Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-20
Daily Brief·2026-07-20·18 Items

Rosetta Daily · Jul 20, 2026

Generated automatically · ~14 sources scanned (via WebSearch) · 18 items selected

Critical Vulnerabilities

  • wp2shell — WordPress Core Pre-Auth RCE — WordPress Core, CVE-2026-63030 (REST API batch-route confusion) + CVE-2026-60137 (SQLi), critical ⚠️
    Chained, an anonymous HTTP request reaches code execution on a stock WordPress install — no plugin or account required. Code-exec path requires no persistent object cache (default installs qualify). Public PoC is on GitHub; no confirmed in-the-wild exploitation as of July 18. Patch to 6.9.5 / 7.0.2; verify the forced auto-update actually landed.
    The Hacker News · Rapid7 · BleepingComputer

  • Microsoft SharePoint Server Unauth RCE — SharePoint Server (Subscription Edition, 2019, 2016), CVE-2026-58644, CVSS 9.8 🔴🔥⚠️
    Critical deserialization-of-untrusted-data flaw weaponized as a zero-day before patches. Post-exploitation includes stealing IIS machine keys for persistence. See KEV section below.
    The Hacker News · Rapid7

  • Microsoft July Patch Tuesday — record 570+ flaws — Microsoft, multiple CVEs, incl. 2 exploited zero-days 🔴🔥
    One of the largest Patch Tuesdays ever (reports of 570–622 CVEs depending on count). Two actively exploited zero-days: CVE-2026-56164 (SharePoint EoP) and CVE-2026-56155 (AD FS EoP), plus a publicly disclosed BitLocker bypass.
    BleepingComputer · ZDI

In-the-Wild Exploitation (CISA KEV)

  • CVE-2026-58644 SharePoint RCE added to KEV 🔥 — FCEB remediation deadline was July 19, 2026. CISA confirmed active exploitation alongside CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164; urged blocking external access to SharePoint Central Admin and not exposing servers to the internet.
    CISA

  • July 14 KEV batch (4 CVEs) 🔥 — SonicWall SMA1000, Microsoft SharePoint, and AD FS flaws added after evidence of active exploitation.
    SecurityAffairs

  • LegacyHive — Windows ProfSvc EoP PoC ⚠️ — Public PoC for a Windows User Profile Service privilege-escalation flaw that reportedly still works after the July 2026 update, across all supported desktop and server versions. Watch for weaponization.
    The Hacker News

Vendor Advisories

  • Microsoft— See Patch Tuesday above; prioritize SharePoint, AD FS, and the BitLocker bypass.
  • WordPress 6.9.5 / 7.0.2— Forced auto-updates enabled for affected versions (6.9.0–6.9.4, 7.0.0–7.0.1); admins should confirm the installed build.
    Cloudflare

Web Security Research

  • PortSwigger — new race-condition classes & single-packet attacks — PortSwigger Research's Black Hat USA work introduces new classes of web race conditions plus tooling in Burp Suite; practical write-up on applying the techniques.
    PortSwigger Research

  • Project Zero — Pixel 9 zero-click to root — A two-exploit chain going from zero-click context to root on Android, involving a Dolby 0-click bug that spanned all of Android until the January 2026 patch.
    Project Zero

AI Security

  • Prompt injection cementing as a structural LLM problem ⚠️ — 2026 research consensus is that prompt injection may not be fully patchable. Pathade's taxonomy of 1,400+ jailbreak prompts shows strong cross-model transferability; Capital One's "Adaptive Instruction Composition" more than doubled attack success rates against Mistral-7B and Llama in simulation. OpenAI continues to call it a "frontier security challenge."
    Astra guide · arXiv (agentic PI)

  • HiddenLayer 2026 AI Threat Landscape Report — Flags the inflection point where agentic AI takes actions (not just outputs), expanding the attack surface for enterprises deploying autonomous workflows.
    HiddenLayer Research

Threat Intelligence

  • North Korea "Contagious Interview" — SVG steganography — DPRK actors hide malicious payloads inside SVG image files, delivered via fake job postings and coding challenges.
    The Hacker News

  • GoSerpent — new malware in Southeast Asia — Previously undocumented malware targeting government and diplomatic entities in SE Asia since late 2025; uncovered by Kaspersky in Feb 2026.
    The Hacker News

  • Intel 471 July update — APT surge — Silver Fox (Taiwan, Gh0stCringe/HoldingHands RATs), Black Basta remnants resurfacing as CACTUS/BlackSuit (finance & construction), PathWiper destructive malware in Ukraine, and Iranian APT33/34/39 activity against critical infrastructure.
    Industrial Cyber

  • TfL 2024 hack — sentencing — Owen Flowers (18) and Thalha Jubair (20) each sentenced to 5.5 years at Woolwich Crown Court (July 16, 2026) for the 2024 Transport for London breach.
    The Hacker News

Chinese-Language Community Picks

  • FreeBuf weekly (July)— covering June's must-patch vulnerability list, the first fully automated AI ransomware attack, and a major APT warning. Also includes the Linux kernel traffic-control subsystem flaw (CVE-2026-46331, local privilege escalation) and "AI agent finds 21 0-days in FFmpeg (some dormant for 23 years)".
    FreeBuf vulnerabilities

Ransomware Today

5 new RansomLook posts in the last 24h across 4 groups (krybit, gunra, blackout, qilin). ⭐ 2 watchlist hits — both qilin, which posted two victims in one day including City Ambulance Service (emergency medical) and Famesa. Consistent with qilin's ~16% market share.
Full victim table

Bug Bounty

The Bug Bounty deep-dive is now a separate daily update (analysis + themed recent disclosures).
View the Bug Bounty daily section


AI Frontier

OpenAI

  • GPT-5.6 (Sol / Terra / Luna) + ChatGPT Work(July 9) — Three tiers publicly released; Sol reportedly 54% more token-efficient on agentic coding. ChatGPT Work blends Codex + ChatGPT to carry out multi-hour jobs across apps and files.
    Axios

Anthropic

  • Claude Reflect, Claude for Teachers, Cowork expansion(July) — Reflect usage-analytics dashboard (beta, Free/Pro/Max); free premium Claude for verified US K-12 teachers; Cowork expanded to mobile/web with scheduled tasks and mobile approvals.
    Chalkbeat· TechCrunch

Google DeepMind / AI

  • Gemini 3.5 Pro — targeted July 17 after full rebuild(unconfirmed officially) — Ground-up architecture redesign (2M-token context, "Deep Think" reasoning layer) amid a high-profile DeepMind talent exodus; ~$225B wiped off Alphabet in one session.
    The Agent Report

🛡 = security-relevant


Failed Sources (if any)

  • Direct RSS/Atom/HTML feed fetches skipped (provenance gate + sandbox network block). Brief assembled via WebSearch per category + RansomLook API. Feed-level timestamps approximate.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 19, 2026
Next →
Rosetta Daily · Jul 21, 2026