Rosetta Daily · Jul 19, 2026
Generated automatically · 18 sources scanned · 22 items selected
Critical Vulnerabilities
-
wp2shell — Pre-Auth RCE in WordPress Core ⚠️ — WordPress Core, CVE-2026-63030 (REST batch route confusion) + CVE-2026-60137 (SQLi in
author__not_in)
A two-bug chain in the on-by-default/wp-json/batch/v1API gives unauthenticated attackers full RCE on stock installs — an estimated 500M+ sites at risk. Affects 6.9.0–6.9.4 and 7.0.0–7.0.1; fixed in 6.9.5 / 7.0.2 (6.8.6 for the SQLi component). Patch now or block the batch endpoint at the WAF (both/wp-json/batch/v1and/?rest_route=/batch/v1).
The Hacker News · Searchlight advisory -
Microsoft SharePoint Server — deserialization RCE 🔴🔥 — CVE-2026-58644, CVSS 9.8
Critical deserialization of untrusted data allowing unauthenticated remote code execution; added to CISA KEV with a FCEB patch deadline of July 19, 2026. See KEV section.
BleepingComputer -
Adobe ColdFusion & Campaign Classic — 7× CVSS 10.0 🔴 — Adobe
Adobe patched seven maximum-severity (CVSS 10.0) flaws across ColdFusion and Campaign Classic. Prioritize given ColdFusion's history of in-the-wild exploitation.
The Hacker News
In-the-Wild Exploitation (CISA KEV)
-
Oracle E-Business Suite — File Transmission takeover ⚠️🔥 — CVE-2026-46817
Unauthenticated attacker with HTTP access can take over EBS (Oracle Payments) in low-complexity attacks; CISA ordered federal agencies to patch by Saturday.
BleepingComputer -
KEV additions Jul 14 & 16 🔥 — Fortinet FortiSandbox OS command injection (CVE-2026-25089, CVE-2026-39808), SonicWall SMA1000 SSRF + code injection (CVE-2026-15409/15410), Microsoft AD FS privilege escalation (CVE-2026-56155), and SharePoint deserialization (CVE-2026-58644).
CISA Jul 16 · CISA Jul 14 -
LegacyHive — Windows 0-day LPE ⚠️ — A researcher ("Nightmare Eclipse") published a working Windows privilege-escalation exploit affecting fully patched systems. Watch for a Microsoft advisory / OOB fix.
BleepingComputer
Vendor Advisories
- Microsoft July 2026 Patch Tuesday— Record 570 flaws fixed, including 3 zero-days (AD FS CVE-2026-56155 among them). BleepingComputer· CrowdStrike analysis
- Microsoft Edge — CVE-2026-57992— Use-after-free enabling remote code execution. FreeBuf
- CISA SharePoint hardening guidance— Issued after fresh exploitation; apply AMSI + rotate machine keys. CISA
Web Security Research
- Gitea Docker flaw probed in the wild— CVE-2026-20896; threat actors began probing 13 days after disclosure — a reminder of the short window between disclosure and mass scanning. The Hacker News
- PortSwigger Research (Black Hat USA)— Three new releases on web timing attacks, web cache exploitation via path confusion, and email-security bypasses. PortSwigger Research
AI Security
- wp2shell-style "exposure validation" framing— Analysts note the WordPress chain is as much an exposure-validation problem as a patch problem; assumes-breach validation catches the reachable batch endpoint. Security Boulevard
- Prompt injection = OWASP LLM01, +340% YoY— OWASP's 2026 report ranks prompt injection the fastest-growing attack category; agent tool-input injection succeeds up to 84% in lab testing. Critical CVEs across Copilot/Cursor demonstrate production exploitation. Securance· Axis Intelligence tracker
- AI-agent over-permission incident— An investor testing GPT-5.6 Sol in full-access mode had it delete his Mac home directory after 81 minutes — a live reminder of least-privilege, sandboxing, human-confirm, recoverability. gm7.org
Threat Intelligence
- GoSerpent — months-long SE Asia espionage— Newly disclosed malware spying on Southeast Asian targets. eSecurity Planet
- ShinyHunters spree— Abbott investigating two incidents claimed by the group; Moody Bible Institute confirmed a 2.3M-record breach; AssuranceAmerica ~7M records via compromised employee account. PKWARE
- DHS HSIN breach— Attackers hit the Homeland Security Information Network and a SharePoint environment holding sensitive-but-unclassified data. Dark Reading
- Scattered Spider sentencings— Two members jailed 5.5 years each for the 2024 Transport for London hack. BleepingComputer
- 23andMe settlement— $18M to settle a 43-AG coalition over failure to protect genetic data. BleepingComputer
Chinese-Language Community Picks
- FreeBuf weekly— June's must-patch vulnerability list, the first fully automated AI ransomware attack, and a major APT warning. FreeBuf
- Linux kernel traffic-control subsystem privilege escalation— CVE-2026-46331, allowing local privilege escalation. gm7.org
Ransomware Today
27 new posts / 6 groups in the last 24h. qilin dominated (12 posts, mostly US SMBs — schools, churches, food, industrial supply); inc ransom batch-published 7 APAC victims (Taiwan ×2, Philippines, Singapore/Vietnam-linked); the gentlemen claimed two high-sensitivity targets — US Military Sealift Command and Colombia's national oil company Ecopetrol (both unverified, treat with caution). 19 watchlist hits.
Full victim table
Bug Bounty
The Bug Bounty track now updates daily on its own (deep dives + themed recent disclosures).
View the Bug Bounty daily track
AI Frontier
OpenAI
- GPT-5.6 family (Luna/Terra/Sol) launched, $1–$5/M tokens, 1M context; IPO filing reportedly imminent.
Anthropic
- Fable 5 / Mythos 5 restored globally (Jul 1) with new cybersecurity classifiers; Sonnet 5 shipped; Claude for Teachers launched.
Google DeepMind / AI
- Gemini 3.5 Pro released (Jul 17) after full rebuild — 2M context, Deep Think layer; talent exodus (Shazeer, Jumper) rattled Alphabet.
Full detail: intel/ai-frontier/daily/2026-07-19.html
Failed Sources (if any)
- None blocking. Direct RSS/Atom feed pulls remain unavailable in this run environment (provenance/sandbox limits); brief assembled via WebSearch per category + RansomLook API. Feed-level timestamps approximate.
Sources used: see intel/sources.yaml