wp2shell.comVulnerability checker and disclosure site for wp2shell WordPress RCE flaw
ThreatNoir Weekend Brief — July 18
Morning Review in IT Security — July 18, 2026
The cybersecurity landscape faces mounting pressure on multiple fronts this week, with critical vulnerabilities emerging in foundational infrastructure, supply chain attacks expanding into new ecosystems, and law enforcement securing convictions against prominent threat actors. Organizations face an urgent need to prioritize patching while remaining vigilant against sophisticated exploitation campaigns targeting both legacy systems and modern cloud deployments.
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical remote code execution vulnerability has been discovered in WordPress core that allows unauthenticated attackers to execute arbitrary code through anonymous HTTP requests. The flaw affects WordPress versions 6.9 and 7.0, and because it resides in core functionality, even a bare WordPress installation with zero plugins remains exploitable. Adam Kues at Assetnote, Searchlight Cyber's attack surface management division, identified and reported the vulnerability. Source: The Hacker News
WordPress responded by releasing patches in versions 6.9.5 and 7.0.2 on Friday and simultaneously enabled forced updates through its auto-update system to ensure widespread remediation. The domain wp2shell.com has been associated with this vulnerability. Organizations running affected WordPress versions should prioritize immediate updates to mitigate the risk of compromise.
Abbott Laboratories Probes Two Cyber Incidents Amid Extortion Claims
Abbott Laboratories is currently investigating two separate cybersecurity incidents following confirmation of unauthorized access to internal legacy systems within its Cancer Diagnostics business, specifically affecting Exact Sciences infrastructure. Additionally, the company is investigating a separate breach claim alleging that attackers compromised its LabCentral portal and exfiltrated company data. Source: Bleeping Computer
The incidents appear to involve Microsoft Entra SSO compromise as a vector for initial access. The dual nature of these breaches suggests either coordinated attacks or opportunistic exploitation following initial compromise. Abbott's investigation remains ongoing as the company works to contain the incidents and assess the scope of affected data.
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
A denial-of-service vulnerability in OpenSSL, dubbed HollowByte, allows attackers to exhaust server memory using remarkably small TLS requests of just eleven bytes. When exploited, an unpatched OpenSSL server allocates up to 131 kilobytes of memory for messages that never arrive, and on glibc systems tested by Okta, this memory remains unavailable until the process restarts. Source: The Hacker News
The vulnerability, identified by Okta's Red Team, was patched in OpenSSL's June release but notably shipped without a CVE assignment, security advisory, or changelog entry highlighting the fix. The associated CVEs are CVE-2025-66199 and CVE-2026-34183. Organizations running OpenSSL should ensure they have deployed the patched version to prevent memory exhaustion attacks against their TLS endpoints.
Inc Ransomware Exploits SonicWall SMA Zero-Days
The Inc ransomware gang has begun actively exploiting two previously unknown zero-day vulnerabilities in SonicWall's Secure Mobile Access (SMA) appliances. When chained together, these vulnerabilities grant threat actors root-level access to the affected devices, providing a powerful foothold for lateral movement and data exfiltration. Source: Dark Reading
SonicWall SMA appliances are critical access points for remote workers and partners, making root compromise particularly dangerous. Organizations relying on these devices should immediately contact SonicWall for guidance on patching and implement compensating controls to restrict access to SMA appliances while updates are deployed.
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Researchers at Checkmarx have identified seven malicious npm packages targeting the Vite frontend build tooling ecosystem as part of a software supply chain attack campaign. Dubbed ViteVenom, this attack represents an expansion of the ChainVeil malware family, which employs an unprecedented four-tier blockchain-based command-and-control infrastructure spanning multiple blockchain networks. Source: The Hacker News
The malicious packages deliver a remote access trojan (RAT) to compromised development environments, potentially affecting any project that installed these dependencies. The use of blockchain-based C2 infrastructure complicates detection and takedown efforts. Developers should audit their npm dependencies immediately, review package installation logs, and regenerate credentials for any systems that may have executed code from these packages.
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go-based botnet named NadMesh emerged in early July, specifically targeting exposed AI services to harvest cloud credentials and Kubernetes tokens. The operator's own dashboard claims possession of 3,811 unique AWS keys, indicating successful large-scale credential theft. The botnet uses a Shodan harvester to continuously scan for exposed instances of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio—popular AI and workflow tools frequently deployed with inadequate network segmentation. Source: The Hacker News
The campaign exploits the common pattern of teams rapidly deploying AI services without proper firewall configuration or credential management. Compromised cloud keys grant attackers direct access to cloud environments, while Kubernetes tokens enable container orchestration attacks. Organizations should implement strict network policies restricting AI service exposure, enforce credential rotation for cloud and container platforms, and monitor for suspicious API activity from development infrastructure.
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster called CylindricalCanine, identified as a sub-group of GoldenEyeDog, a Chinese cybercrime group also known by aliases including APT-Q-27, Dragon Breath, and Miuuti Group. The group is known for targeting the gambling and gaming sectors and has successfully stolen code-signing certificates from DigiCert. Source: The Hacker News
The breach involved spear-phishing attacks delivering multiple remote access trojans including Gh0st RAT, Golden Gh0st Loader, Golden Gh0st RAT, RONINGLOADER, and Zhong Stealer. The theft of code-signing certificates represents a critical supply chain risk, as these credentials can be used to sign malware, making it appear legitimate to end-user systems. Organizations should revoke trust in any DigiCert-issued code-signing certificates that may have been compromised and implement strict certificate pinning and verification procedures.
Leading Members of Scattered Spider Sentenced in UK to 66 Months in Jail
Thalha Jubair and Owen Flowers, leading members of the Scattered Spider threat group, have been sentenced in the United Kingdom to 66 months in prison. U.S. authorities previously implicated Jubair in participation in at least 120 cyberattacks. The sentencing represents a significant law enforcement victory against one of the most active social engineering-focused threat groups. Source: CyberScoop
Scattered Spider became notorious for its role in the Transport for London cyberattack, which caused major operational disruption to the transit system. The group's tactics centered on social engineering, credential compromise, and lateral movement rather than sophisticated technical exploits. This conviction demonstrates that international law enforcement cooperation can successfully prosecute even highly mobile and distributed threat actors.
The week underscores the critical importance of maintaining current patch levels across all infrastructure layers, from web platforms to VPN appliances, while simultaneously strengthening defenses against supply chain attacks and credential theft targeting both traditional systems and emerging AI deployments.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Microsoft Entra SSO compromiseVishing attack targeting SSO account for lateral movement into internal systems
- Related QUIC PATH_CHALLENGE unbounded memory growth, rated Moderate
- Related TLS 1.3 certificate-compression buffer growth issue, rated Low
- Inc ransomwareRansomware variant actively exploiting SonicWall SMA zero-days
- RATRemote access trojan delivered via blockchain C2 infrastructure
- ChainVeilEarlier supply chain attack campaign; ViteVenom is an expansion of this
- ViteVenomCampaign name for seven malicious Vite npm packages
- Shodan-based harvesting of exposed AI service deployments
- Extracting ~/.aws/config, .env, and ~/.docker/config.json
- Harvesting AWS keys, Kubernetes tokens, and environment variables
- NadMeshGo-based botnet targeting exposed AI services and cloud infrastructure
- Zhong StealerMalware documented by ANY.RUN in February 2025 with overlaps to Golden Gh0st RAT
- Golden Gh0st RATModified variant of Gh0st RAT used by GoldenEyeDog for remote access
- Golden Gh0st LoaderMulti-stage loader delivering Golden Gh0st RAT
- RONINGLOADERMulti-stage loader distributing Gh0st RAT via NSIS installers
- Gh0st RATRemote access trojan widely used by Chinese threat groups