hacker-news · Crawled Jul 20, 2026

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

7 IoCs 8 CVEs
Read original article ↗

AI Summary

This week's threat landscape highlights critical vulnerabilities in widely used platforms such as WordPress, SonicWall, and Microsoft SharePoint, with active exploitation observed in the wild. A pre-authenticated remote code execution flaw in WordPress Core (CVE-2026-63030 and CVE-2026-60137) enables unauthenticated attackers to execute code, posing a significant risk due to WordPress's global reach. SonicWall SMA appliances were exploited via zero-day vulnerabilities prior to patching, while CISA added a SharePoint RCE (CVE-2026-58644) to its known exploited list. Additionally, new malware frameworks like OkoBot and NadMesh target crypto assets and cloud AI services, indicating evolving attacker tactics leveraging automation and AI.

AI-extracted · verify before operational use

Extracted Entities 8 found

Indicators of Compromise 7 extracted

Type Value Detail
GitHub Repo Cursor agent Details →
Filename .ssh/authorized_keys Details →
Filename /dev/shm/.a Details →
Filename /var/tmp/.a Details →
Filename /tmp/.a Details →
Filename /etc/cron.d/.sys_monitor Details →
Filename /etc/cron.d/.s Details →

MITRE ATT&CK TTPs 5 techniques