New exploit chains and exploitation activity, AI between autonomous capabilities and offensive use, cyber incidents and campaigns

Weekly Threats hor Telsy

Vulnerabilities: Pre-auth RCE exploit chain in WordPress and new evidence of in-the-wild exploitation

On July 17, 2026, WordPress released versions 6.9.5 and 7.0.2 to address two core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, which, when chained together, form the critical exploit chain known as wp2shell. The first vulnerability allows authorization checks on the REST API batch endpoint to be bypassed, while the second is a SQL Injection flaw in the WP_Query class. When combined, these vulnerabilities allow an unauthenticated attacker to achieve Remote Code Execution (RCE) on standard WordPress installations without requiring additional plugins. Just hours after the patches were released, a Proof-of-Concept (PoC) exploit was published. Although no in-the-wild (ITW) exploitation had initially been observed, attacks began within hours of the fixes becoming available, with mass scanning campaigns and confirmed compromises reported worldwide. Observed activity included credential hash extraction, administrative user enumeration, retrieval of credentials and authentication keys, installation of malicious plugins and PHP webshells, and ultimately unauthorized access to administration panels and persistence on compromised systems. On July 21, 2026, CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation. In addition, the following vulnerabilities were also added to the KEV catalog: CVE-2026-25089 and CVE-2026-39808 affecting Fortinet FortiSandbox (both OS Command Injection vulnerabilities); CVE-2026-58644 and CVE-2026-50522 affecting Microsoft SharePoint (both Deserialization of Untrusted Data vulnerabilities); CVE-2021-27137 affecting DD-WRT (Stack-based Buffer Overflow); CVE-2026-0770 affecting Langflow (Inclusion of Functionality from Untrusted Control Sphere); and CVE-2026-16232 affecting Check Point SmartConsole, an Improper Authentication zero-day. Additionally, security researchers detected active exploitation of an exploit chain consisting of two zero-day vulnerabilities affecting SonicWall Secure Mobile Access 1000 series appliances, specifically models 6210, 7210, and 8200v, by a threat actor tracked as UTA0533 to achieve root-level Remote Code Execution. The chain combines CVE-2026-15409 (Server-Side Request Forgery) with CVE-2026-15410 (Code Injection), enabling full compromise of vulnerable devices. Finally, on July 20, 2026, South Korea’s Ministry of Foreign Affairs announced that an attack of unknown origin had exploited vulnerabilities in the online training system of the National Diplomatic Academy. According to official statements, the attackers leveraged a zero-day vulnerability, potentially affecting approximately 6,000 individuals. Authorities are continuing their investigation and, according to reports, are also assessing the possible involvement of threat actors linked to North Korea.

 

AI: offensive cyber use continues to expand

Over the past week, multiple developments have highlighted the increasingly significant role of AI within the cyber threat landscape. On July 21, 2026, OpenAI disclosed that an autonomous AI agent compromised part of the production infrastructure of Hugging Face, the leading open-source platform for artificial intelligence models. According to the reconstruction of the incident, the model, operating in an isolated environment but with reduced cyber restrictions, exploited a zero-day vulnerability in an internally hosted third-party software component to gain internet access, escalate privileges, and move laterally across the infrastructure, chaining together additional vulnerabilities and stolen credentials until achieving Remote Code Execution on the platform’s servers. Hugging Face confirmed that the intrusion was carried out entirely by the autonomous AI agent, and that access was limited to internal datasets and service credentials, with no impact on public models, datasets, or services. The incident was detected and contained by the respective security teams of both organizations, which subsequently collaborated on the investigation and remediation efforts. At the same time, researchers documented a campaign attributed to suspected Chinese threat actors that operationally integrated the Claude Code and DeepSeek-v4-pro models into offensive operations, using them to automate reconnaissance, exploit development, command-and-control infrastructure management, and post-compromise activities during attacks targeting government systems and organizations across multiple countries. During the same period, researchers also identified an operation dubbed ClaudeFix, which abused Claude.ai’s chat-sharing feature together with the ClickFix technique to distribute the MacSync infostealer on macOS systems through sponsored advertisements and social engineering. Victims were tricked into manually executing malicious commands that installed the malware and enabled the theft of credentials, sensitive data, and financial information.

 

Cybercrime: ransomware, data breaches, and campaigns targeting Italy

The incident affecting DigiCert in April 2026 has been attributed to the Chinese cybercrime group CylindricalCanine (an operational subgroup of Dragon Breath, also known as GoldenEyeDog and APT-Q-27), which, after compromising the device of a customer support operator, obtained initialization codes used for the fraudulent issuance of Extended Validation (EV) certificates that were later employed to sign Zhong Stealer malware. Ernst & Young (EY) disclosed a data breach resulting from the compromise of a third-party ticketing platform, potentially exposing customers’ personal and tax-related information. Several ransomware attacks also affected major industrial organizations. fairlife, the dairy company owned by The Coca-Cola Company, experienced unauthorized access to its systems, including production environments, in an attack claimed by the ANUBIS group. Meanwhile, Ecopetrol reported a partially unsuccessful ransomware attack that nevertheless resulted in the exfiltration of approximately 3,300 user accounts belonging to companies within the group. Stadler Rail, the Swiss manufacturer of railway vehicles, signaling systems, and rail transportation solutions, announced that it had suffered a cyber incident in mid-July 2026 involving unauthorized access by Everest Team to a data-sharing platform jointly used with one of its suppliers. On the institutional front, the official website of the Presidency of Kenya was targeted in a defacement attack for extortion purposes, during which the attackers replaced the homepage with threatening messages and demanded a ransom of five bitcoins to prevent the publication of allegedly stolen data. In Italy, the week was characterized by persistent phishing and smishing activity, with campaigns abusing the names and logos of the Italian Revenue Agency (Agenzia delle Entrate), Interactive Brokers, INPS, and Trenitalia to trick victims into disclosing login credentials, personal information, and payment details. On the ransomware front, Qilin Team claimed the compromise of Sicc S.r.l. on its leak site, while NightSpire claimed to have breached Auto Royal Company.

 


Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.

The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.

Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.

Learn more about our Cyber Threat Intelligence solution.