"This is going to hurt," watchTowr CEO Benjamin Harris said. The warning was directed at a pre-authenticated WordPress Core flaw — a chained pair of vulnerabilities that, together, let an anonymous web request turn into remote code execution on a standard WordPress instance.
wp2shell: WordPress Core RCE (CVE-2026-63030 + CVE-2026-60137)
Searchlight Cyber disclosed a pre-authenticated remote code execution issue in WordPress Core — a chain of CVE-2026-63030 (a REST API batch-route confusion) and CVE-2026-60137 (an SQL injection in WordPress core). watchTowr reported proof-of-concept exploits circulating and said it is beginning to see the first signs of in-the-wild exploitation. Their operational advice: patch immediately, then investigate to see whether attackers already dropped backdoors. The disclosure also highlighted a broader dynamic: attackers are weaponizing vulnerabilities that were surfaced with the aid of AI-assisted tooling.
SonicWall SMA zero-days and the UTA0533 actor
Volexity attributed exploitation of SonicWall Secure Mobile Access (SMA) 1000-series appliances to a previously undocumented actor codenamed UTA0533. The actor used multiple zero-day exploits and appliance-specific malware prior to public disclosure, Volexity said. The two vulnerabilities identified are CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2), which can be chained to facilitate arbitrary command execution and device takeover. Patches for both flaws were released by SonicWall last week; the impacted organization that prompted the investigation was not identified.
NadMesh: a botnet hunting exposed AI services for cloud keys
QiAnXin XLab described a new Go-based botnet named NadMesh that scans for exposed AI services — including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio — to steal AWS keys and Kubernetes tokens. "It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform," QiAnXin XLab said. On compromised hosts the agent establishes persistence along three independent paths: an SSH public-key backdoor (.ssh/authorized_keys); persistence files in multiple locations (/dev/shm/.a, /var/tmp/.a, /tmp/.a); and hidden cron watchdogs (/etc/cron.d/.sys_monitor, /etc/cron.d/.s).
OkoBot: a modular campaign to phish crypto seed phrases
Kaspersky reported a new framework called OkoBot — an evolution of TookPS — designed to capture cryptocurrency wallet windows and seed phrases. The campaign uses ClickFix and malicious code distributed via GitHub that masquerades as legitimate software for initial access, and orchestrates payloads over an SSH tunnel. The framework includes more than 20 payloads, a browser-extension loader that delivers Rilide, and an implant (OkoSpyware) that injects into Trezor Suite, Ledger Wallet, and Ledger Live to collect seed phrases, log keystrokes and clipboard content, take screenshots, and capture video streams of targeted application windows. Kaspersky said hundreds of victims have been detected across more than 25 countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye; the activity remains unattributed.
CISA adds SharePoint RCE to KEV; OpenSSL HollowByte DoS detailed
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-58644 — a critical deserialization of untrusted data vulnerability in Microsoft SharePoint Server (CVSS 9.8) — to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply fixes by July 19, 2026. Microsoft released the patches as part of the Patch Tuesday updates on July 14, 2026 and revised its bulletin to say CVE-2026-58644 had been exploited in the wild prior to the fixes being available.
Separately, the Okta Red Team disclosed HollowByte, a denial-of-service flaw in OpenSSL. "By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins," Okta said. The crafted input can convince OpenSSL to reserve up to 128 KB of heap memory for a handshake message that never arrives, causing a server to exhaust RAM and trigger a DoS. The OpenSSL team resolved the issue in versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, and Okta noted OpenSSL now grows buffers only as bytes actually arrive: "A claim with no follow-through now costs the server nothing."
What this means for technologists, federal agencies, and end users
- Technologists and security teams: prioritize immediate patching for WordPress Core (CVE-2026-63030 / CVE-2026-60137), the SonicWall SMA CVEs, and the SharePoint CVE-2026-58644; hunt for indicators of compromise and backdoors that may predate patches.
- Federal agencies and procurement leaders: meet the CISA KEV deadline for CVE-2026-58644 and treat Microsoft’s disclosure of in-the-wild exploitation as a signal to accelerate verification and incident response.
- End users and operators of crypto wallets and AI services: validate sources of downloads and extensions (noting OkoBot’s use of GitHub and browser loaders), and review exposed AI service endpoints and credentials to guard against NadMesh-style harvesting.
The week’s pattern is unmistakable: small inputs, big consequences. From an 11‑byte OpenSSL probe to a chained WordPress exploit that runs code without authentication, attackers are converting minor openings into decisive access. The practical takeaway is blunt and repeated across vendors and researchers in this report — patch fast, assume public interfaces have been probed, and investigate systems for traces of compromise that may have arrived before fixes did.




