Daily Security Intel

Archives
Log in
Subscribe
July 22, 2026

[SecurityIntel] 22 Jul | SharePoint and PAN-OS Flaws Actively Exploited

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, July 22, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

SharePoint and PAN-OS Flaws Actively Exploited

CRITICAL

5

C2 IPs

0

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Active exploitation of critical vulnerabilities dominates today's landscape, highlighted by the active abuse of Microsoft SharePoint (CVE-2026-50522) and WordPress "wp2shell" (CVE-2026-63030, CVE-2026-60137) to establish persistence and deploy webshells. Additionally, the Qilin ransomware group is actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability for initial access. Organizations must also contend with the "FakeGit" campaign distributing SmartLoader and StealC malware via thousands of malicious GitHub repositories.

■ CRITICAL STORIES

CRITICAL#1

Critical SharePoint RCE flaw exploited to steal machine keys

Hackers are actively exploiting CVE-2026-50522 in Microsoft SharePoint to steal machine keys, allowing them to maintain persistent access even after the servers have been patched.

INFO#2

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect VPNs to breach enterprise networks, emphasizing the rapid weaponization of edge device flaws.

CRITICAL#3

Critical wp2shell WordPress flaws exploited to install webshells

Threat actors began exploiting the "wp2shell" vulnerability chain (CVE-2026-63030 and CVE-2026-60137) within hours of patch release, deploying persistent webshells and malicious plugins across affected WordPress sites.

INFO#4

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A massive software supply chain campaign has leveraged over 7,600 malicious GitHub repositories, generating 14 million downloads to distribute SmartLoader and StealC infostealers.

■ CVEs IDENTIFIED

CVE-2026-50522

Microsoft SharePoint Server — Deserialization Remote Code Execution (RCE) and machine key theft

Critical

CVE-2026-63030

WordPress Core (wp2shell) — Remote Code Execution and webshell installation

Critical

CVE-2026-60137

WordPress Core (wp2shell) — Remote Code Execution and webshell installation

Critical

[CVE-TBD]

Palo Alto Networks PAN-OS GlobalProtect — Authentication Bypass leading to ransomware deployment

Critical

■ THREAT ACTORS

Qilin (aka Agenda)

Ransomware Group

Exploiting PAN-OS GlobalProtect authentication bypass for initial access and network intrusion.

Anubis

Ransomware Group

Claimed responsibility for a cyberattack on Coca-Cola Fairlife, threatening data leaks.

FakeGit Operators

Cybercrime Group

Operating 7,600 malicious GitHub repos to distribute SmartLoader and StealC malware.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Qilin ransomware exploiting PAN-OS; attackers exploiting SharePoint CVE-2026-50522 and WordPress wp2shell.
T1505.003
Server Software Component: Web Shell | Attackers deploying webshells via WordPress wp2shell vulnerabilities.
T1204.002
User Execution: Malicious File | Users downloading SmartLoader and StealC from FakeGit GitHub repositories.
T1071.004
Application Layer Protocol: DNS/Web Protocols | HollowGraph malware using Microsoft 365 Calendar for C2.
T1090
Proxy | LG Smart TV apps turning devices into residential proxy nodes.
T1553.004
Subvert Trust Controls: Install Root Certificate / Steal Keys | SharePoint exploitation used to steal machine keys.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Microsoft SharePoint Server — CVE-2026-50522 is actively exploited to steal machine keys and maintain persistent access — [BC]

[P1 PATCH NOW]≤24h

Palo Alto Networks PAN-OS GlobalProtect — Critical authentication bypass is actively exploited by Qilin ransomware for initial access — [THN]

[P1 PATCH NOW]≤24h

WordPress Core — wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) is actively exploited to install webshells — [BC]

[P2 PATCH NOW]≤72h

Zimbra Collaboration — Patched critical SNMP command injection and multiple XSS vulnerabilities — [THN]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Microsoft SharePoint Server immediately to address CVE-2026-50522, and rotate all machine keys as attackers are known to steal them to maintain access post-patch.
2[P1] Apply security updates to Palo Alto Networks PAN-OS GlobalProtect VPN to mitigate the critical authentication bypass vulnerability currently being exploited by the Qilin ransomware group.
3[P1] Update WordPress Core to remediate the critical wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) to prevent webshell installation.
4[P2] Apply the latest Zimbra Collaboration patches to resolve the critical SNMP command injection and cross-site scripting (XSS) vulnerabilities.
5[P2] Audit defense contractor supply chains and software dependencies to comply with the new executive order on end-to-end supply chain visibility.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 23 Jul | SharePoint and Langflow Flaws Face Active Exploitation Older → [SecurityIntel] 20 Jul | SonicWall VPN Zero-Days and Critical NGINX RCE
Powered by Buttondown, the easiest way to start and grow your newsletter.