SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, July 23, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY SharePoint and Langflow Flaws Face Active Exploitation | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 34 ARTICLES |
|
■ ANALYST TLDR Active exploitation of critical vulnerabilities in Microsoft SharePoint (CVE-2026-50522) and the Langflow AI framework highlights an immediate threat to enterprise collaboration tools and AI development pipelines. Concurrently, a high-severity path traversal flaw in the Windmill developer platform (CVE-2026-29059) and a silent data exfiltration vulnerability in the Adobe Acrobat Chrome extension are actively putting sensitive server files and messaging data at risk. Organizations must also defend against credential-stuffing campaigns and sophisticated phishing kits like Kratos that bypass multi-factor authentication to compromise corporate accounts. |
|
■ CRITICAL STORIES Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Threat actors are actively exploiting CVE-2026-50522 in Microsoft SharePoint to steal machine keys, allowing them to bypass security controls and maintain persistent, long-term access to corporate networks. |
CISA orders urgent action on actively exploited Langflow RCE flaw CISA has added an actively exploited remote code execution (RCE) vulnerability in the Langflow visual framework to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure their AI agent-building systems immediately. |
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication An unauthenticated path traversal vulnerability (CVE-2026-29059) in the Windmill developer platform is being actively exploited in the wild, enabling remote attackers to read sensitive configuration and server files. |
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data A newly disclosed vulnerability chain in the Adobe Acrobat Chrome extension allows malicious websites to silently hijack and exfiltrate private WhatsApp Web conversations and contact lists without requiring user authentication. |
|
■ CVEs IDENTIFIED CVE-2026-50522 Microsoft — SharePoint — Machine key theft and persistent unauthorized access |
CVE-2026-29059 Windmill Labs — Windmill — Unauthenticated path traversal and arbitrary file read |
[CVE-TBD] Langflow — Langflow Visual Framework — Remote code execution via visual AI agent builder |
[CVE-TBD] Adobe — Acrobat Chrome Extension — Silent information disclosure and WhatsApp Web data hijacking |
|
■ THREAT ACTORS Targeted South Korean collaborative-work software vendors in a supply chain compromise campaign. |
Breached a shared data exchange platform and demanded a $12.3 million ransom from Swiss rail manufacturer Stadler Rail. |
Conducted targeted attacks on operational technology (OT) systems, manipulating SCADA and HMI displays using malicious project files. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Used to exploit SharePoint (CVE-2026-50522), Windmill (CVE-2026-29059), and Langflow. |
| T1068 | | Exploitation for Privilege Escalation | Utilized via the snap-confine vulnerability to obtain root access on Ubuntu. |
| T1195 | | Supply Chain Compromise | Employed by Kimsuky to target South Korean collaborative software vendors. |
| T1110.004 | | Credential Stuffing | Used to hijack Chick-fil-A One loyalty accounts. |
| T1566 | | Phishing | Distributed via the Kratos phishing kit to harvest credentials. |
| T1111 | | Multi-Factor Authentication Bypass | Executed by the Kratos phishing kit to steal active Microsoft 365 sessions. |
|
■ PATCH PRIORITY CRITICAL — Microsoft — SharePoint (CVE-2026-50522) — Actively exploited to steal machine keys and establish persistent access — [SW] Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks |
CRITICAL — Langflow — Langflow Visual Framework ([CVE-TBD]) — Actively exploited RCE vulnerability targeted in the wild and flagged by CISA — [BC] CISA orders urgent action on actively exploited Langflow RCE flaw |
HIGH — Windmill Labs — Windmill (CVE-2026-29059) — High-severity path traversal under active exploitation to read arbitrary server files — [THN] Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication |
HIGH — Canonical — snap-confine ([CVE-TBD]) — Local privilege escalation vulnerability giving root access on default Ubuntu desktops — [THN] Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Microsoft SharePoint immediately to remediate CVE-2026-50522 and prevent attackers from stealing machine keys. |
| 2 | [P1] Update the Langflow visual framework to the latest secure version to mitigate the actively exploited RCE vulnerability. |
| 3 | [P1] Apply security updates to Windmill developer platform instances to address the CVE-2026-29059 path traversal vulnerability. |
| 4 | [P2] Force an immediate update of the Adobe Acrobat Chrome extension across all enterprise endpoints to block WhatsApp Web data hijacking. |
| 5 | [P2] Update Canonical snap-confine on all Ubuntu desktop deployments to eliminate the risk of local privilege escalation to root. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |