Jul 30, 2026 · Covering Jul 20, 2026 – Jul 26, 2026
This Week in Threats: July 20–July 26, 2026
Multiple zero-day and unpatched vulnerabilities exploited in ransomware, espionage, and data theft campaigns targeting critical enterprise systems.
Overview
This week saw widespread exploitation of critical vulnerabilities in widely used enterprise platforms including PTC Windchill, FlexPLM, Fastjson, SharePoint, and Palo Alto Networks’ GlobalProtect VPN. Threat actors leveraged unauthenticated remote code execution flaws to deploy webshells, steal credentials, and conduct ransomware and espionage operations across high-value sectors.
Active Threat Actors
Cl0p-affiliated threat actors, associated with DEV-0950 (Lace Tempest), exploited CVE-2026-12569 in internet-exposed PTC Windchill and FlexPLM systems to achieve unauthenticated remote code execution and deploy JSP webshells for data exfiltration and double extortion Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Clop ransomware targets Windchill, FlexPLM in data theft attacks. The Qilin ransomware gang actively exploited CVE-2026-0257 in Palo Alto Networks’ GlobalProtect VPN to gain unauthorized access to corporate networks and deploy ransomware domain-wide Critical GlobalProtect VPN bug now exploited by Qilin ransomware gang. A Russian state-supported espionage group exploited a zero-day in Zimbra (CVE-2025-66376) to steal emails, passwords, and 2FA codes via a zero-click exploit Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes. Microsoft tracks Storm-2603 as a China-based actor observed deploying webshells and attempting to steal MachineKeys via on-premises SharePoint vulnerabilities Critical SharePoint RCE flaw exploited to steal machine keys. Void Blizzard, a Russian cyberespionage group, continued targeting government, defense, and NGO sectors in Europe and North America using stolen credentials Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes.
Notable Malware
The Cl0p ransomware (ELF) was deployed by affiliates exploiting vulnerabilities in PTC Windchill and FlexPLM systems Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE. More_eggs, a JavaScript backdoor used by the Cobalt group, enables download and execution of payloads, retrieval of additional scripts, and command shell execution More_eggs. TrickBot, a financial Trojan with modules for VNC and Socks5 proxy, continues to be active TrickBot. SectopRAT (ArechClient), a .NET-based RAT, was observed stealing browser and cryptocurrency wallet data and enabling remote desktop control SectopRAT. Sliver, a command-and-control framework used by advanced persistent threats, supports multiple architectures and callback protocols including DNS and HTTP(S) Sliver. BaoLoader, associated with AppSuite-PDF and PDF Editor campaigns, uses legitimate code-signing certificates to appear trustworthy BaoLoader. Quasar RAT, an open-source .NET malware, is used by various attackers and often packed to hinder analysis Quasar RAT. Odyssey Stealer and PteroGraphin were identified in the data but no specific activity was reported.
Key CVEs & Campaigns
CVE-2026-12569 in PTC Windchill and FlexPLM was exploited by Cl0p-affiliated actors to achieve unauthenticated RCE and deploy JSP webshells Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE. CVE-2026-16723, an unpatched RCE in Fastjson 1.x, is actively exploited in Spring Boot applications via malicious JSON input Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available. CVE-2026-0770 in Langflow, a critical RCE flaw allowing root-level code execution, prompted CISA to mandate urgent patching by federal agencies CISA orders urgent action on actively exploited Langflow RCE flaw. CVE-2026-50522 in Microsoft SharePoint, a deserialization flaw, is exploited to steal machine keys and forge authentication tokens Critical SharePoint RCE flaw exploited to steal machine keys. CVE-2026-63030 and CVE-2026-60137, collectively known as ‘wp2shell’, are exploited in WordPress Core via the REST API to deploy webshells Critical wp2shell WordPress flaws exploited to install webshells. CVE-2026-6875 in ServiceNow AI Platform allows unauthenticated RCE via a sandbox escape Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution. CVE-2026-0257 in Palo Alto Networks’ GlobalProtect VPN enables authentication bypass and unauthorized access Critical GlobalProtect VPN bug now exploited by Qilin ransomware gang. CVE-2025-66376, a zero-day in Zimbra, was exploited by a Russian espionage group to steal sensitive data via a zero-click email exploit Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes. Hugging Face disclosed a breach where an autonomous AI agent exploited code-execution vulnerabilities in its pipeline to access internal datasets and credentials Hugging Face warns an autonomous AI agent hacked its network.
Sources
- Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE — hacker-news
- Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available — hacker-news
- Clop ransomware targets Windchill, FlexPLM in data theft attacks — bleeping-computer
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes — hacker-news
- CISA orders urgent action on actively exploited Langflow RCE flaw — bleeping-computer
- Critical SharePoint RCE flaw exploited to steal machine keys — bleeping-computer
- Critical wp2shell WordPress flaws exploited to install webshells — bleeping-computer
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution — hacker-news
- Critical GlobalProtect VPN bug now exploited by Qilin ransomware gang — bleeping-computer
- Hugging Face warns an autonomous AI agent hacked its network — bleeping-computer