SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, July 22, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY SharePoint and PAN-OS Flaws Actively Exploited | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Active exploitation of critical vulnerabilities dominates today's landscape, highlighted by the active abuse of Microsoft SharePoint (CVE-2026-50522) and WordPress "wp2shell" (CVE-2026-63030, CVE-2026-60137) to establish persistence and deploy webshells. Additionally, the Qilin ransomware group is actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability for initial access. Organizations must also contend with the "FakeGit" campaign distributing SmartLoader and StealC malware via thousands of malicious GitHub repositories. |
|
■ CRITICAL STORIES Critical SharePoint RCE flaw exploited to steal machine keys Hackers are actively exploiting CVE-2026-50522 in Microsoft SharePoint to steal machine keys, allowing them to maintain persistent access even after the servers have been patched. |
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect VPNs to breach enterprise networks, emphasizing the rapid weaponization of edge device flaws. |
Critical wp2shell WordPress flaws exploited to install webshells Threat actors began exploiting the "wp2shell" vulnerability chain (CVE-2026-63030 and CVE-2026-60137) within hours of patch release, deploying persistent webshells and malicious plugins across affected WordPress sites. |
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware A massive software supply chain campaign has leveraged over 7,600 malicious GitHub repositories, generating 14 million downloads to distribute SmartLoader and StealC infostealers. |
|
■ CVEs IDENTIFIED CVE-2026-50522 Microsoft SharePoint Server — Deserialization Remote Code Execution (RCE) and machine key theft |
CVE-2026-63030 WordPress Core (wp2shell) — Remote Code Execution and webshell installation |
CVE-2026-60137 WordPress Core (wp2shell) — Remote Code Execution and webshell installation |
[CVE-TBD] Palo Alto Networks PAN-OS GlobalProtect — Authentication Bypass leading to ransomware deployment |
|
■ THREAT ACTORS Qilin (aka Agenda) | Ransomware Group |
Exploiting PAN-OS GlobalProtect authentication bypass for initial access and network intrusion. |
Claimed responsibility for a cyberattack on Coca-Cola Fairlife, threatening data leaks. |
FakeGit Operators | Cybercrime Group |
Operating 7,600 malicious GitHub repos to distribute SmartLoader and StealC malware. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Qilin ransomware exploiting PAN-OS; attackers exploiting SharePoint CVE-2026-50522 and WordPress wp2shell. |
| T1505.003 | | Server Software Component: Web Shell | Attackers deploying webshells via WordPress wp2shell vulnerabilities. |
| T1204.002 | | User Execution: Malicious File | Users downloading SmartLoader and StealC from FakeGit GitHub repositories. |
| T1071.004 | | Application Layer Protocol: DNS/Web Protocols | HollowGraph malware using Microsoft 365 Calendar for C2. |
| T1090 | | Proxy | LG Smart TV apps turning devices into residential proxy nodes. |
| T1553.004 | | Subvert Trust Controls: Install Root Certificate / Steal Keys | SharePoint exploitation used to steal machine keys. |
|
■ PATCH PRIORITY Microsoft SharePoint Server — CVE-2026-50522 is actively exploited to steal machine keys and maintain persistent access — [BC] |
Palo Alto Networks PAN-OS GlobalProtect — Critical authentication bypass is actively exploited by Qilin ransomware for initial access — [THN] |
WordPress Core — wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) is actively exploited to install webshells — [BC] |
Zimbra Collaboration — Patched critical SNMP command injection and multiple XSS vulnerabilities — [THN] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Microsoft SharePoint Server immediately to address CVE-2026-50522, and rotate all machine keys as attackers are known to steal them to maintain access post-patch. |
| 2 | [P1] Apply security updates to Palo Alto Networks PAN-OS GlobalProtect VPN to mitigate the critical authentication bypass vulnerability currently being exploited by the Qilin ransomware group. |
| 3 | [P1] Update WordPress Core to remediate the critical wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) to prevent webshell installation. |
| 4 | [P2] Apply the latest Zimbra Collaboration patches to resolve the critical SNMP command injection and cross-site scripting (XSS) vulnerabilities. |
| 5 | [P2] Audit defense contractor supply chains and software dependencies to comply with the new executive order on end-to-end supply chain visibility. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |