Rosetta Daily · Jul 20, 2026
Generated automatically · ~14 sources scanned (via WebSearch) · 18 items selected
Critical Vulnerabilities
-
wp2shell — WordPress Core Pre-Auth RCE — WordPress Core, CVE-2026-63030 (REST API batch-route confusion) + CVE-2026-60137 (SQLi), critical ⚠️
Chained, an anonymous HTTP request reaches code execution on a stock WordPress install — no plugin or account required. Code-exec path requires no persistent object cache (default installs qualify). Public PoC is on GitHub; no confirmed in-the-wild exploitation as of July 18. Patch to 6.9.5 / 7.0.2; verify the forced auto-update actually landed.
The Hacker News · Rapid7 · BleepingComputer -
Microsoft SharePoint Server Unauth RCE — SharePoint Server (Subscription Edition, 2019, 2016), CVE-2026-58644, CVSS 9.8 🔴🔥⚠️
Critical deserialization-of-untrusted-data flaw weaponized as a zero-day before patches. Post-exploitation includes stealing IIS machine keys for persistence. See KEV section below.
The Hacker News · Rapid7 -
Microsoft July Patch Tuesday — record 570+ flaws — Microsoft, multiple CVEs, incl. 2 exploited zero-days 🔴🔥
One of the largest Patch Tuesdays ever (reports of 570–622 CVEs depending on count). Two actively exploited zero-days: CVE-2026-56164 (SharePoint EoP) and CVE-2026-56155 (AD FS EoP), plus a publicly disclosed BitLocker bypass.
BleepingComputer · ZDI
In-the-Wild Exploitation (CISA KEV)
-
CVE-2026-58644 SharePoint RCE added to KEV 🔥 — FCEB remediation deadline was July 19, 2026. CISA confirmed active exploitation alongside CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164; urged blocking external access to SharePoint Central Admin and not exposing servers to the internet.
CISA -
July 14 KEV batch (4 CVEs) 🔥 — SonicWall SMA1000, Microsoft SharePoint, and AD FS flaws added after evidence of active exploitation.
SecurityAffairs -
LegacyHive — Windows ProfSvc EoP PoC ⚠️ — Public PoC for a Windows User Profile Service privilege-escalation flaw that reportedly still works after the July 2026 update, across all supported desktop and server versions. Watch for weaponization.
The Hacker News
Vendor Advisories
- Microsoft— See Patch Tuesday above; prioritize SharePoint, AD FS, and the BitLocker bypass.
- WordPress 6.9.5 / 7.0.2— Forced auto-updates enabled for affected versions (6.9.0–6.9.4, 7.0.0–7.0.1); admins should confirm the installed build.
Cloudflare
Web Security Research
-
PortSwigger — new race-condition classes & single-packet attacks — PortSwigger Research's Black Hat USA work introduces new classes of web race conditions plus tooling in Burp Suite; practical write-up on applying the techniques.
PortSwigger Research -
Project Zero — Pixel 9 zero-click to root — A two-exploit chain going from zero-click context to root on Android, involving a Dolby 0-click bug that spanned all of Android until the January 2026 patch.
Project Zero
AI Security
-
Prompt injection cementing as a structural LLM problem ⚠️ — 2026 research consensus is that prompt injection may not be fully patchable. Pathade's taxonomy of 1,400+ jailbreak prompts shows strong cross-model transferability; Capital One's "Adaptive Instruction Composition" more than doubled attack success rates against Mistral-7B and Llama in simulation. OpenAI continues to call it a "frontier security challenge."
Astra guide · arXiv (agentic PI) -
HiddenLayer 2026 AI Threat Landscape Report — Flags the inflection point where agentic AI takes actions (not just outputs), expanding the attack surface for enterprises deploying autonomous workflows.
HiddenLayer Research
Threat Intelligence
-
North Korea "Contagious Interview" — SVG steganography — DPRK actors hide malicious payloads inside SVG image files, delivered via fake job postings and coding challenges.
The Hacker News -
GoSerpent — new malware in Southeast Asia — Previously undocumented malware targeting government and diplomatic entities in SE Asia since late 2025; uncovered by Kaspersky in Feb 2026.
The Hacker News -
Intel 471 July update — APT surge — Silver Fox (Taiwan, Gh0stCringe/HoldingHands RATs), Black Basta remnants resurfacing as CACTUS/BlackSuit (finance & construction), PathWiper destructive malware in Ukraine, and Iranian APT33/34/39 activity against critical infrastructure.
Industrial Cyber -
TfL 2024 hack — sentencing — Owen Flowers (18) and Thalha Jubair (20) each sentenced to 5.5 years at Woolwich Crown Court (July 16, 2026) for the 2024 Transport for London breach.
The Hacker News
Chinese-Language Community Picks
- FreeBuf weekly (July)— covering June's must-patch vulnerability list, the first fully automated AI ransomware attack, and a major APT warning. Also includes the Linux kernel traffic-control subsystem flaw (CVE-2026-46331, local privilege escalation) and "AI agent finds 21 0-days in FFmpeg (some dormant for 23 years)".
FreeBuf vulnerabilities
Ransomware Today
5 new RansomLook posts in the last 24h across 4 groups (krybit, gunra, blackout, qilin). ⭐ 2 watchlist hits — both qilin, which posted two victims in one day including City Ambulance Service (emergency medical) and Famesa. Consistent with qilin's ~16% market share.
Full victim table
Bug Bounty
The Bug Bounty deep-dive is now a separate daily update (analysis + themed recent disclosures).
View the Bug Bounty daily section
AI Frontier
OpenAI
- GPT-5.6 (Sol / Terra / Luna) + ChatGPT Work(July 9) — Three tiers publicly released; Sol reportedly 54% more token-efficient on agentic coding. ChatGPT Work blends Codex + ChatGPT to carry out multi-hour jobs across apps and files.
Axios
Anthropic
- Claude Reflect, Claude for Teachers, Cowork expansion(July) — Reflect usage-analytics dashboard (beta, Free/Pro/Max); free premium Claude for verified US K-12 teachers; Cowork expanded to mobile/web with scheduled tasks and mobile approvals.
Chalkbeat· TechCrunch
Google DeepMind / AI
- Gemini 3.5 Pro — targeted July 17 after full rebuild(unconfirmed officially) — Ground-up architecture redesign (2M-token context, "Deep Think" reasoning layer) amid a high-profile DeepMind talent exodus; ~$225B wiped off Alphabet in one session.
The Agent Report
🛡 = security-relevant
Failed Sources (if any)
- Direct RSS/Atom/HTML feed fetches skipped (provenance gate + sandbox network block). Brief assembled via WebSearch per category + RansomLook API. Feed-level timestamps approximate.
Sources used: see intel/sources.yaml