W1RETAP Intel Report — 2026-07-18

W1RETAP INTEL REPORT
2026-07-18
========================================================================

OVERALL SEVERITY: 8/10 - HIGH
Two Microsoft zero-days under active exploitation (SharePoint, AD FS), an
unauthenticated pre-auth RCE in WordPress core exposing hundreds of millions
of sites, and a public Windows privilege-escalation PoC dropped days after
Patch Tuesday combine to make this a high-threat window for defenders.

TOP STORY:
wp2shell - an unauthenticated, pre-authentication remote code execution flaw
in WordPress CORE - is the dominant story. Disclosed by Adam Kues of Assetnote
(Searchlight Cyber) and patched July 17 in WordPress 6.9.5 and 7.0.2, the bug
chains a REST API batch-route confusion (CVE-2026-63030) with a SQL injection
in the author__not_in parameter of WP_Query (CVE-2026-60137, also cited in some
reports as CVE-2026-63030 for the chain). It requires no authentication, no
plugins, and no preconditions - a stock install is vulnerable, putting an
estimated hundreds of millions of sites at risk. As of July 17 no confirmed
in-the-wild exploitation was reported, but by July 18 a working proof-of-concept
was public and the full mechanism published, sharply raising the risk. WordPress
has force-pushed automatic updates to affected versions. Patch to 6.9.5 / 7.0.2
now; if you cannot, block /wp-json/batch/v1 at the WAF.

BREACHES & INCIDENTS:
Several major disclosures landed this week. Abbott Laboratories is investigating
two separate incidents - unauthorized access to legacy Exact Sciences systems in
its Cancer Diagnostics unit, plus a separate claim of a breach of its LabCentral
portal. Ernst & Young is notifying customers after a third-party support-ticket
system used by its IT staff was compromised. Earlier in the week AssuranceAmerica,
a US auto insurer, disclosed a breach hitting up to 6.9 million people (names,
contact info, driver's license and policy data). Accenture confirmed a breach
after threat actor "888" claimed 35GB of source code, SSH/RSA keys, and Azure
storage keys. Fluke Corporation reportedly lost over 100GB including 21 million
Salesforce records, attributed to ShinyHunters. On July 17 the World Leaks group
posted a cache tied to India's Kudankulam nuclear plant, sourced from a partial
breach at contractor Reliance Group on a Yotta-hosted server. Deutsche Bank and
Ford Mexico also appeared on ransomware leak sites (Unsafe and Krybit groups).

VULNERABILITIES & EXPLOITS:
Microsoft's July Patch Tuesday was the largest on record - roughly 620+ CVEs
(sources cite 570 to 622) - including two actively exploited zero-days:
CVE-2026-56164, a SharePoint Server privilege-escalation/RCE flaw being chained
with older SharePoint bugs to steal IIS machine keys and establish persistence,
and CVE-2026-56155, an AD FS elevation-of-privilege bug credited to Microsoft's
DART incident-response team. CISA added the exploited SharePoint flaw to its KEV
catalog and issued a SharePoint hardening alert (note: some reporting labels the
SharePoint KEV entry CVE-2026-58644, CVSS 9.8 - source numbering conflicts, so
treat the exact CVE ID as unconfirmed and patch all July SharePoint fixes). A
publicly disclosed BitLocker bypass (CVE-2026-50661) was also fixed. Separately,
SonicWall warned of active exploitation of two SMA 1000-series zero-days
(CVE-2026-15409 SSRF, CVE-2026-15410 code injection). A researcher also flagged
"HollowByte," an 11-byte payload that can trigger a DoS on OpenSSL servers.

TOOLS & TECH:
Offensive Security released Kali Linux 2026.1, bringing a kernel bump to 6.18,
183 package updates, and eight new tools including Fluxion (wireless attack
simulation), SSTImap (server-side template injection detection), WPProbe
(WordPress plugin enumeration), and XSStrike (advanced XSS detection). On the
offensive-research side, a researcher using the handle "Chaotic Eclipse" (also
reported as "Nightmare Eclipse") dropped a public PoC named LegacyHive - a
Windows User Profile Service arbitrary-hive-load privilege-escalation exploit
that reportedly works on fully patched systems including the July Patch Tuesday
build. On defense, Polygraf AI launched Meeting Guard, a real-time AI
fraud/deepfake detection tool that joins enterprise video meetings as a
participant.

U.S. GOVERNMENT CYBER MOVES:
The headline federal action is a July 14 joint advisory - CISA with NSA, FBI, the
Defense Cyber Crime Center (DC3), and international partners (Australia's ACSC and
Canada's CCCS) - titled "Improve Router Hygiene to Protect Against Russian
State-Sponsored Targeting." It warns that FSB Center 16-linked actors have spent
years extracting configuration data from poorly secured routers across critical
infrastructure (communications, energy, defense industrial base, financial
services, government, and healthcare) and provides updated TTPs and mitigations.
CISA also issued a SharePoint hardening alert after the new exploitations and
added two KEV entries this week (variously reported as the SharePoint flaw, plus
CVE-2023-4346 in the KNX protocol and CVE-2026-46817 in Oracle E-Business Suite).
NIST published SP 800-238, its FY2025 Cybersecurity and Privacy Program Annual
Report, with several other publications in public-comment periods. No specific new
U.S. Cyber Command activity surfaced in this window.

TRENDS TO WATCH:
AI-driven offense is accelerating - researchers documented what is described as
the first fully autonomous ransomware attack orchestrated by an AI agent
("JADEPUFFER"), and "shadow AI" (unsanctioned employee AI-tool adoption) is
spreading across SaaS environments as an emerging attack surface. The pattern of
researchers publishing working PoCs within hours or days of Patch Tuesday
(LegacyHive, wp2shell) continues to compress the window defenders have between
disclosure and exploitation - assume anything patched this week is being reverse-
engineered right now.

------------------------------------------------------------------------
Report window: approx. last 24-48 hours as of 2026-07-18. Compiled from open-
source reporting (BleepingComputer, The Hacker News, SecurityWeek, CISA.gov,
Help Net Security, and others); some CVE identifiers show source conflicts and
are flagged as unconfirmed above. Verify before acting on high-stakes items.

Read more