π‘οΈ CyberShield Weekly
July 13 β July 19, 2026
|
|
Hey there,
This was a heavy week for defenders. CISA flagged active exploitation of SharePoint, a ransomware crew chained two SonicWall zero-days into root access, and Microsoft shipped its biggest Patch Tuesday on record. On top of it all, a fresh WordPress core flaw landed with a public proof-of-concept. Here's everything you need to know, and why it matters for your work.
|
π¨ Critical Threats & Active Exploits
|
CISA warns admins to patch actively exploited SharePoint flaws
CISA confirmed attackers are actively exploiting three vulnerabilities in on-premises SharePoint Server instances exposed to the internet. If you administer SharePoint, patch now β this isn't theoretical risk, it's live exploitation. Read more β
|
Inc ransomware chains two SonicWall SMA zero-days for root access
Two vulnerabilities in SonicWall's Secure Mobile Access appliances β one an improper security control, the other insufficient input validation β combine to give attackers root-level control. Inc ransomware is already exploiting the pair in the wild. Read more β
|
New "wp2shell" flaw lets unauthenticated attackers run code on WordPress
A critical core-level flaw in WordPress 6.9 and 7.0 lets an anonymous HTTP request execute code β no plugins required. CVEs are assigned and a working proof-of-concept is already public, so expect mass scanning soon. Read more β
|
Cursor auto-executes git.exe from cloned repos on Windows β no prompt
If a cloned repo contains a file named git.exe in its project root, Cursor on Windows runs it automatically β no click, no warning β with your permissions, potentially exposing SSH keys and cloud tokens for as long as the project stays open. Read more β
|
Compromised jscrambler npm release drops a cross-platform infostealer
Version 8.14.0 of jscrambler shipped with a malicious preinstall hook that drops a native infostealer on Windows, macOS, and Linux alike. Socket flagged it just six minutes after publish β a good reminder of why supply-chain monitoring matters. Read more β
|
π οΈ Patches, Tools & Defense Strategy
|
Microsoft's biggest Patch Tuesday on record β 570+ flaws fixed
Microsoft patched over 570 vulnerabilities this month (Talos put the fuller count at 622, with 57 critical and two exploited in the wild) β nearly triple the prior record, with AI-assisted vulnerability discovery credited for the surge. Talos called it fittingly: the Patch Wars have begun. Prioritize testing and rollout this week. Read more β
|
Update now: 7-Zip patches an RCE flaw in malicious archives
7-Zip 26.02 fixes a remote code execution bug triggered simply by opening a specially crafted compressed file. If you or your org still rely on 7-Zip, push the update. Read more β
|
Cisco Talos discloses 18 vulnerabilities across WolfSSL, GeoVision, VTK
Three in WolfSSL, fourteen in GeoVision, one in VTK-DICOM β all responsibly disclosed and patched by vendors. A clean example of coordinated disclosure working as intended. Read more β
|
Australia warns of a global campaign hitting vulnerable CMS platforms
The Australian Cyber Security Centre flagged active exploitation of outdated CMS platforms and plugins worldwide. Regular patching and a web application firewall go a long way here. Read more β
|
π° Industry & Policy
|
White House launches an AI cybersecurity clearinghouse
A new centralized hub aims to speed up threat-intel sharing between government, private industry, and international partners on AI-driven cyber threats. Read more β
|
Oak raises $60M to fix the identity mess AI agents are making worse
As autonomous AI agents multiply, so do the identity and access problems they create. Israeli startup Oak just came out of stealth with serious backing to tackle it β a space worth watching. Read more β
|
Nigeria deepens cybersecurity efforts as cybercrime profits climb
New mandatory-disclosure rules for cyberattacks are part of a broader global trend toward transparency β a policy shift worth tracking if you work in compliance or GRC. Read more β
|
Jen Ellis honored with an MBE for security researcher advocacy
Ellis has spent years bridging the security research community and policymakers, pushing for legal protections and responsible disclosure norms. A good reminder that policy work is cybersecurity work too. Read more β
|
Felons, fraudsters flog an offensive cybersecurity startup
A new startup offering big payouts for zero-days is run by founders with a history of fake intelligence companies and false identities. Vet who you're selling vulnerabilities to β reputation and legitimacy matter as much as the paycheck. Read more β
|
Sponsored
|
π Build your project pages fast with Carrd
Need a clean landing page for a CTF write-up hub, tool release, or personal portfolio? Carrd is the lightweight builder I use to spin up project and portfolio pages in minutes, no full CMS required. Check it out β
Transparency: this is an affiliate link β if you sign up, it may support CyberShield at no extra cost to you.
|
π¨ Level up your reports with this Canva pack for blue/red teamers
A ready-to-edit Canva pack with incident-timeline templates, IR one-pagers, threat-model diagrams, and CTF write-up layouts β built so your technical work looks as sharp as your analysis. Free Canva account works. Get the pack β
Transparency: this is an affiliate link β if you sign up, it may support CyberShield at no extra cost to you.
|
That's the week. Patch what you can, question what you can't, and keep building your skills one CVE at a time.
Stay sharp, The CyberShield Team π‘οΈ
|