggests sophisticated reconnaissance and coordination. Attribution remains under active federal investigation.</p><h2>Operational Impact</h2><p>Water operators reported disrupted automated controls, loss of cellular connectivity to remote monitoring systems, and at least one plant offline. The attack affected multiple jurisdictions simultaneously, indicating either a supply-chain compromise, shared vulnerability, or centrally coordinated campaign against a common toolset or configuration.</p><h2>Defender Actions</h2><p>CISA released a checklist (July 29) in collaboration with the Australian Signals Directorate to help critical infrastructure operators isolate vital OT systems during cyberattacks or geopolitical crises. This is a direct response to the unfolding Minnesota incident. Key mitigations: air-gap critical OT from IT networks, enforce multi-factor authentication on remote access systems, and conduct immediate inventory of water system SCADA/HMI devices exposed to the internet.</p><p>Water sector CISOs should immediately assume Iranian-affiliated actors are actively reconnaissance networks in your region. If you operate water/wastewater treatment, this is not a "possibility"&#8212;it is active threat. Patch or isolate any internet-facing OT access points, inventory VPN appliances (Fortinet, Ivanti, Pulse, Cisco&#8212;all targeted historically by Iran), and brief your board today.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Arista VeloCloud Orchestrator CVSS 10.0 Zero-Day Under Active Exploitation — 29 July 2026]]></title><description><![CDATA[Arista VeloCloud Orchestrator &#8212; CVSS 10.0 Zero-Day Under Active Exploitation]]></description><link>https://www.cisointelligence.co/p/breaking-arista-velocloud-orchestrator-5ec</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-arista-velocloud-orchestrator-5ec</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 29 Jul 2026 12:01:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Arista VeloCloud Orchestrator &#8212; CVSS 10.0 Zero-Day Under Active Exploitation</h2><p>A maximum-severity OS command injection vulnerability in Arista VeloCloud Orchestrator (VCO) on-premises deployments is being actively exploited in the wild. Tracked as CVE-2026-16812, the flaw carries a CVSS v3.1 score of 10.0 and a CVSS v4.0 score of 10.0 &#8212; the highest possible rating on both scales.</p><p>CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on July 27, 2026, giving federal agencies until July 30 to patch. That is a three-day deadline, which signals the urgency.</p><h2>What Happened</h2><p>Arista disclosed the vulnerability on July 27, confirming it was discovered externally and is under active exploitation. The flaw exists in VeloCloud Orchestrator on-prem versions, where a function intended for internal use is exposed to remote attackers without requiring authentication, tenant credentials, or any special configuration. By default, VCO's web interface is accessible and vulnerable. No credentials are needed.</p><p>An attacker with network access to the VCO web interface can inject OS commands, gaining full control of the orchestrator host &#8212; compromising confidentiality, integrity, and availability of the platform and all data it manages. Because VCO centrally manages VeloCloud Edge devices, compromise of the orchestrator can cascade to downstream SD-WAN edges: credential theft, configuration manipulation, and lateral movement into the managed network.</p><h2>Affected Versions</h2><p>- VCO 5.2.x prior to 5.2.3.14 - VCO 6.1.x prior to 6.1.3.4 - VCO 6.4.x prior to 6.4.2.4 - VCO 7.0.x prior to 7.0.0.1</p><p>Hosted and dedicated VCO deployments were patched by Arista in advance of the advisory. Only on-premises installations are affected. Arista EOS-based products, VeloCloud Edge, and VeloCloud Gateway are not affected.</p><h2>IoCs and Detection</h2><p>Arista published three attacker IP addresses: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Block these at the perimeter and search logs for their presence immediately. There is no single definitive indicator of compromise &#8212; look for unusual URL-like path components, encoded characters, references to local services, or high-frequency requests to internal endpoints in VCO web access logs. Review backend application logs, system logs, database logs, and file-system timestamps for anomalies. Preserve all logs before remediation.</p><h2>Escalation Risk</h2><p>Compromise of VCO gives attackers control over managed VeloCloud Edge devices. Check administrator activity for unexpected changes, validate device state, and rotate credentials on both the orchestrator and downstream edges. Treat an exploited VCO as a full network-layer compromise until proven otherwise.</p><h2>Also on the KEV: Fortinet FortiOS SSL-VPN Bypass</h2><p>CISA also added CVE-2025-68686 (CVSS 5.3) &#8212; a FortiOS SSL-VPN information exposure allowing unauthenticated attackers to bypass the patch for a symbolic link persistency mechanism. This is a secondary issue: exploitation requires prior compromise via another vulnerability at the filesystem level. Patching deadline is August 10.</p><h2>So What / Action</h2><p>If you run VeloCloud Orchestrator on-prem, this is an emergency. Patch to the fixed version today. If immediate patching is not possible, restrict VCO web interface access to trusted administrative networks only and monitor for the three known attacker IPs. After patching, rotate all orchestrator and edge credentials, validate device state, and review logs for signs of prior compromise. CISA's July 30 deadline is not aspirational &#8212; it reflects active exploitation right now. For organisations not running VCO, verify that no SD-WAN vendor or MSSP manages VeloCloud on your behalf &#8212; their orchestrator compromise becomes your incident.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Arista VeloCloud Orchestrator CVSS 10.0 Zero-Day Under Active Exploitation — 28 July 2026]]></title><description><![CDATA[Arista VeloCloud Orchestrator: CVSS 10.0 Zero-Day Under Active Exploitation]]></description><link>https://www.cisointelligence.co/p/breaking-arista-velocloud-orchestrator</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-arista-velocloud-orchestrator</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Tue, 28 Jul 2026 17:01:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Arista VeloCloud Orchestrator: CVSS 10.0 Zero-Day Under Active Exploitation</h2><p>Arista has disclosed a maximum-severity OS command injection vulnerability in VeloCloud Orchestrator (VCO) On-Prem that is being actively exploited in the wild. CVE-2026-16812 scores 10.0 on both CVSS v3.1 and v4.0, requires no authentication, no user interaction, and no special configuration to exploit. It affects every supported on-premises VCO release.</p><p>The flaw exists in privileged internal functionality that was never intended to be remotely accessible. Because VCO exposes its web interface by default and the vulnerable endpoint requires no tenant or operator credentials, any network-reachable orchestrator is vulnerable. An attacker who reaches the web interface can execute arbitrary commands on the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and all data it manages, including SD-WAN configuration, device credentials, and certificate material.</p><p>Arista confirmed the vulnerability was discovered externally and is under active exploitation. The company has published three attacker IP addresses observed conducting the attacks: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Organisations running VCO on-prem should block these immediately and review logs for historical access.</p><p>The blast radius extends beyond the orchestrator itself. Because VCO manages VeloCloud Edge devices across the SD-WAN fabric, a compromised orchestrator gives attackers a path to edge devices as well, including the ability to rotate credentials, modify configurations, and replace trusted orchestrator instances with attacker-controlled ones.</p><p>CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog on July 27, with a federal remediation deadline of July 30. That two-day turnaround reflects the severity.</p><h3>Affected Versions</h3><p>- VCO 5.2.x prior to 5.2.3.14 - VCO 6.1.x prior to 6.1.3.4 - VCO 6.4.x prior to 6.4.2.4 - VCO 7.0.x prior to 7.0.0.1</p><p>Hosted and dedicated VCO instances have already been patched by Arista in advance. On-prem deployments are the concern.</p><h3>Immediate Actions</h3><p>1. Patch now. Upgrade to the fixed releases listed above. If immediate patching is not possible, restrict VCO web interface access to trusted administrative networks only. 2. Block the known IOCs. Add 8.19.75.217, 206.72.242.124, and 206.72.242.162 to firewall and WAF block lists. 3. Hunt for compromise. Review VCO web access logs, backend application logs, system logs, and database logs for access from the attacker IPs or anomalous activity. Look for unexpected outbound connections, unfamiliar admin actions, and any evidence of credential or certificate access. 4. Post-remediation. Treat the orchestrator as potentially compromised. Rotate all credentials and certificates, validate the state of managed Edge devices, and consider restoring from a trusted backup rather than remediating in place.</p><h2>Also on the KEV: Fortinet FortiOS SSL-VPN Bypass</h2><p>CISA simultaneously added CVE-2025-68686 (CVSS 5.3) to the KEV catalog, citing active exploitation. This FortiOS SSL-VPN vulnerability allows an unauthenticated remote attacker to bypass the patch for a previous symbolic link persistence mechanism via crafted HTTP requests, but only after the device has already been compromised at the filesystem level through a separate vulnerability. The remediation deadline is August 10. If you have already patched FortiOS and do not have evidence of prior compromise, the immediate risk is lower. If you have unpatched FortiGate SSL-VPNs facing the internet, this is another reason to prioritise patching.</p><h2>So What</h2><p>The VeloCloud issue is the urgent one. A CVSS 10.0 zero-day in a central SD-WAN management platform, under active exploitation, with a 48-hour CISA remediation deadline, is about as serious as enterprise vulnerability situations get. The orchestrator sits at the heart of the network. Compromise of VCO is not a perimeter event; it is a control plane takeover. If you run VeloCloud on-prem, this should be the only thing your network team is doing right now.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: WordPress wp2shell & SharePoint RCE — Two Critical Exploits Under Active Attack — 27 July 2026]]></title><description><![CDATA[WordPress wp2shell: Pre-Auth RCE in Core, Mass Exploitation Confirmed]]></description><link>https://www.cisointelligence.co/p/breaking-wordpress-wp2shell-and-sharepoint</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-wordpress-wp2shell-and-sharepoint</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 27 Jul 2026 17:02:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>WordPress wp2shell: Pre-Auth RCE in Core, Mass Exploitation Confirmed</h2><p>A pre-authentication remote code execution chain in WordPress Core is being actively exploited in the wild, with webshells deployed on compromised servers and mass scanning campaigns underway. The vulnerability pair, dubbed "wp2shell" (CVE-2026-63030 and CVE-2026-60137), affects every default WordPress installation running versions 6.9.0 through 7.0.1 without requiring plugins, authentication, or user interaction.</p><p>CVE-2026-63030 is a logic flaw in the WordPress REST API batch processor. When `wp_parse_url()` fails on a sub-request path, the error is pushed to the validation array but not the matches array, desynchronizing them. This causes every subsequent request to dispatch under the wrong handler, bypassing authorisation checks. CVE-2026-60137 is a SQL injection in the `author__not_in` parameter of the posts endpoint, which is normally protected by parameter validation. The batch API desynchronization bypasses that validation, enabling a UNION-based SQL injection. Chained together, the two flaws allow an unauthenticated attacker to create an administrator account, log in, and upload a malicious plugin for full code execution.</p><p>Wiz Research has confirmed active exploitation in cloud environments, observing malicious plugin uploads, user enumeration, local file inclusion targeting `wp-config.php` credentials, and admin panel access following successful batch API exploitation. Two categories of webshell have been identified: a minimal one-liner returning 404 as evasion, and a 150KB obfuscated full-featured attack platform disguised as a legitimate WordPress plugin. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on July 21, confirming active exploitation.</p><p>WordPress 6.9.5 and 7.0.2 fix the issue. Administrators should verify that every internet-facing WordPress instance has updated. Organisations that cannot patch immediately should block the `/wp-json/batch/v1` endpoint at the WAF, or disable anonymous REST API access. Even after patching, investigate for signs of compromise: review access logs for batch endpoint requests returning HTTP 207/200, check for unfamiliar plugins or PHP files, and audit admin accounts created since mid-July.</p><h2>SharePoint CVE-2026-50522: Machine Key Theft Persists Past Patching</h2><p>Microsoft SharePoint Server is under active exploitation via CVE-2026-50522 (CVSS 9.8), a deserialization vulnerability that enables unauthenticated remote code execution. Demonstrated live at Pwn2Own Berlin, the flaw was patched in July's Patch Tuesday. A public proof-of-concept released on July 20 triggered immediate exploitation: watchTowr's honeypot network captured compromise attempts within hours, and Defused Cyber confirmed unauthenticated attacks delivering .NET deserialization payloads through SharePoint sign-in endpoints.</p><p>The critical detail is persistence. Attackers are stealing SharePoint machine keys in a single request, enabling continued access even after the vulnerability itself is patched. Organisations that applied the Microsoft update but did not rotate machine keys and other exposed credentials remain compromised. CISA added CVE-2026-50522 to its KEV catalog on July 22 with a remediation deadline of July 25.</p><p>Patch immediately. Then rotate machine keys and any credentials that may have been exposed through the SharePoint server. Treat the patch as necessary but insufficient: any SharePoint instance that was unpatched between July 8 (Patch Tuesday) and now should be assumed compromised until key rotation and forensic review are complete.</p><h2>So What</h2><p>Two critical RCE vulnerabilities, both in widely deployed software, both under confirmed active exploitation, both added to CISA KEV in the past week. WordPress powers roughly 43% of the web. SharePoint is backbone infrastructure for thousands of enterprises. The WordPress situation is the more immediately urgent because the attack requires no credentials and the vulnerable code path exists in default installations, but the SharePoint machine key issue means that organisations which patched without rotating keys are likely still compromised.</p><p>If you run WordPress, verify patch levels now. If you run SharePoint on-premises, patch and then rotate keys. If you run both, this is the weekend those change windows were made for.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Three Critical RCE Flaws Under Active Exploitation — WordPress, Check Point, SharePoint — 24 July 2026]]></title><description><![CDATA[WordPress Core Unauthenticated RCE (wp2shell) Under Active Exploitation]]></description><link>https://www.cisointelligence.co/p/breaking-three-critical-rce-flaws</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-three-critical-rce-flaws</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 24 Jul 2026 17:01:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>WordPress Core Unauthenticated RCE (wp2shell) Under Active Exploitation</h2><p>Three critical vulnerabilities with confirmed active exploitation were added to CISA's Known Exploited Vulnerabilities catalog this week. The most urgent: a WordPress Core flaw chain enabling unauthenticated remote code execution on default installations.</p><p>WordPress wp2shell &#8212; CVE-2026-63030 + CVE-2026-60137 (CVSS 9.1/10.0). Two vulnerabilities in WordPress Core that, when chained, allow an unauthenticated attacker to achieve full RCE on default WordPress installations. No plugins, no special configuration, no authentication required. CVE-2026-63030 is a REST API batch-route interpretation conflict that enables SQL injection via CVE-2026-60137 (a WP_Query `author__not_in` SQLi). The chain has been dubbed "wp2shell." Wiz reports 60% of organisations running WordPress initially had at least one vulnerable instance, with 25% exposing it to the internet. Public PoC exploits are circulating. Active exploitation confirmed by Wiz and Coalition. CISA added both CVEs to KEV on July 21 with a remediation deadline of July 24 for CVE-2026-63030. Patch: WordPress 7.0.2.</p><p>Check Point SmartConsole Auth Bypass &#8212; CVE-2026-16232 (CVSS 9.3). An improper authentication vulnerability in SmartConsole that allows an unauthenticated remote attacker to obtain a login token and authenticate with full administrative privileges. Check Point has confirmed active exploitation in the wild affecting a small number of customers. Any exposed Check Point management server is at critical risk. CISA KEV added July 22, remediation deadline July 25. Patch: Check Point sk185169.</p><p>Microsoft SharePoint Deserialization RCE &#8212; CVE-2026-50522 (CVSS 9.8). The third SharePoint RCE added to KEV in this month's sustained exploitation campaign, following CVE-2026-56164 and CVE-2026-58644. An unauthenticated deserialization vulnerability enabling remote code execution. watchTowr reports active exploitation following public PoC release, with attackers pulling SharePoint machine keys for persistent access. Defused Cyber has observed .NET deserialization payloads hitting SharePoint sign-in endpoints with no authentication material. CISA KEV added July 22, remediation deadline July 25. This is the fourth SharePoint zero-day exploited in the past month.</p><p>So what? Three of the most widely deployed platforms in enterprise environments &#8212; WordPress, Check Point, and SharePoint &#8212; have critical unauthenticated RCE or admin-takeover flaws under active exploitation simultaneously. The wp2shell chain is particularly dangerous because it requires no plugins and hits default WordPress installations. CISA's three-day remediation deadlines (July 24-25) signal urgency. If you run any of these, patch immediately and assume compromise: rotate credentials on exposed SharePoint servers, audit Check Point management server access logs, and scan WordPress instances for webshell indicators. The WordPress patch deadline is today.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Iranian Hackers Actively Disrupting US Water and Energy ICS — 24 July 2026]]></title><description><![CDATA[Iranian State Hackers Actively Disrupting US Water and Energy Industrial Control Systems]]></description><link>https://www.cisointelligence.co/p/breaking-iranian-hackers-actively</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-iranian-hackers-actively</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 24 Jul 2026 08:02:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Iranian State Hackers Actively Disrupting US Water and Energy Industrial Control Systems</h2><p>The FBI, NSA, CISA, and the Department of Energy issued an updated joint advisory (AA26-097A) this week confirming that Iranian state-backed hackers are actively breaching and manipulating industrial control systems at US water and energy providers, with disruptive effects already achieved in the field. This is not a theoretical warning. The agencies state the attackers have already broken into at least one critical infrastructure provider and altered controller programming logic to disable shutdown and alarm processes, allowing systems to enter unsafe operating conditions without notifying operators.</p><p>The campaign targets programmable logic controllers (PLCs) on internet-connected operational technology networks. Initial reporting earlier this year identified Rockwell Automation/Allen-Bradley controllers as the primary target. The updated advisory expands the scope significantly, confirming exploitation now extends to Schneider Electric and Siemens PLCs as well, with the agencies warning that "potentially all internet exposed" PLCs across US critical infrastructure sectors may be vulnerable.</p><p>The attackers are manipulating data shown on human-machine interface (HMI) and SCADA displays while simultaneously altering the underlying control logic, so operators see normal readings while the physical process drifts into an unsafe state. Indicators of compromise include traffic on ports 44818, 2222, 102, and 502 originating from foreign hosting providers, and malicious modifications to reusable code modules within controller programs.</p><p>CISA attributes the motive to ongoing hostilities between Iran and the US/Israel, describing the activity as intended "to cause disruptive effects within the United States." This fits a broader pattern this year of escalating Iranian offensive cyber activity, including the Handala group's wipe of tens of thousands of employee devices at medical device maker Stryker, a claimed (though unconfirmed) attempt to disrupt California's Cal Water supply, and the leak of FBI Director Kash Patel's personal email contents.</p><p>While the confirmed victims sit in the US, the technique is vendor-based rather than geography-based. Any organisation running internet-exposed Rockwell, Schneider Electric, or Siemens PLCs anywhere, including in Europe, is within the stated blast radius. European utilities and manufacturers using the same controller families should treat this as directly relevant, not a US-only problem.</p><h2>So What / Action</h2><p>Audit every PLC and OT device for direct internet exposure today, not this quarter. If you cannot immediately verify a controller is isolated behind a secure gateway or firewall, assume it is exposed and remediate now. For Rockwell Automation devices specifically, CISA recommends physically setting the controller's mode switch to RUN to block remote logic changes. Review logs for connections on ports 44818, 2222, 102, and 502 from unfamiliar or foreign-hosted IP ranges, and compare current controller program logic against known-good backups to detect unauthorised changes to shutdown and alarm routines. Enforce strict multi-factor authentication on any remote engineering access, and brief OT operations teams that HMI/SCADA display readings cannot currently be trusted as ground truth on affected networks; physical verification of safety-critical states may be necessary until systems are confirmed clean. This is an active, ongoing campaign with confirmed disruptive impact, not a patch-and-move-on advisory.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: SharePoint RCE + Check Point Admin Bypass + Qilin Ransomware via Palo Alto VPN — 23 July 2026]]></title><description><![CDATA[Three Critical Infrastructure Attacks: SharePoint RCE, Check Point Admin Bypass, and Qilin Ransomware via Palo Alto VPN]]></description><link>https://www.cisointelligence.co/p/breaking-sharepoint-rce-check-point</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-sharepoint-rce-check-point</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Thu, 23 Jul 2026 08:01:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Three Critical Infrastructure Attacks: SharePoint RCE, Check Point Admin Bypass, and Qilin Ransomware via Palo Alto VPN</h2><p>CISA added two new entries to the Known Exploited Vulnerabilities catalog on July 22, both with confirmed active exploitation and three-day remediation deadlines. Separately, Arctic Wolf has confirmed that Qilin ransomware operators are actively exploiting a Palo Alto Networks GlobalProtect authentication bypass to breach corporate networks.</p><h2>SharePoint CVE-2026-50522: Deserialization RCE Under Active Exploitation</h2><p>Microsoft SharePoint Server contains a critical deserialization vulnerability (CVSS 9.8) allowing unauthenticated remote code execution over the network. This is the fifth SharePoint vulnerability exploited in a sustained campaign targeting on-premises deployments. watchTowr has observed active exploitation following the release of a public proof-of-concept, with attackers stealing IIS machine keys to maintain persistent access even after patching. Defused Cyber reports that captured exploit requests carry no authentication material, consistent with the unauthenticated attack profile. CISA's remediation deadline is July 25.</p><p>This is not a single CVE to patch and move on. The sustained SharePoint campaign (CVEs 32201, 45659, 56164, 58644, and now 50522) demands patching, machine key rotation, and credential reset on any exposed SharePoint server. Organisations that patched earlier SharePoint CVEs without rotating machine keys should assume persistence mechanisms may already be in place.</p><h2>Check Point SmartConsole CVE-2026-16232: Firewall Management Plane Compromise</h2><p>Check Point SmartConsole contains an improper authentication vulnerability (CVSS 9.3) that allows unauthenticated remote attackers to obtain an application login token and authenticate with full administrative privileges over firewall management. This affects Security Management and Multi-Domain Management running R81.10 through R82.10. Check Point has confirmed active exploitation affecting a limited number of customers whose management interfaces were exposed directly to the internet without IP restrictions. The vendor has released a jumbo hotfix alongside additional hardening fixes. CISA's remediation deadline is July 25.</p><p>Firewall management plane compromise is a worst-case scenario. An attacker with full SmartConsole privileges can modify security policies, disable logging, create backdoor access rules, and reconfigure VPN tunnels. The observed indicator of compromise is connections from specific IP addresses (151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250, 194.213.18.137) to management interfaces. Smart-1 Cloud customers are already protected. On-premises management must apply the jumbo hotfix immediately and restrict management access to trusted IP ranges.</p><h2>Qilin Ransomware Deployed via Palo Alto GlobalProtect CVE-2026-0257</h2><p>Arctic Wolf Labs has confirmed that Qilin ransomware operators are exploiting CVE-2026-0257 (CVSS 7.8), a GlobalProtect authentication bypass in PAN-OS, to gain unauthenticated VPN access and deploy ransomware. The flaw becomes exploitable when authentication override cookies are enabled alongside specific certificate configurations. Multiple intrusions throughout June 2026 traced back to this single entry point. Post-exploitation activity includes LSASS credential dumping, full Active Directory database extraction via ntdsutil, lateral movement via PsExec, data exfiltration to MEGA cloud storage using Rclone, and encryption via a password-protected payload staged in C:\PerfLogs. Attackers also disabled Microsoft Defender real-time protection and wiped all Windows Event Log channels before ransomware deployment. Affected PAN-OS versions include 12.1, 11.2, 11.1, and 10.2 prior to patched builds.</p><h2>So What / Action</h2><p>Three urgent actions this week. First, patch SharePoint Server immediately and rotate IIS machine keys on any internet-facing instance. Patching without key rotation leaves the door open. Second, apply the Check Point jumbo hotfix to all Security Management and Multi-Domain Management servers, verify management interface access is restricted to trusted IPs, and check logs for connections from the listed IoC IPs. Third, for Palo Alto GlobalProtect, apply PAN-OS patches for CVE-2026-0257 across all internet-facing firewalls, terminate all active GlobalProtect sessions after patching, and if you suspect prior exploitation, rotate all domain credentials including the KRBTGT account. Monitor for execution from C:\PerfLogs and ensure Windows Event Logs are forwarded to a centralised SIEM to preserve evidence even if local logs are cleared. All three are in active exploitation with documented ransomware or persistence activity. This is not patch-and-forget week.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: WordPress wp2shell mass exploitation underway — 22 July 2026]]></title><description><![CDATA[WordPress wp2shell: Mass Exploitation Underway After PoC Release]]></description><link>https://www.cisointelligence.co/p/breaking-wordpress-wp2shell-mass</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-wordpress-wp2shell-mass</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 22 Jul 2026 12:01:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>WordPress wp2shell: Mass Exploitation Underway After PoC Release</h2><p>Two WordPress Core vulnerabilities tracked as CVE-2026-63030 (CVSS 9.8) and CVE-2026-60137 (CVSS 5.9) are being chained under the name "wp2shell" to achieve unauthenticated remote code execution on default WordPress installations. CISA added both to the Known Exploited Vulnerabilities catalog on July 21. The situation has escalated rapidly over the past 24 hours.</p><p>CVE-2026-63030 is a logic flaw in the WordPress REST API batch endpoint (/wp-json/batch/v1). The batch processor validates and executes in separate loops; when wp_parse_url() fails on a sub-request, the error is pushed to the validation array but not the matches array, desynchronising them and causing every subsequent request to dispatch under the wrong handler. This lets an unauthenticated attacker reach internal API endpoints that normally require authentication.</p><p>CVE-2026-60137 is a SQL injection in the author__not_in parameter of WP_Query. The parameter is interpolated directly into raw SQL when provided as a scalar string. On its own, parameter validation prevents exploitation, but the batch API desynchronisation bypass removes that guard, yielding pre-authentication UNION-based SQL injection.</p><p>When chained, the two flaws enable an attacker to create an administrator account via SQL injection, log in, and upload a malicious plugin for full code execution. No plugins, no special configuration, no user interaction required. WordPress versions 6.8.0 through 7.0.1 are affected. Fixes shipped in 6.8.6, 6.9.5, and 7.0.2 on July 17.</p><p>Wiz Research has confirmed active exploitation in cloud environments. Post-exploitation activity includes malicious plugin uploads (persistent webshells), user enumeration, local file inclusion targeting wp-config.php for database credentials, and successful admin panel access. Two webshell variants have been identified: a minimal one-liner returning 404 as evasion, and a 150KB full-featured attack platform disguised as a WordPress plugin called "CMSmap" with file management, database access, port scanning, and privilege escalation modules. A third variant registers a custom REST API endpoint to accept base64-encoded commands. At least 13 attacker IPs are involved, with activity shifting from targeted probing to broad internet-wide scanning.</p><p>Field Effect reports that public PoC code appeared within hours of disclosure. Multiple repositories now host working exploits and automated scanners. Cloudflare data indicates the vulnerable code path is reachable when a persistent object cache is not in use, which covers most default WordPress installations.</p><p>So what / Action: Patch WordPress immediately to 6.8.6, 6.9.5, or 7.0.2 and verify automatic updates completed. Where immediate patching is not possible, block the /wp-json/batch/v1 and ?rest_route=/batch/v1 endpoints at the WAF or disable anonymous REST API access. After patching, hunt for indicators of compromise: HTTP 207/200 responses to batch endpoint requests, user agents containing "wp2shell" or "rezwp2shell", unexpected PHP files in content and cache directories, unfamiliar plugins, and unauthorised administrator accounts. Regenerate credentials and authentication salts on any site that was exposed. This is not a wait-and-see situation. The attack surface is enormous (WordPress powers 43% of the web) and weaponised exploit code is freely available.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: WordPress wp2shell RCE under mass exploitation — 22 July 2026]]></title><description><![CDATA[WordPress wp2shell: Unauthenticated RCE Under Active Mass Exploitation]]></description><link>https://www.cisointelligence.co/p/breaking-wordpress-wp2shell-rce-under</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-wordpress-wp2shell-rce-under</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 22 Jul 2026 08:01:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>WordPress wp2shell: Unauthenticated RCE Under Active Mass Exploitation</h2><p>Two WordPress Core vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog on July 21 are being exploited in the wild at scale. Codenamed "wp2shell," the chain combines CVE-2026-63030 (REST API batch endpoint route confusion) with CVE-2026-60137 (WP_Query SQL injection via `author__not_in`) to achieve unauthenticated remote code execution on default WordPress installations. No plugins, no authentication, no preconditions.</p><p>CISA has assigned a three-day remediation deadline of July 24 for CVE-2026-63030, reflecting the urgency. WordPress 6.9.5 and 7.0.2 patch both flaws. Any site running 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1 is vulnerable.</p><h2>Active Exploitation Escalating Rapidly</h2><p>WatchTowr reports "tens of thousands of exploitation attempts" against honeypots following the release of public proof-of-concept code. KEVIntel has traced exploitation from 13 unique IPs across Switzerland, Germany, the UK, Indonesia, Lithuania, the Netherlands, and Singapore. Attackers are using blind, UNION-based, and Boolean-based SQL injection payloads matching publicly available exploit code.</p><p>Wiz estimates that 60% of organizations using WordPress had at least one vulnerable instance at disclosure, with 25% exposing a vulnerable server to the internet.</p><h2>Post-Exploitation Activity Confirmed</h2><p>Observed attacker behaviour includes deploying a 150 KB web shell disguised as the legitimate CMSmap plugin, which functions as a full attack platform with file management, database access, port scanning, batch code injection, and privilege escalation modules including MySQL UDF exploitation. Over 100 backdoor administrator accounts have been created across compromised sites. At least one threat actor has attempted to install Overlord RAT, a Golang-based remote access trojan. Credential exfiltration and local file inclusion targeting database credentials and authentication keys have also been observed.</p><h2>Langflow RCE Also Added to KEV</h2><p>In the same CISA batch, CVE-2026-0770 (Langflow Inclusion of Functionality from Untrusted Control Sphere) was added. This CVSS 9.8 vulnerability allows unauthenticated remote code execution on Langflow installations versions 1.0.0 through 1.10.0. CISA set a July 24 remediation deadline. BleepingComputer reports active exploitation against AI application servers. Patch to Langflow 1.9.0 or later.</p><h2>So What / Action</h2><p>For WordPress: Update to 7.0.2 or 6.9.5 immediately. If you cannot patch, enable persistent object caching (Redis or Memcached) to block the RCE path, and apply WAF rules to filter REST API batch endpoint abuse. After patching, audit for new administrator accounts, unfamiliar plugins (especially anything claiming to be CMSmap), and unexpected PHP files. Patching alone is not sufficient if exploitation predates the update.</p><p>For Langflow: Update to v1.9.0+ and review logs for unauthenticated API calls to code execution endpoints. Any internet-facing Langflow instance on an older version should be considered compromised until verified.</p><p>Both are three-day CISA deadlines. This is not a drill.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: ServiceNow Pre-Auth RCE Exploited — 21 July 2026]]></title><description><![CDATA[ServiceNow Pre-Auth RCE Now Exploited in the Wild]]></description><link>https://www.cisointelligence.co/p/breaking-servicenow-pre-auth-rce</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-servicenow-pre-auth-rce</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Tue, 21 Jul 2026 08:02:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>ServiceNow Pre-Auth RCE Now Exploited in the Wild</h2><p>CVE-2026-6875, a CVSS 9.5 pre-authentication sandbox-escape remote code execution vulnerability in the ServiceNow AI Platform, is now being actively exploited. Threat intelligence firm Defused confirmed in-the-wild exploitation on Saturday, with attack payloads observed hitting the same pre-auth sink that researchers from Assetnote at Searchlight Cyber documented, but using a different sandbox-escape gadget chain than the published proof of concept. In other words, attackers reverse-engineered an independent exploitation path, which signals real capability and intent, not script-kiddie PoC chasing.</p><p>ServiceNow addressed the vulnerability for hosted instances in April and released patches for self-hosted instances on July 13. But exploitation was confirmed just one week after those self-hosted patches shipped, and attackers are already bypassing the specific gadget chain the published PoC used. ServiceNow has not yet formally acknowledged active exploitation in its advisory, stating it is "not currently aware of exploitation against ServiceNow instances," a position that is now contradicted by observed attack traffic. If you run ServiceNow self-hosted and have not patched since July 13, treat this as an active incident, not a future risk.</p><p>The scale of exposure is enormous. ServiceNow's AI Platform processes over 100 billion workflows annually and powers more than 100,000 enterprise applications at 85% of Fortune 500 companies. A pre-auth RCE in this platform means that any internet-facing, unpatched self-hosted instance is a single HTTP request away from full code execution, no credentials required.</p><h2>Context: A Week of Critical Exploitation</h2><p>The ServiceNow exploitation joins an already brutal July patch cycle. Four SharePoint Server CVEs (including CVSS 9.8 CVE-2026-58644) are being chained for RCE, web shell deployment, and IIS machine key theft. Two FortiSandbox OS command injection flaws (CVE-2026-39808 and CVE-2026-25089, both CVSS 9.1) have landed on the CISA KEV with three-day patch deadlines. SonicWall SMA1000 zero-days are being exploited by a likely state-sponsored actor (UTA0533) deploying custom KnuckleBall malware. WordPress core has a chained pre-auth RCE (CVE-2026-63030 + CVE-2026-60137). And Oracle E-Business Suite is being exploited in the wild (CVE-2026-46817, confirmed by the Est&#233;e Lauder breach disclosure). Each of these has CISA KEV deadlines that have either just passed or are imminent.</p><p>Separately, Hugging Face disclosed the first confirmed breach by an autonomous AI agent. An agentic framework exploited template injection and a remote code dataset loader to gain code execution, steal cloud and cluster credentials, and move laterally across internal systems. Thousands of short-lived sandbox actions with self-migrating C2 on public services. Hugging Face's own forensic analysis was initially blocked by frontier model safety guardrails. This is the "agentic attacker" scenario the industry has been forecasting, and it has now arrived.</p><h2>So What / Action</h2><p>If you run self-hosted ServiceNow, patch CVE-2026-6875 immediately. The patch has been available since July 13. Exploitation is active, and the attacker's independent gadget chain means network-level controls tuned to block the published PoC will not stop this. For hosted instances, confirm your version is current.</p><p>For the broader July picture: audit every system on the CISA KEV list with a July deadline (SharePoint, FortiSandbox, SonicWall SMA1000, Oracle EBS). The patch deadlines have passed. If you have not applied patches, assume potential compromise and scope incident response accordingly. On SharePoint specifically, patching alone is insufficient; rotate IIS machine keys after patching, or persistence survives remediation.</p><p>For AI infrastructure: the Hugging Face breach changes the threat model. Any organization processing untrusted data through AI pipelines (model evaluation, dataset processing, sandboxed inference) should audit those pipelines for code execution paths. Have a self-hosted LLM capability vetted and ready for incident response. Relying on hosted models for forensics introduces a guardrail lockout risk at the moment you can least afford it.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: SharePoint Attack Chain Escalates to Domain Compromise via Web Shells and IIS Key Theft — 20 July 2026]]></title><description><![CDATA[SharePoint Under Siege: Active Attacks Chain RCE, Web Shells, and IIS Key Theft for Domain Compromise]]></description><link>https://www.cisointelligence.co/p/breaking-sharepoint-attack-chain</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-sharepoint-attack-chain</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 20 Jul 2026 17:01:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>SharePoint Under Siege: Active Attacks Chain RCE, Web Shells, and IIS Key Theft for Domain Compromise</h2><p>A new Resecurity analysis published today confirms what CISA's rapid KEV additions already signalled: the July 2026 SharePoint vulnerability cluster is not a patch-and-move-on event. Attackers are chaining three actively exploited CVEs into a full compromise pipeline that starts with an unauthenticated web request and ends with domain-level control, persistent web shell access, and stolen IIS cryptographic keys that survive patching.</p><p>Three CVEs sit at the centre of the attack chain now confirmed in the wild. CVE-2026-56164 (CVSS 9.8) is a missing authentication flaw that lets unauthenticated attackers reach critical SharePoint functions directly. CVE-2026-45659 (CVSS 8.8) is a deserialization vulnerability allowing authenticated attackers with Site Member privileges to execute arbitrary code remotely. CVE-2026-32201 (CVSS 6.5) provides improper input validation that enables privilege escalation from Site Member to Site Owner. When chained, an attacker can bypass authentication, elevate privileges, and achieve remote code execution without needing valid credentials at all.</p><p>Resecurity's report documents the attack chain in detail. After achieving RCE, threat actors deploy persistent web shells, specifically a variant named spinstall0.aspx, which extracts the machineKey element from SharePoint's web.config file. This IIS machine key is used to sign and encrypt ASP.NET view state and session data. Once stolen, an attacker can forge authentication tokens that persist even after the original vulnerability is patched, because simply applying the Microsoft update does not rotate the compromised key material. The stolen keys also enable lateral movement into SQL Server, Active Directory-connected resources, and other IIS applications sharing the same machine key.</p><p>Three additional SharePoint CVEs disclosed in the same patch cycle expand the attack surface further, even though they are not yet listed on KEV for active exploitation. CVE-2026-58644 (CVSS 9.8) is another unauthenticated deserialization RCE. CVE-2026-50522 (CVSS 9.8) is a second unauthenticated deserialization flaw. CVE-2026-55040 (CVSS 9.1) bypasses JWT authentication. Any one of these on its own would warrant emergency patching. All three in the same month, alongside three already-exploited vulnerabilities, turns this from a vulnerability management exercise into an active incident response situation.</p><p>CISA's BOD 26-04 deadlines have already passed for the first three: CVE-2026-56164 was due July 17, and the SharePoint and FortiSandbox additions from July 16 carried a July 19 deadline. If you run on-premises SharePoint and have not patched yet, you are now outside the compliance window and, more importantly, in the exploitation window.</p><p>The threat actor profile fits both nation-state and ransomware affiliate patterns. CISA attributes activity to "malicious cyber threat actors" without naming a specific group, but the TTPs (SharePoint exploitation, web shell deployment, machineKey theft, IIS module persistence) align with both espionage operators seeking long-term access and initial access brokers selling footholds to ransomware groups.</p><p>SharePoint Online and Microsoft 365 environments are not affected. This is an on-premises problem. Affected versions are SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016.</p><p>So what / Action: Patch immediately if you have not already. Then go further. Enable AMSI integration on every SharePoint web application. Hunt for spinstall0.aspx and any unexpected .aspx files in your SharePoint virtual directories. Check IIS logs for anomalous POST requests to SharePoint application pages. Crucially, after patching, rotate the IIS machineKey in web.config on every SharePoint server. A patch without a key rotation leaves the persistence door open. If you find indicators of compromise, assume domain-level compromise and scope your incident response accordingly. The attack chain is fast, the persistence is durable, and the window between patch availability and active exploitation has closed.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: SharePoint Zero-Day Confirmed, FortiSandbox Under Sustained Attack — 17 Jul 2026]]></title><description><![CDATA[SharePoint Zero-Day Confirmed &#8212; Four CVEs Under Active Attack as CISA Issues Hardening Alert]]></description><link>https://www.cisointelligence.co/p/breaking-sharepoint-zero-day-confirmed</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-sharepoint-zero-day-confirmed</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 17 Jul 2026 12:00:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>SharePoint Zero-Day Confirmed &#8212; Four CVEs Under Active Attack as CISA Issues Hardening Alert</h2><p>Microsoft has confirmed that CVE-2026-58644, a CVSS 9.8 deserialization-of-untrusted-data vulnerability in SharePoint Server, was exploited in the wild before patches were available &#8212; making it a true zero-day. The flaw allows unauthenticated remote code execution without user interaction across all supported on-premises SharePoint versions (Subscription Edition, 2019, and 2016). Microsoft initially listed it as "exploitation more likely" in its July 14 Patch Tuesday release, then revised the advisory within 24 hours to confirm active exploitation.</p><p>This is not an isolated incident. CISA's July 14 alert (updated July 16) identifies four separate SharePoint CVEs under active exploitation: CVE-2026-32201 (KEV-listed since April), CVE-2026-45659 (added July 1), CVE-2026-56164 (added July 14), and CVE-2026-58644 (added July 16). Together they form a complete attack chain: initial access via deserialization flaws, followed by privilege escalation, IIS machine key theft, and persistent malware deployment. The BOD 26-04 remediation deadline for the latest additions is July 19.</p><p>CISA's alert goes beyond patching guidance. It specifies concrete detection and hardening measures: enable AMSI integration with "Full Mode" request body scanning, watch for three specific AMSI detections (Exploit:Script/SuspSignoutReqBody.A, Exploit:Script/ToolPaneAuthBypass.A, Exploit:Script/ToolPaneAuthBypass.C) and the MDAV detection Backdoor:MSIL/LeakFang.A!dha for post-exploitation activity involving IIS-protected secrets. The agency warns that organisations must hunt for and remove intrusion artifacts, including machine-key harvesters, before rotating IIS machine keys &#8212; otherwise rotated keys will simply be stolen again.</p><p>A fifth SharePoint CVE, CVE-2026-50522, also scores CVSS 9.8 as an unauthenticated deserialization RCE. It was demonstrated at Pwn2Own Berlin with a working exploit handed to Microsoft, yet Microsoft still lists its exploit maturity as "unknown." Treat it as weaponised.</p><h2>FortiSandbox Exploitation Escalates &#8212; Third CVE in Six Months</h2><p>CISA added two Fortinet FortiSandbox OS command injection vulnerabilities to the KEV catalog on July 16, both with confirmed active exploitation. CVE-2026-25089 (CVSS 9.8) and CVE-2026-39808 (CVSS 9.1) allow unauthenticated remote code execution via crafted HTTP requests. Threat intelligence firm Defused Cyber reports observing exploitation of both CVEs within the past 24 hours, with a third related flaw (CVE-2026-39813) also showing exploitation activity. This makes three FortiSandbox CVEs exploited in 2026 alone. The BOD 26-04 remediation deadline is July 19.</p><h2>So What / Action</h2><p>- SharePoint: This is a full attack chain, not a single patch-and-move-on situation. Apply July 2026 Patch Tuesday immediately. Enable AMSI with Full Mode request body scanning. Before rotating IIS machine keys, hunt for and remove intrusion artifacts &#8212; specifically machine-key harvesting tools. Check for the AMSI and MDAV detection signatures CISA listed. Restrict SharePoint from direct internet exposure. Block external access to Central Administration. Assume that any internet-facing SharePoint server patched after this week may already be compromised. - FortiSandbox: Upgrade to patched versions before July 19. Inventory all FortiSandbox instances including Cloud and PaaS. Check web server logs for unusual HTTP requests to management interfaces. If running FortiSandbox 4.4.0&#8211;4.4.8, this is a direct, unauthenticated RCE &#8212; treat it as an active incident, not a routine patch. - Both of these are perimeter and collaboration technologies sitting at trust boundaries. The 3-day CISA remediation deadlines are a signal: these are being exploited now, not theoretically. Prioritise accordingly.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: SonicWall SMA1000 Zero-Days Exploited as Enterprise Backdoors, FortiSandbox Under Sustained Attack — 17 July 2026]]></title><description><![CDATA[SonicWall SMA1000 Zero-Days Under Active Exploitation &#8212; CVSS 10.0 SSRF Turns VPN Appliances Into Backdoors]]></description><link>https://www.cisointelligence.co/p/breaking-sonicwall-sma1000-zero-days</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-sonicwall-sma1000-zero-days</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 17 Jul 2026 08:01:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>SonicWall SMA1000 Zero-Days Under Active Exploitation &#8212; CVSS 10.0 SSRF Turns VPN Appliances Into Backdoors</h2><p>Rapid7's MDR team discovered two zero-day vulnerabilities in SonicWall SMA1000 appliances that are being actively exploited in the wild. CVE-2026-15409, a server-side request forgery flaw scoring CVSS 10.0, allows an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services. CVE-2026-15410, a code injection vulnerability, enables an authenticated admin-level attacker to execute arbitrary OS commands. Together, these form a complete attack chain: unauthenticated SSRF to establish a foothold, then privilege escalation to full appliance compromise.</p><p>What makes this particularly dangerous is what Rapid7 observed in customer environments. Attackers who exploited these flaws extracted high-value Active Directory credentials, session databases, and TOTP multi-factor authentication seed configurations. They then used the compromised SMA appliance as a stealthy pivot point, making Active Directory authentications that appeared to originate from the appliance's internal IP with no corresponding VPN tunnel. The appliance became an unmonitored backdoor into directory infrastructure.</p><p>CISA added both CVEs to the Known Exploited Vulnerabilities catalog on July 14 with a remediation deadline of July 17, 2026 &#8212; today. SonicWall has released platform hotfix releases that address both vulnerabilities.</p><h2>FortiSandbox Under Sustained Attack &#8212; Third Exploited CVE in 2026</h2><p>CISA added two Fortinet FortiSandbox OS command injection vulnerabilities to the KEV catalog on July 16, both confirmed as actively exploited. CVE-2026-25089 (CVSS 9.8) and CVE-2026-39808 (CVSS 9.1) both allow unauthenticated remote code execution via crafted HTTP requests to the web UI. This is the third FortiSandbox vulnerability exploited in the wild during 2026, following earlier flaws patched in April that saw active exploitation by mid-June.</p><p>Threat intelligence firm Defused Cyber reports observing exploitation of both CVEs over the past 24 hours. The 3-day CISA remediation deadline (July 19) and the unauthenticated nature of the attack make this urgent for any organisation running FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS.</p><h2>Microsoft SharePoint Deserialization RCE Added to KEV</h2><p>CVE-2026-58644, a deserialization of untrusted data vulnerability in Microsoft SharePoint scoring CVSS 9.8, was added to CISA's KEV catalog on July 16. The flaw allows unauthenticated remote code execution without user interaction. Microsoft initially flagged it as "exploitation more likely" in the July Patch Tuesday release, then updated the advisory within 24 hours to confirm active exploitation. The remediation deadline is July 19 under BOD 26-04.</p><p>This adds to an already problematic SharePoint security picture: CVE-2026-50522, another CVSS 9.8 unauthenticated deserialization RCE demonstrated at Pwn2Own Berlin, was also patched this month. The attack chain for these SharePoint flaws typically involves initial RCE followed by IIS machine key theft and persistent malware deployment.</p><h2>So What / Action</h2><p>- SonicWall SMA1000: Patch immediately with the latest platform hotfix. If patching is not possible today, isolate the appliance from internal networks and block external management access. Review logs for anomalous AD authentications originating from SMA appliance IPs without corresponding VPN sessions. Assume credential compromise: rotate all AD credentials and TOTP seeds that passed through affected appliances. - Fortinet FortiSandbox: Apply Fortinet's patches before the July 19 deadline. Inventory all FortiSandbox instances including Cloud and PaaS deployments. Check for signs of exploitation in web server logs, particularly unusual HTTP requests to management interfaces. - Microsoft SharePoint: Apply July 2026 Patch Tuesday security updates to all SharePoint servers. Rotate IIS machine keys on patched systems, not just patching alone. Restrict SharePoint admin interfaces from direct internet exposure. The pattern of SharePoint exploitation in 2026 (four separate CVEs) warrants a hardening review beyond patching. - Across all three: these are perimeter and collaboration technologies that attackers target precisely because they sit at trust boundaries. The CISA remediation deadlines are measured in days, not weeks. Prioritise accordingly.</p>]]></content:encoded></item></channel></rss>