CVE-2025-3248, CVE-2025-61882, CVE-2026-0257, CVE-2026-0770, CVE-2026-10520, CVE-2026-10591, CVE-2026-15409, CVE-2026-15410, CVE-2026-32201, CVE-2026-45659, CVE-2026-50055, CVE-2026-50522, CVE-2026-56164, CVE-2026-58644, CVE-2026-60137, CVE-2026-63030, CVE-2026-6875, CVE-2026-9108, CVE-2026-9140
Domains:
cloudlanecdn[.]com.
Get tomorrow's brief in your inbox
SharePoint's third actively exploited on-prem zero-day this month (CVE-2026-50522, CVSS 9.8) is letting attackers steal IIS machine keys straight off a single request. WordPress core's wp2shell chain (CVE-2026-63030 + CVE-2026-60137) is under mass scanning and exploitation and just landed in CISA's KEV catalog. SonicWall SMA1000 zero-days were exploited for a month before patches shipped, and Qilin ransomware affiliates are chaining a PAN-OS authentication bypass for initial access. Patch all four today.
SharePoint Server Machine Key Theft Under Active Exploitation (CVE-2026-50522)
Summary: A critical deserialization flaw in on-prem SharePoint Server (CVSS 9.8) is being actively exploited to steal IIS machine keys via a single unauthenticated request, following release of a public PoC. It is the third SharePoint flaw exploited this month alongside CVE-2026-56164 (5.3) and CVE-2026-58644 (9.8), and CISA has separately confirmed exploitation of CVE-2026-32201 and CVE-2026-45659 on the same platform. All affect Subscription Edition, 2019, and 2016.
WordPress Core wp2shell Chain Now in Mass Exploitation (CVE-2026-63030, CVE-2026-60137)
Summary: An unauthenticated RCE chain in WordPress core, combining a REST API batch-route confusion bug (CVE-2026-63030) with a SQL injection flaw (CVE-2026-60137), requires no plugins and no special configuration. Both CVEs were added to CISA's KEV catalog with a due date of 2026-08-04. SANS honeypots and multiple vendors report live exploitation from at least 13 unique source IPs, including credential harvesting, malicious plugin uploads, and web shells disguised as security plugins.
SonicWall SMA1000 Zero-Days Exploited for Weeks Before Patch (CVE-2026-15409, CVE-2026-15410)
Summary: Threat actor UTA0533 exploited two SonicWall SMA1000 VPN appliance flaws (CVSS 10.0 and 7.2) as zero-days starting around June 22, weeks before SonicWall's July 14 advisory. Volexity assesses the activity looks more like state-sponsored espionage than profit-driven crime; attackers deployed custom malware (KnuckleBall, OrangeTail webshell, Suo5 proxy) to harvest cached credentials and intercept traffic through the appliance.
Qilin Ransomware Chains PAN-OS Authentication Bypass for Initial Access (CVE-2026-0257)
Summary: Arctic Wolf Labs traced multiple June 2026 intrusions to CVE-2026-0257, a PAN-OS auth bypass (CVSS 7.8) that lets unauthenticated attackers establish VPN sessions when authentication override cookies are enabled with specific certificate configurations. It is CISA-KEV listed as ransomware-linked, EPSS 86.7 percent (100th percentile). Post-exploitation used PsExec over admin shares, cleared event logs, and disabled Defender before deploying Qilin, with tradecraft varying by RaaS affiliate.
ENCFORGE Ransomware Targets AI Infrastructure via Langflow RCE (CVE-2025-3248, CVE-2026-0770)
Summary: The JADEPUFFER operator behind an earlier Langflow attack (CVE-2025-3248, CVSS 9.8, KEV, EPSS 100 percent) has deployed a new compiled Go ransomware, ENCFORGE, that specifically targets PyTorch, TensorFlow, GGUF, and other AI model files across roughly 180 file extensions. CISA separately added a related Langflow flaw, CVE-2026-0770, to KEV this week (due 2026-07-24).
Ransomware Volume Up 25 Percent, Driven by Ecosystem Fragmentation, Not AI
Summary: Black Kite tracked 7,551 ransomware victims over the past 12 months, a 25 percent year-over-year increase, with 60+ new groups entering the field and 861 victims in March 2026 alone. 41 percent of organizations with a high externally-visible risk score were hit, versus 0.14 percent of low-risk organizations, and over 90 percent of victims showed a risk spike just before the attack. Manufacturing remains the top-targeted sector.
Ransom Payment Rates Rising as Some Jurisdictions Move to Ban Payments
Summary: Nearly half of ransomware victims pay, and median demands are rising, per Sophos data. The UK is advancing a ban on ransom payments by public sector and critical infrastructure bodies including the NHS. Confirmed ransomware victims globally rose 389 percent from 2024 to 2025, from roughly 1,600 to 7,831.
Estée Lauder Confirms Cl0p Oracle EBS Breach Exposed HR Data
Summary: Estée Lauder began notifying employees that names, Social Security numbers, passport numbers, bank account numbers, health data, and payroll information were stolen from its Oracle E-Business Suite instance in August 2025 via CVE-2025-61882 (KEV, ransomware-linked, EPSS 99.7 percent), the Cl0p mass-exploitation campaign. Cl0p claims 870GB of stolen archives.
Printer Ransom Notes: BitLocker Abuse in Low-Dollar Extortion
Summary: Kaspersky documented two Latin America incidents where attackers abused BitLocker to encrypt a single drive (exposed RDP in one case, misconfigured MSSQL in the other), then printed ransom notes on the victim's own office printers demanding as little as $3,000. Both intrusions were enabled by internet-exposed remote access and disabled endpoint protection.
HollowGraph / Cavern Manticore: Microsoft 365 Calendar Used as C2 Dead-Drop
Summary: An Iran-linked implant (Group-IB names it HollowGraph, Kaspersky's overlapping research calls the campaign Project CAV3RN) hides command-and-control inside Microsoft 365/Outlook calendar events dated 2050-05-13, using the Graph API so traffic looks like ordinary M365 activity. A DNS-based fallback channel refreshes stolen Entra ID client credentials via AAAA record responses. Group-IB found 12 victims, primarily Israeli organizations, active since June 3. Attribution leans toward Cavern Manticore (Iran MOIS-linked, overlapping MuddyWater/Lyceum) with low-to-moderate confidence.
TFF Trap: Font-File-Disguised Loaders Deliver Commodity RATs via BEC
Summary: Fortinet documented "The TFF Trap," a phishing campaign impersonating FedEx and other logistics brands that hides a Lua/AutoIt loader inside a disguised TrueType font (.ttf) file. The loader decrypts and executes payloads entirely in memory, unhooks monitored Windows APIs, and drops Agent Tesla, Remcos, XWorm, or Best Private Logger with no file written to disk.
SANDWORM_MODE: npm Supply Chain Worm Targets AI CI/CD Pipelines
Summary: CrowdStrike detailed SANDWORM_MODE, a 19-package npm worm from February 2026 that fingerprints whether it is running on a developer workstation versus a CI runner, harvests .npmrc tokens, secrets, and crypto wallet keys, and self-propagates by stealing npm publish tokens. CI environments skip a built-in delay gate and trigger immediately; Stage 2 payloads execute from /dev/shm and self-delete, leaving no disk artifacts.
ServiceNow Sandbox Escape Exploited Days After Patch (CVE-2026-6875)
Summary: A critical unauthenticated sandbox escape in the ServiceNow AI platform was patched July 14 for hosted instances; self-hosted customers must patch manually. Defused reported in-the-wild exploitation on July 18 using details from Searchlight Cyber's technical disclosure, though ServiceNow says it has seen no evidence tied to its own hosted instances.
AWS Kiro IDE: Hidden Web Text Could Rewrite Config and Execute Code (CVE-2026-10591)
Summary: Researchers showed that one-pixel hidden text on a webpage could make AWS's Kiro agentic IDE rewrite its own MCP configuration file and launch attacker-controlled code, bypassing the tool's approval-prompt security boundary entirely; the popup asked for approval but reloaded the malicious config regardless. AWS patched the underlying class of bug as CVE-2026-10591 (CVSS 8.8) in the 0.11 series, though this specific mcp.json chain was a separate, newly reported issue.
Zimbra Patches Critical SNMP Command Injection Plus Four XSS Flaws
Summary: Zimbra 10.1.20 fixes a critical command injection in the SNMP monitoring component (triggered when SNMP notifications are enabled) along with four stored/reflected XSS flaws in the Classic Web Client and a mail-forwarding restriction bypass (CVE-2026-50055) that let authenticated users exfiltrate mail despite forwarding restrictions. None are confirmed exploited yet, but Zimbra XSS bugs have a history of in-the-wild abuse.
Executive Order Requires Defense Contractors to Map Software Supply Chains
Summary: A new executive order directs the Department of War to require defense contractors, including subcontractors at every tier, to submit an "indentured Bill of Materials" tracing software, firmware, and physical components back to origin, with implementing regulations due within roughly 270 days. Significant supply chain risks must be reported to DoW within 15 days of vetting.
No AD/Entra/Exchange-specific developments today beyond the HollowGraph Graph API abuse and SharePoint machine key theft covered above; both warrant Entra ID conditional access and credential rotation review regardless.
N-Day Exploitation Is Compressing to N-Hour
Summary: Anthropic's red team had Claude Mythos Preview turn 18 Firefox patch diffs into 8 working exploits, the first landing under an hour after Mozilla shipped the fix, and 18 of 21 Windows kernel bugs into PoC crashes from stripped binaries alone, including one Microsoft had rated "Exploitation Unlikely." Verizon's 2026 DBIR puts median time-to-fix for known-exploited flaws at 43 days; the gap between patch-speed and exploit-speed is the core risk now.
LLM-Based Vulnerability Triage Still Produces High False-Positive Rates
Summary: Testing across a dozen application-scanning tools found over 60 percent of flagged vulnerabilities are false positives, unreachable, or low severity, and current LLMs have not meaningfully improved this without deep organizational and code context, per Pixee's CTO. Separately, Google DeepMind launched Gemini 3.5 Flash Cyber for governments and trusted partners via CodeMender, claiming it outperformed Claude Opus 4.6 on vulnerability discovery in tests against Chrome and Safari, and Ivanti detailed using LLMs (including Claude) to both find and auto-remediate SAST/DAST findings, crediting an LLM with discovering CVE-2026-10520, a maximum-severity Ivanti Sentry flaw (KEV, EPSS 99 percent).
OpenSSL fixed HollowByte (CVE pending), a DoS flaw where 11 bytes of crafted handshake data could force a server to allocate up to 128KB of memory per request; fixed in 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21. CISA published six Siemens ICS advisories this week (CADRA, SIDIS Secured SmartPlug, IAM Client across COMOS/Solid Edge/Teamcenter/Simcenter, Opcenter X, RUGGEDCOM APE1808 with Palo Alto NGFW) covering zlib, OpenSSL, OpenSSH, and PAN-OS bundled component flaws; vendor fixes are available for each. Rockwell Automation patched three Studio 5000 Logix Designer flaws (path traversal and two RCE/privilege issues, CVE-2026-9108/9127/9128) and a DoS in 1718/1719-AENTR I/O modules (CVE-2026-9140); upgrades available for all.
Multiple stories today point to the same shift: the gap between disclosure and exploitation has collapsed from weeks to hours, driven by both AI-assisted reverse engineering and low-effort mass scanning of newly disclosed CVEs (WordPress, SharePoint, ServiceNow all saw exploitation within days of PoC release). Ransomware growth is being driven by ecosystem fragmentation and externally-visible exposure rather than novel AI tradecraft, meaning attack-surface reduction still beats awareness training as a control.