Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (18 July 2026)
Published: Loading…
At a Glance
- WordPress shipped forced updates 7.0.2 and 6.9.5 fixing CVE-2026-63030, an unauthenticated RCE via the REST API batch endpoint.
- CISA added CVE-2026-58644, a critical SharePoint deserialization flaw, to its KEV catalog, requiring FCEB patching by July 19.
- CISA ordered agencies to patch two actively exploited FortiSandbox flaws, CVE-2026-39808 and CVE-2026-25089, both scoring CVSS 9.1.
- A cyberattack disconnected Nichirei's systems on July 13, disrupting Japanese frozen food logistics and retail supply chains.
- GoldenEyeDog subgroup CylindricalCanine was linked to the April 2026 DigiCert breach and code-signing certificate theft.
- A leaked Docker Hub token was found exposing push access to 384 Toradex Torizon container images.
Editorial Analysis
Unauthenticated vulnerabilities in widely deployed platforms are moving from disclosure to active exploitation within days. WordPress Core's wp2shell flaw is the clearest case: a pre-authentication remote code execution vulnerability requiring no preconditions, exploitable by an anonymous user on a stock installation with no plugins installed, on software estimated to run over 500 million websites. SharePoint's CVE-2026-58644 and FortiSandbox's paired command injection flaws followed the same trajectory, both added to CISA's KEV catalogue shortly after disclosure.
What distinguishes these cases is less the technical mechanism than how little time separates disclosure from weaponisation. Vulnerability management has traditionally assumed at least a brief interval — often measured in days — before a flaw is weaponised; several of today's incidents show that interval narrowing further, particularly for flaws requiring no authentication or user interaction. This effect scales with installed base: for a platform the size of WordPress, the fix's publication itself tells attackers which sites are still unpatched.
A leaked Docker Hub token, malicious npm packages, and a certificate-authority breach each affected a different layer of the software delivery pipeline — package registries, CI/CD secrets, certificate trust — rather than a production endpoint. None of this is new; supply-chain incidents have recurred have recurred for months, now about as often as ransomware and, in some cases, with comparable disruption. Read together with the platform vulnerabilities, this points to patch-management and secrets-hygiene practices being tested less by the volume of disclosures than by how quickly attackers now put them to use.
Highlights of the Day
CISA Flags Three Actively Exploited Fortinet and Microsoft Flaws
CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog based on confirmed active exploitation, including CVE-2026-25089 and CVE-2026-39808, both OS command injection flaws in Fortinet FortiSandbox. The catalog also now includes CVE-2026-58644, a deserialization of untrusted data vulnerability affecting Microsoft SharePoint. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to remediate such catalogued vulnerabilities on publicly exposed assets that grant full control post-exploitation.
"The Gentlemen" Takes Top Ransomware Spot as "Deadlock" Resurfaces
ReliaQuest reported that ransomware group "The Gentlemen" claimed the top spot with 300 named victims in Q2 2026, overtaking "Qilin," "DragonForce" and "Coinbase Cartel," which all lost significant ground. Newcomer "Deadlock" ended eleven months of silence with 75 victims in June, using blockchain-hosted command and control on the Polygon network alongside a vulnerable driver, tracked as CVE-2024-51324, to terminate EDR tools before encryption. Across 90 groups and 99 countries, professional, scientific and technical services remained the most-targeted sector for a fifth consecutive quarter, with the United States accounting for roughly 49% of victim activity.
WordPress Core Flaw Allows Unauthenticated Remote Code Execution
Searchlight Cyber discovered a pre-authentication remote code execution vulnerability in WordPress Core that requires no plugins and can be exploited by an anonymous user on a stock installation. The flaw affects WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, while versions 6.8.5 and earlier remain unaffected. Searchlight Cyber withheld technical details and instead released a public checking tool at wp2shell[.]com, with fixes available in WordPress 7.0.2 and 6.9.5.
Cyberattack Disrupts Nichirei Operations, Risks Personal Data Leak
Japanese frozen food giant Nichirei Corporation confirmed a cyberattack caused system failures on 13 July 2026, prompting the company to disconnect affected servers across the Nichirei Group. The incident disrupted refrigerated warehouse operations at Nichirei Logistics Group and frozen food shipment operations at Nichirei Foods, affecting retailers including Aeon and Don Quijote as well as food delivery service Co-opdeli. Nichirei confirmed some affected servers stored personal information and submitted an initial report to Japan's Personal Information Protection Commission, with operations set to resume gradually from 17 July.
Chained Zero-Days in Siemens OT Switches Allow Root Takeover
Palo Alto Networks' Unit 42, working with Siemens, disclosed a three-vulnerability exploit chain in Siemens ROX II operational technology switches, comprising CVE-2025-40948, CVE-2025-40947 and CVE-2025-40949, with CVSS scores of 6.8, 7.5 and 9.1 respectively. The chain begins with an arbitrary file disclosure flaw in the xz utility, escalates through a command injection vulnerability in the feature key verification function, and achieves persistent root-level code execution via the device's task scheduler. Siemens issued advisories SSA-973901, SSA-078743 and SSA-081142, recommending customers update affected ROX II devices to firmware version V2.17.1.
Leaked Docker Token Exposed Toradex Embedded Device Supply Chain
Truffle Security discovered a live Docker Hub organisation access token exposed in plaintext within a public GitLab CI artifact belonging to Toradex, a Swiss embedded-systems manufacturer. The token granted push access to all 384 of Toradex's Torizon container images, including torizon/weston, an interface-rendering image pulled over 4.5 million times and used in devices deployed across medical, defence and industrial sectors. GitLab masked the credential in job logs but not in the piuparts-out artifact where it originated, and Toradex rotated the token after disclosure, finding no unauthorised push events across 48,818 audited log entries.
Daily Coverage