# Today's Top Stories

July 22, 2026

  1. 1
    0
    BleepingComputer general Jul 21
    Critical SharePoint RCE flaw exploited to steal machine keys

    CVE-2026-50522, a critical (CVSS 9.8) deserialization RCE flaw in Microsoft SharePoint Server, is being actively exploited to steal machine keys — allowing attackers to maintain persistent access even after patching. The technique is particularly dangerous because machine key theft enables forging ViewState tokens and achieving RCE on patched servers, meaning remediation requires key rotation in addition to patching.

  2. 2
    0
    BleepingComputer general Jul 21
    Critical wp2shell WordPress flaws exploited to install webshells

    Two critical WordPress Core vulnerabilities — CVE-2026-63030 and CVE-2026-60137, dubbed 'wp2shell' — are being chained by attackers to achieve unauthenticated RCE, deploy persistent webshells, and install malicious plugins. Mass scanning began within hours of a public exploit being released, and exploitation was confirmed by early Saturday morning UTC, making immediate patching urgent for the roughly 40% of websites running WordPress.

  3. 3
    0
    The Hacker News general Jul 21
    Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

    Arctic Wolf Labs confirmed that Qilin (aka Agenda) ransomware operators exploited CVE-2026-0257 (CVSS 7.8), a Palo Alto Networks PAN-OS authentication bypass affecting GlobalProtect portal and gateway, in multiple intrusions during June 2026. This is a significant escalation, as a high-severity VPN perimeter flaw is now being used as initial access for ransomware deployment at scale.

  4. 4
    0
    BleepingComputer general Jul 20
    SonicWall SMA1000 flaws exploited as zero-days to push custom malware

    Two SonicWall SMA1000 zero-days — CVE-2026-15409 and CVE-2026-15410 — were exploited for weeks before patches were available by threat actor UTA0533 (tracked by Volexity), who installed custom malware on vulnerable VPN appliances. Pre-patch exploitation of VPN appliances for custom implant delivery represents a high-impact supply chain risk for enterprise network perimeters.

  5. 5
    0
    The Hacker News general Jul 21
    Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

    CVE-2026-6875 (CVSS 9.5), a sandbox escape vulnerability in the ServiceNow AI Platform allowing unauthenticated remote code execution, was observed being actively exploited in the wild just days after public disclosure, per Defused Cyber. ServiceNow's broad enterprise deployment as an IT service management platform makes this a high-priority patch for organizations running the AI Platform.

  6. 6
    0
    BleepingComputer general Jul 21
    FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

    The 'FakeGit' campaign has weaponized 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, accumulating over 14 million downloads. The scale of this supply chain-style attack on the developer ecosystem makes it a critical threat for security teams monitoring open-source dependency risk and developer endpoint compromise.

  7. 7
    0
    BleepingComputer general Jul 21
    Police dismantle Kratos phishing platform, arrest developer

    A joint German-U.S. law enforcement operation dismantled the Kratos phishing-as-a-service (PhaaS) platform and arrested its developer in Indonesia. Kratos had global reach providing turnkey phishing infrastructure to cybercriminals, and the takedown marks a significant disruption to the PhaaS ecosystem following prior actions against platforms like LabHost and Darcula.

  8. 8
    0
    The Hacker News general Jul 21
    New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

    Sysdig researchers linked a second attack on a Langflow server to JADEPUFFER, an autonomous AI agent operator, which deployed ENCFORGE — a new Go-compiled ransomware that specifically targets AI infrastructure including model weights, vector indexes, and training datasets. This represents an emerging threat class where agentic AI attackers deploy ransomware tailored to destroy AI assets rather than traditional business data.

  9. 9
    0
    BleepingComputer general Jul 20
    Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

    Researchers discovered sandbox escape vulnerabilities in four AI coding tools — Cursor, Codex (OpenAI), Gemini CLI, and Antigravity — by inducing AI agents to write files that trusted host tools subsequently execute, resulting in host-level code execution. Multiple CVEs were issued and patches released, but the attack class exposes a systemic trust boundary problem in agentic coding environments.

  10. 10
    0
    The Hacker News general Jul 20
    HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

    Group-IB disclosed HollowGraph, a new espionage implant that uses a hijacked Microsoft 365 calendar as its C2 channel, embedding operator commands and exfiltrating stolen files as attachments on calendar events dated to the year 2050. By routing all activity through legitimate Microsoft Graph API calls, the malware blends into normal Microsoft 365 traffic and evades network-based detection.