Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-22
Daily Brief·2026-07-22·20 Sources·17 Items

Rosetta Daily · Jul 22, 2026

Generated automatically · 20+ sources scanned · 17 items selected

Critical Vulnerabilities

  • wp2shell — WordPress Core Pre-Auth RCE — WordPress, CVE-2026-63030 + CVE-2026-60137 ⚠️
    Two-bug chain in default WordPress core, no plugins required: a REST API batch-route confusion in WP_REST_Server::serve_batch_request_v1() (/wp-json/batch/v1, introduced in 6.9) smuggles a rogue parameter into WP_Query, driving a SQL injection in author__not_in (present since 6.8) all the way to code execution. Affected: 6.9.0–6.9.4 and 7.0.0–7.0.1 (full RCE chain); 6.8.0–6.8.5 carry the SQLi only (fixed in 6.8.6). Patch to 6.9.5 / 7.0.2+. Disclosed 2026-07-17; public PoCs appeared within hours and multiple vendors confirm in-the-wild exploitation.
    The Hacker News · Tenable FAQ · CyCognito · SOCRadar

  • SonicWall SMA1000 — Chained Zero-Days to Root — SonicWall, CVE-2026-15409 (CVSS 10.0) + CVE-2026-15410 🔴⚠️🔥
    Unauthenticated SSRF against the /wsproxy endpoint opens WebSocket tunnels to localhost services; a path traversal in execRemoveHotfix then executes an attacker-planted /tmp file as root. Exploited since at least 2026-06-22 by UTA0533, weeks before the 07-14 disclosure. Affects SMA 6210 / 7210 / 8200v; fixed in hotfixes 12.4.3-03453 and 12.5.0-02835.
    Volexity · Rapid7 · BleepingComputer

  • SharePoint Deserialization RCE Under Attack — Microsoft, CVE-2026-50522, CVSS 9.8 🔴⚠️🔥
    Deserialization of untrusted data in Microsoft Office SharePoint allowing unauthenticated network code execution; reporting places it under active exploitation as of 2026-07-21. Adds to an already-ugly SharePoint cluster (CVE-2026-58644 / -56164 / -45659 / -32201) that CISA flagged for on-prem hardening last week.
    CISA hardening alert · The Hacker News

  • ServiceNow AI Platform Pre-Auth RCE — now with public PoC — ServiceNow, CVE-2026-6875 ⚠️🔥
    Sandbox-escape RCE confirmed exploited in the wild by Defused; full instance takeover (read tables, create admin accounts, run commands on linked MID Servers). Self-hosted fix shipped 07-13 — carried over from yesterday because the exploitation reporting firmed up.
    BleepingComputer · Help Net Security

  • Palo Alto PAN-OS Flaw → Qilin Ransomware — Palo Alto Networks 🔴⚠️
    Attackers are exploiting a high-severity PAN-OS vulnerability for initial access into corporate networks and deploying Qilin ransomware. Edge-device-to-encryption remains the most reliable 2026 attack chain — verify PAN-OS patch levels today.
    BleepingComputer

In-the-Wild Exploitation (CISA KEV)

  • July KEV additions keep stacking 🔥
    Multiple batches this month: 07-07 (3 — JoomShaper SP Page Builder CVE-2026-48908, Langflow CVE-2026-55255, Joomlack Page Builder CVE-2026-56290), 07-10 (2 — iCagenda CVE-2026-48939, Balbooa Forms CVE-2026-56291), 07-13 (1 — Cisco IOS CSRF CVE-2008-4128, an 18-year-old bug back in circulation), 07-14 (4 — SonicWall SMA1000, SharePoint, AD FS). Prioritize internet-facing assets under BOD 22-01.
    CISA KEV catalog · 07-13 alert

  • CVE-2026-56155 — AD FS privilege escalation ⚠️🔥
    Insufficient access-control granularity lets a low-privileged local attacker reach administrative privileges with no user interaction and low attack complexity. One of the exploited zero-days in the record July Patch Tuesday (570–622 CVEs depending on the tracker, 59 rated Critical).
    ZDI review · Malwarebytes

Vendor Advisories

  • Microsoft — emergency fix for Dell shutdown regression
    Out-of-band updates released to fix July 2026 Windows 11 security updates causing some Dell PCs to shut down. Microsoft also signalled it expects more Windows security updates driven by AI-discovered flaws — a quiet but consequential shift in patch cadence.
    BleepingComputer · MSRC

  • Windows zero-day — unofficial micropatch available
    Free unofficial patches are circulating for a recently disclosed Windows privilege-escalation zero-day that works on fully updated systems. Treat as a stopgap; watch for the official fix.
    BleepingComputer

Web Security Research

  • CSS/HTML-based email account takeover — PortSwigger Research
    Novel techniques for compromising email accounts using nothing but CSS and HTML, including end-to-end account takeovers demonstrated against multiple major providers. Strong candidate for a lab reproduction.
    PortSwigger Research · Black Hat USA writeups

  • "HTTP/1.1 must die" — the desync endgame
    Expect-header quirks plus early-response gadgets turn 0.CL deadlocks into reliable double-desync request smuggling → response queue poisoning and cross-tenant cache/content hijacking. Notably, an autonomous system was used to invent new desync triggers and exploit live sites at scale, reportedly compromising banks, security vendors and government infrastructure.
    PortSwigger · Top 10 web hacking techniques of 2025

AI Security

  • Hugging Face breached by an autonomous AI agent system
    The world's largest AI model repository disclosed that an autonomous agent framework executed 17,000+ logged actions across a weekend: a malicious dataset triggered two code-execution paths in the dataset-processing pipeline, then the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across multiple internal clusters. Public models, Spaces and published packages show no tampering; partner/customer data exposure still under investigation. HF shut the code paths, evicted the attacker, rebuilt nodes from scratch, rotated all credentials, engaged external forensics and notified law enforcement. This is one of the first documented AI-led— not AI-assisted — intrusions.
    BleepingComputer · The Hacker News · Axios · SecurityAffairs

  • Prompt injection: agent tool-input injection is the unsolved core
    OWASP's 2026 LLM report puts prompt injection up 340% YoY — the fastest-growing attack category. Agent tool-input injection succeeds 84% of the time in lab testing. Real-world: in April 2026, 26 of 428 tested LLM routers rewrote tool calls, exfiltrated secrets or redirected transactions — one drained a ~$500K crypto wallet. Root cause is unchanged: LLMs have no built-in boundary between instructions and data.
    Microsoft Security Blog — when prompts become shells · AI agent attack timeline

  • China-linked campaign automated with Claude Code and DeepSeek
    Check Point tracked a China-linked operation using commercial coding agents to automate attacks on government and financial organizations. Check Point's 2026 AI Security Report frames the shift bluntly: AI has moved from attack to active across live intrusions and malware development.

Threat Intelligence

  • HOLLOWGRAPH — Microsoft 365 calendar as a C2 channel
    Windows implant that turns M365 calendar events into a covert command-and-control channel. Living-off-trusted-services C2 that blends into normal Graph API traffic — worth a detection-engineering pass against calendar-event write patterns.
    BleepingComputer

  • ShinyHunters — OAuth consent abuse against Salesforce
    Voice phishing pushes victims to authorize lookalike OAuth applications, granting persistent API access to Salesforce environments without ever touching a password. Audit connected-app consent grants.
    Check Point Research

  • CylindricalCanine / GoldenEyeDog → DigiCert portal compromise
    A subgroup of the Chinese cybercrime collective GoldenEyeDog has been linked to DigiCert's April 2026 support-portal compromise, where stolen code-signing certificates led to 60 revocations. Supply-chain trust erosion at the CA layer.
    Check Point Research

  • APT-C-60 — SpyGlace against Japan, still running
    Spear-phishing with Proton Drive links or weaponized RAR archives; ongoing throughout 2026.
    Check Point Research

  • Estée Lauder breach via Oracle E-Business Suite
    Customer notifications going out after attackers exploited an Oracle EBS flaw used for HR operations. Separately, gig platform Paidwork is linked to a breach affecting 23.3M accounts.
    BleepingComputer


Chinese-Language Community Picks

  • OpenClaw becomes a new supply-chain poisoning target— per the FreeBuf weekly, 341 malicious skill modulesdistributed Atomic Stealerthrough ClawHub, with an infection rate of roughly 12%; attackers embedded payloads in SKILL.mdto steal data, and there are links to ransomware crews. The "skill/plugin marketplace" of AI agents is becoming a new supply-chain attack surface — this thread bears directly on how skills and plugins are used in this workbench.
    FreeBuf weekly (repost)· FreeBuf supply-chain security column
  • Other FreeBuf / Anquanke / Xianzhi Community searches in this window returned mostly stale index results; no additional new items for 7/21–7/22 were confirmed. Check the FreeBuf vulnerabilities channeland Anquankedirectly.

Ransomware Today

RansomLook (days=1) returned 5 posts / 4 groups, 2 hitting the watchlist — both qilin (Famesa, manufacturing/defense; City Ambulance Service, healthcare/EMS), plus krybit → euroins.bg, gunra → a US law firm, blackout → bluebellgroup.com. ⚠️ Same five posts as yesterday (timestamps still 07-18/07-19) — the feed appears stale rather than genuinely quiet; RSS fallback returned binary. Corroborating signal from the news side: PAN-OS exploitation is currently delivering Qilin.
Full victim table

Bug Bounty

The Bug Bounty track now updates daily on its own (deep-dive analysis + recent disclosures grouped by theme).
Open the Bug Bounty daily track


AI Frontier

OpenAI

  • $42.6B stake offered to Washington— an unusual government-equity arrangement; watch for the policy and procurement knock-ons.
  • Reporting notes ChatGPT voice mode still runs on a markedly older, weaker modelwith an April 2024 knowledge cutoff — a reminder that "the product" and "the frontier model" are not the same thing when you threat-model a deployment.
    ThursdAI July 2026 releases

Anthropic

  • Claude Sonnet 5shipped and is now the default for Free/Pro.
  • Coefficient Bio(computational biology) acquired for ~$400M all-stock; Andrej Karpathyjoined to work on frontier LLMs.
  • Interpretability: using a technique called the J-lens, researchers identified a small internal subspace of ~25 active concepts behaving like the "global workspace" from consciousness neuroscience — relevant to anyone building model-internals-based safety monitors.
    Anthropic news tracker

Google DeepMind / AI

  • Gemini Robotics-ER 1.6 into Boston Dynamics Spot— partnership with Google Cloud and DeepMind covering the Spot robot dog and the Orbit AI visual-inspection platform. Embodied agents inherit every agent security problem, plus physical consequences.
    ThursdAI

Cross-vendor safety note

  • The Future of Life Institute's latest AI Safety Indexfinds leading developers have weakened or removedprior commitments. Anthropic ranks first with a C+; OpenAI and Google DeepMind both get C.

Failed Sources (if any)

  • RansomLook RSS fallback(https://www.ransomlook.io/rss.xml) — returned binary/unparseable content; API ?days=1used instead (and it returned stale data, see above).
  • Direct RSS/Atom feed fetching(NVD, GitHub Advisories, MSRC, PortSwigger, Project Zero, Trail of Bits, Detectify, THN, BleepingComputer, Krebs, Mandiant, DFIR Report, CrowdStrike, Unit 42, FreeBuf, 安全客, arXiv cs.CR, OpenAI/DeepMind/Google AI feeds) — blocked by the WebFetch provenance gate (feed URLs read from sources.yamlare not in provenance) and the sandbox has no outbound network. Worked around with per-category WebSearch, so coverage is intact but feed-level timestamps are approximate.
  • 先知社区 / FreeBuf / 安全客— searches returned mostly stale indexed results; only one recent item confirmed (see Chinese-community note in the zh edition).

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 21, 2026
Next →
Rosetta Daily · Jul 23, 2026
aid
operator

Check Point Research