SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSaturday, July 18, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Unauthenticated WordPress Core wp2shell RCE Threatens Millions | CRITICAL |
|
5 C2 IPs | 59 OTX IOCs | 30 ARTICLES |
|
■ ANALYST TLDR Today's intelligence landscape is dominated by critical remote code execution and privilege escalation vulnerabilities, highlighted by the unauthenticated "wp2shell" flaw in WordPress Core and an actively exploited SharePoint RCE. Additionally, threat actors are leveraging a newly disclosed Windows "LegacyHive" zero-day for local privilege escalation, while the "NadMesh" botnet aggressively targets exposed AI services to harvest cloud credentials. Organizations must prioritize immediate patching of public-facing assets and secure development environments against sophisticated supply chain and steganography-based campaigns. |
|
■ CRITICAL STORIES New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code This zero-plugin core vulnerability allows trivial remote code execution on WordPress 6.9 and 7.0 sites, presenting an immediate threat to millions of unpatched web servers. |
New Windows LegacyHive zero-day gives hackers admin privileges A newly released zero-day exploit named LegacyHive bypasses modern Windows defenses to grant local attackers full administrative privileges, requiring immediate monitoring and mitigation. |
Fresh SharePoint Vulnerability Exploited Soon After Disclosure Attackers are actively exploiting a critical-severity SharePoint vulnerability to achieve remote code execution, forcing organizations to accelerate patch cycles. |
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go-based botnet is actively scanning for exposed AI interfaces like ComfyUI and Ollama to harvest AWS credentials and Kubernetes tokens, signaling a shift in threat actor targeting toward AI infrastructure. |
|
■ CVEs IDENTIFIED [CVE-TBD] WordPress Core (6.9, 7.0) — Unauthenticated Remote Code Execution (wp2shell) |
[CVE-TBD] Microsoft Windows — Local Privilege Escalation (LegacyHive zero-day) |
[CVE-TBD] Microsoft SharePoint — Remote Code Execution |
[CVE-TBD] Fortinet FortiSandbox — Active Exploitation / Remote Code Execution |
|
■ THREAT ACTORS CylindricalCanine | APT Subgroup (GoldenEyeDog) |
Attributed to the April 2026 DigiCert breach and code-signing certificate theft. |
Contagious Interview Campaign Actors | APT (North Korea) |
Utilizing steganography in SVG flag images within fake coding tests to deliver OtterCookie-aligned malware. |
NadMesh Operator | Cybercriminal / Botnet Operator |
Scanning for exposed AI services (ComfyUI, Ollama, n8n) to harvest AWS keys and Kubernetes tokens. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Used to exploit WordPress Core (wp2shell), SharePoint, and Fortinet FortiSandbox. |
| T1068 | | Exploitation for Privilege Escalation | Seen in Windows LegacyHive zero-day and Siemens ROX II switch vulnerabilities. |
| T1195.002 | | Compromise Software Supply Chain: Malicious Package | ViteVenom campaign distributing malicious npm packages. |
| T1580 | | Cloud Infrastructure Discovery | NadMesh botnet harvesting AWS keys and Kubernetes tokens from exposed AI services. |
| T1027.003 | | Obfuscated Files or Information: Steganography | North Korean actors hiding OtterCookie malware in SVG flag images. |
| T1486 | | Data Encrypted for Impact | Ransomware attack disrupting Fairlife/Coca-Cola production and Nichirei operations. |
|
■ PATCH PRIORITY WordPress Core — Unauthenticated RCE vulnerability (wp2shell) exploitable on bare installs — [THN] |
Microsoft SharePoint — Critical RCE vulnerability actively exploited in the wild shortly after disclosure — [SW] |
Fortinet FortiSandbox — Two actively exploited vulnerabilities highlighted by CISA — [BC] |
Microsoft Windows — LegacyHive zero-day privilege escalation exploit released publicly — [BC] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately update WordPress Core installations to versions 6.9.5 or 7.0.2 to remediate the critical wp2shell unauthenticated RCE vulnerability ([CVE-TBD]). |
| 2 | [P1] Apply emergency patches to Microsoft SharePoint servers to mitigate the actively exploited RCE vulnerability ([CVE-TBD]). |
| 3 | [P1] Implement CISA-mandated patches for the two actively exploited vulnerabilities in the Fortinet FortiSandbox platform ([CVE-TBD]). |
| 4 | [P2] Deploy host-based detection rules to monitor for unauthorized registry access and privilege escalation attempts associated with the Windows LegacyHive zero-day ([CVE-TBD]). |
| 5 | [P2] Audit and restrict public access to AI development interfaces, specifically ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio, to prevent exploitation by the NadMesh botnet. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |