# Today's Top Stories
July 22, 2026
-
1BleepingComputer general Jul 21Critical SharePoint RCE flaw exploited to steal machine keys
CVE-2026-50522, a critical (CVSS 9.8) deserialization RCE flaw in Microsoft SharePoint Server, is being actively exploited to steal machine keys — allowing attackers to maintain persistent access even after patching. The technique is particularly dangerous because machine key theft enables forging ViewState tokens and achieving RCE on patched servers, meaning remediation requires key rotation in addition to patching.
-
2BleepingComputer general Jul 21Critical wp2shell WordPress flaws exploited to install webshells
Two critical WordPress Core vulnerabilities — CVE-2026-63030 and CVE-2026-60137, dubbed 'wp2shell' — are being chained by attackers to achieve unauthenticated RCE, deploy persistent webshells, and install malicious plugins. Mass scanning began within hours of a public exploit being released, and exploitation was confirmed by early Saturday morning UTC, making immediate patching urgent for the roughly 40% of websites running WordPress.
-
3The Hacker News general Jul 21Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Arctic Wolf Labs confirmed that Qilin (aka Agenda) ransomware operators exploited CVE-2026-0257 (CVSS 7.8), a Palo Alto Networks PAN-OS authentication bypass affecting GlobalProtect portal and gateway, in multiple intrusions during June 2026. This is a significant escalation, as a high-severity VPN perimeter flaw is now being used as initial access for ransomware deployment at scale.
-
4BleepingComputer general Jul 20SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two SonicWall SMA1000 zero-days — CVE-2026-15409 and CVE-2026-15410 — were exploited for weeks before patches were available by threat actor UTA0533 (tracked by Volexity), who installed custom malware on vulnerable VPN appliances. Pre-patch exploitation of VPN appliances for custom implant delivery represents a high-impact supply chain risk for enterprise network perimeters.
-
5The Hacker News general Jul 21Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
CVE-2026-6875 (CVSS 9.5), a sandbox escape vulnerability in the ServiceNow AI Platform allowing unauthenticated remote code execution, was observed being actively exploited in the wild just days after public disclosure, per Defused Cyber. ServiceNow's broad enterprise deployment as an IT service management platform makes this a high-priority patch for organizations running the AI Platform.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6BleepingComputer general Jul 21FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
The 'FakeGit' campaign has weaponized 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, accumulating over 14 million downloads. The scale of this supply chain-style attack on the developer ecosystem makes it a critical threat for security teams monitoring open-source dependency risk and developer endpoint compromise.
-
7BleepingComputer general Jul 21Police dismantle Kratos phishing platform, arrest developer
A joint German-U.S. law enforcement operation dismantled the Kratos phishing-as-a-service (PhaaS) platform and arrested its developer in Indonesia. Kratos had global reach providing turnkey phishing infrastructure to cybercriminals, and the takedown marks a significant disruption to the PhaaS ecosystem following prior actions against platforms like LabHost and Darcula.
-
8The Hacker News general Jul 21New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Sysdig researchers linked a second attack on a Langflow server to JADEPUFFER, an autonomous AI agent operator, which deployed ENCFORGE — a new Go-compiled ransomware that specifically targets AI infrastructure including model weights, vector indexes, and training datasets. This represents an emerging threat class where agentic AI attackers deploy ransomware tailored to destroy AI assets rather than traditional business data.
-
9BleepingComputer general Jul 20Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Researchers discovered sandbox escape vulnerabilities in four AI coding tools — Cursor, Codex (OpenAI), Gemini CLI, and Antigravity — by inducing AI agents to write files that trusted host tools subsequently execute, resulting in host-level code execution. Multiple CVEs were issued and patches released, but the attack class exposes a systemic trust boundary problem in agentic coding environments.
-
10The Hacker News general Jul 20HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
Group-IB disclosed HollowGraph, a new espionage implant that uses a hijacked Microsoft 365 calendar as its C2 channel, embedding operator commands and exfiltrating stolen files as attachments on calendar events dated to the year 2050. By routing all activity through legitimate Microsoft Graph API calls, the malware blends into normal Microsoft 365 traffic and evades network-based detection.