Daily Security Intel

Archives
Log in
Subscribe
July 18, 2026

[SecurityIntel] 18 Jul | Unauthenticated WordPress Core wp2shell RCE Threatens Millions

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, July 18, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Unauthenticated WordPress Core wp2shell RCE Threatens Millions

CRITICAL

5

C2 IPs

59

OTX IOCs

30

ARTICLES

■ ANALYST TLDR

Today's intelligence landscape is dominated by critical remote code execution and privilege escalation vulnerabilities, highlighted by the unauthenticated "wp2shell" flaw in WordPress Core and an actively exploited SharePoint RCE. Additionally, threat actors are leveraging a newly disclosed Windows "LegacyHive" zero-day for local privilege escalation, while the "NadMesh" botnet aggressively targets exposed AI services to harvest cloud credentials. Organizations must prioritize immediate patching of public-facing assets and secure development environments against sophisticated supply chain and steganography-based campaigns.

■ CRITICAL STORIES

CRITICAL#1

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

This zero-plugin core vulnerability allows trivial remote code execution on WordPress 6.9 and 7.0 sites, presenting an immediate threat to millions of unpatched web servers.

CRITICAL#2

New Windows LegacyHive zero-day gives hackers admin privileges

A newly released zero-day exploit named LegacyHive bypasses modern Windows defenses to grant local attackers full administrative privileges, requiring immediate monitoring and mitigation.

CRITICAL#3

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

Attackers are actively exploiting a critical-severity SharePoint vulnerability to achieve remote code execution, forcing organizations to accelerate patch cycles.

HIGH#4

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go-based botnet is actively scanning for exposed AI interfaces like ComfyUI and Ollama to harvest AWS credentials and Kubernetes tokens, signaling a shift in threat actor targeting toward AI infrastructure.

■ CVEs IDENTIFIED

[CVE-TBD]

WordPress Core (6.9, 7.0) — Unauthenticated Remote Code Execution (wp2shell)

Critical

[CVE-TBD]

Microsoft Windows — Local Privilege Escalation (LegacyHive zero-day)

Critical

[CVE-TBD]

Microsoft SharePoint — Remote Code Execution

Critical

[CVE-TBD]

Fortinet FortiSandbox — Active Exploitation / Remote Code Execution

Critical

■ THREAT ACTORS

CylindricalCanine

APT Subgroup (GoldenEyeDog)

Attributed to the April 2026 DigiCert breach and code-signing certificate theft.

Contagious Interview Campaign Actors

APT (North Korea)

Utilizing steganography in SVG flag images within fake coding tests to deliver OtterCookie-aligned malware.

NadMesh Operator

Cybercriminal / Botnet Operator

Scanning for exposed AI services (ComfyUI, Ollama, n8n) to harvest AWS keys and Kubernetes tokens.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Used to exploit WordPress Core (wp2shell), SharePoint, and Fortinet FortiSandbox.
T1068
Exploitation for Privilege Escalation | Seen in Windows LegacyHive zero-day and Siemens ROX II switch vulnerabilities.
T1195.002
Compromise Software Supply Chain: Malicious Package | ViteVenom campaign distributing malicious npm packages.
T1580
Cloud Infrastructure Discovery | NadMesh botnet harvesting AWS keys and Kubernetes tokens from exposed AI services.
T1027.003
Obfuscated Files or Information: Steganography | North Korean actors hiding OtterCookie malware in SVG flag images.
T1486
Data Encrypted for Impact | Ransomware attack disrupting Fairlife/Coca-Cola production and Nichirei operations.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

WordPress Core — Unauthenticated RCE vulnerability (wp2shell) exploitable on bare installs — [THN]

[P1 PATCH NOW]≤24h

Microsoft SharePoint — Critical RCE vulnerability actively exploited in the wild shortly after disclosure — [SW]

[P1 PATCH NOW]≤24h

Fortinet FortiSandbox — Two actively exploited vulnerabilities highlighted by CISA — [BC]

[P1 PATCH NOW]≤24h

Microsoft Windows — LegacyHive zero-day privilege escalation exploit released publicly — [BC]

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately update WordPress Core installations to versions 6.9.5 or 7.0.2 to remediate the critical wp2shell unauthenticated RCE vulnerability ([CVE-TBD]).
2[P1] Apply emergency patches to Microsoft SharePoint servers to mitigate the actively exploited RCE vulnerability ([CVE-TBD]).
3[P1] Implement CISA-mandated patches for the two actively exploited vulnerabilities in the Fortinet FortiSandbox platform ([CVE-TBD]).
4[P2] Deploy host-based detection rules to monitor for unauthorized registry access and privilege escalation attempts associated with the Windows LegacyHive zero-day ([CVE-TBD]).
5[P2] Audit and restrict public access to AI development interfaces, specifically ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio, to prevent exploitation by the NadMesh botnet.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 19 Jul | Public Exploits Released For WordPress wp2shell RCE Older → [SecurityIntel] 17 Jul | ClickLock macOS Malware Kills Apps For Passwords
Powered by Buttondown, the easiest way to start and grow your newsletter.