Weekly review

ThreatNoir Weekend Brief — July 19

2026-07-19Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — July 19, 2026

The cybersecurity landscape continues to shift rapidly as critical vulnerabilities in widely deployed software reach public exploit status, forcing organizations to prioritize emergency patching. Today's threat intelligence reveals an urgent pattern of remote code execution flaws affecting both web platforms and compression utilities, alongside a notable surge in credential-stealing malware targeting enterprise environments.

WordPress Core "wp2shell" RCE Flaws Get Public Exploits, Patch Now

Public exploits have been released for critical remote code execution vulnerabilities affecting WordPress Core, identified as CVE-2026-60137 and CVE-2026-63030. These flaws, collectively known as "wp2shell," allow unauthenticated attackers to execute arbitrary code on vulnerable WordPress installations through anonymous HTTP requests. The vulnerabilities affect WordPress versions 6.9 and 7.0, with WordPress responding by releasing patches in versions 6.9.5 and 7.0.2 and enabling forced updates through its auto-update system. The flaw was discovered by Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm. Source: WordPress Core "wp2shell" RCE flaws get public exploits, patch now

The severity of these vulnerabilities is compounded by the fact that even bare WordPress installations with zero plugins are exploitable, meaning no additional third-party components are required for successful attacks. Organizations running WordPress should treat this as a critical incident requiring immediate action to update their installations to the patched versions.

Update Now: 7-Zip Fixes RCE Flaw Exploitable with Malicious Archives

7-Zip version 26.02 has been released to address a remote code execution vulnerability that allows attackers to execute malicious code through specially crafted compressed files. The flaw, designated CVE-2025-8088, represents a significant supply chain and malware risk, as attackers can exploit it by convincing users to open seemingly innocent archive files. Source: Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

This vulnerability underscores the risks associated with software that relies on manual-only update mechanisms, as users may remain unaware of critical patches for extended periods. Organizations and individuals using 7-Zip should upgrade to version 26.02 or later to mitigate exploitation risk.

Microsoft Warns of Surge in ACR Stealer Attacks on Customers

Microsoft has reported a significant increase in attacks leveraging the ACR Stealer malware to target its enterprise customers. The malware is designed to steal browser-stored passwords, authentication tokens, and sensitive documents from compromised systems. Related threats identified in the same campaign include Amatera Stealer, Bumblebee, and Voldemort, suggesting a coordinated effort to compromise enterprise credentials and intellectual property. Source: Microsoft warns of surge in ACR Stealer attacks on customers

The surge in ACR Stealer activity demonstrates how threat actors continue to prioritize credential harvesting as a primary attack vector. Organizations should strengthen defenses around browser security, implement credential management solutions, and conduct awareness training to help employees recognize social engineering tactics used to deliver these threats.

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

A newly disclosed WordPress Core vulnerability enables unauthenticated attackers to execute arbitrary code on vulnerable sites through anonymous HTTP requests. The flaw affects WordPress versions 6.9 and 7.0, with WordPress releasing patches in versions 6.9.5 and 7.0.2 on Friday. The forced update mechanism has been activated to ensure widespread patching across the WordPress ecosystem. Source: New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

The critical nature of this vulnerability and the rapid deployment of patches through WordPress's forced update system reflect the urgency of the threat. All WordPress administrators should verify that their installations have been updated to the patched versions to prevent exploitation.

Today's threat landscape demonstrates the continued importance of rapid patching cycles and proactive security monitoring. Organizations must maintain vigilance across their software supply chains and implement robust update management practices to respond effectively to emerging threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Microsoft warns of surge in ACR Stealer attacks on customers
Malware4
  • Voldemort
    Historical malware using similar WebDAV delivery tactics
  • ACR Stealer
    Info-stealing malware-as-a-service targeting browser data, credentials, and documents
  • Amatera Stealer
    Original malware believed rebranded as ACR Stealer
  • Bumblebee
    Historical malware using similar WebDAV delivery tactics