SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, July 19, 2026 INTEL CONFIDENCE 94% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Public Exploits Released For WordPress wp2shell RCE | CRITICAL |
|
5 C2 IPs | 40 OTX IOCs | 4 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by active exploitation risks, highlighted by the release of public exploits for critical "wp2shell" remote code execution vulnerabilities in WordPress Core and a newly patched RCE flaw in 7-Zip. Additionally, Microsoft has warned of a significant surge in ACR Stealer malware campaigns actively targeting enterprise customers to harvest passwords, session tokens, and sensitive documents. Organizations must prioritize immediate patching of web infrastructure and archiving utilities while hardening endpoints against credential theft. |
|
■ CRITICAL STORIES WordPress Core "wp2shell" RCE flaws get public exploits, patch now Public exploits are now available for critical remote code execution vulnerabilities in WordPress Core, significantly increasing the risk of automated site takeovers and web shell deployments. |
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives A remote code execution vulnerability in 7-Zip (fixed in v26.02) allows attackers to execute arbitrary code if a user is tricked into opening a specially crafted archive, posing a high risk for phishing and social engineering campaigns. |
Microsoft warns of surge in ACR Stealer attacks on customers A spike in ACR Stealer malware activity threatens enterprise environments by actively exfiltrating browser-stored credentials, authentication tokens, and sensitive files. |
|
■ CVEs IDENTIFIED [CVE-TBD] (WordPress wp2shell) WordPress Core — Remote Code Execution via wp2shell exploit |
[CVE-TBD] (7-Zip RCE) 7-Zip (versions prior to 26.02) — Remote Code Execution via malicious archives |
|
■ THREAT ACTORS ACR Stealer Operators | Cybercrime / Info-stealer Group |
Targeting Microsoft enterprise customers to steal passwords, tokens, and documents |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Public exploits released for WordPress Core wp2shell RCE vulnerabilities |
| T1203 | | Exploitation for Client Execution | Attackers exploiting 7-Zip RCE via malicious archives |
| T1555.003 | | Credentials from Web Browsers | ACR Stealer stealing browser-stored passwords |
| T1539 | | Steal Web Session Information | ACR Stealer harvesting authentication tokens from browsers |
| T1567 | | Exfiltration Over Web Service | ACR Stealer exfiltrating sensitive documents and credentials |
|
■ PATCH PRIORITY WordPress Core — Public exploits are available for critical "wp2shell" RCE vulnerabilities — [BC] WordPress Core "wp2shell" RCE flaws get public exploits, patch now |
7-Zip (versions prior to 26.02) — Remote code execution vulnerability exploitable via malicious archives — [BC] Update now: 7-Zip fixes RCE flaw exploitable with malicious archives |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately update all WordPress Core installations to the latest patched version to mitigate the "wp2shell" RCE vulnerabilities now actively targeted with public exploits. |
| 2 | [P1] Upgrade all 7-Zip installations across the enterprise to version 26.02 or higher to remediate the [CVE-TBD] remote code execution flaw. |
| 3 | [P2] Deploy endpoint detection rules to identify ACR Stealer execution, specifically monitoring unauthorized access to browser credential stores and sensitive document directories. |
| 4 | [P2] Implement email filtering rules to block or inspect incoming archive files (e.g., .zip, .7z) from external sources to prevent exploitation of the 7-Zip RCE vulnerability. |
| 5 | [P3] Review and invalidate active enterprise session tokens if anomalous credential access or ACR Stealer activity is detected on host endpoints. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |