profile

CyberSHIELD | CybersecurityOS πŸ›‘οΈ

This Week in Cybersecurity: Active Exploits, a Record Patch Tuesday & AI's Identity Problem


πŸ›‘οΈ CyberShield Weekly
July 13 – July 19, 2026

Hey there,

This was a heavy week for defenders. CISA flagged active exploitation of SharePoint, a ransomware crew chained two SonicWall zero-days into root access, and Microsoft shipped its biggest Patch Tuesday on record. On top of it all, a fresh WordPress core flaw landed with a public proof-of-concept. Here's everything you need to know, and why it matters for your work.

🚨 Critical Threats & Active Exploits

CISA warning icon over Microsoft SharePoint logo, symbolizing actively exploited vulnerabilities

CISA warns admins to patch actively exploited SharePoint flaws

CISA confirmed attackers are actively exploiting three vulnerabilities in on-premises SharePoint Server instances exposed to the internet. If you administer SharePoint, patch now β€” this isn't theoretical risk, it's live exploitation. Read more β†’

Illustration of ransomware exploiting SonicWall SMA firewall zero-day vulnerabilities

Inc ransomware chains two SonicWall SMA zero-days for root access

Two vulnerabilities in SonicWall's Secure Mobile Access appliances β€” one an improper security control, the other insufficient input validation β€” combine to give attackers root-level control. Inc ransomware is already exploiting the pair in the wild. Read more β†’

WordPress logo with a broken lock icon representing the wp2shell unauthenticated code execution flaw

New "wp2shell" flaw lets unauthenticated attackers run code on WordPress

A critical core-level flaw in WordPress 6.9 and 7.0 lets an anonymous HTTP request execute code β€” no plugins required. CVEs are assigned and a working proof-of-concept is already public, so expect mass scanning soon. Read more β†’

Cursor code editor icon with a warning symbol representing the Windows auto-execution flaw

Cursor auto-executes git.exe from cloned repos on Windows β€” no prompt

If a cloned repo contains a file named git.exe in its project root, Cursor on Windows runs it automatically β€” no click, no warning β€” with your permissions, potentially exposing SSH keys and cloud tokens for as long as the project stays open. Read more β†’

npm logo with a skull icon representing the compromised jscrambler package delivering an infostealer

Compromised jscrambler npm release drops a cross-platform infostealer

Version 8.14.0 of jscrambler shipped with a malicious preinstall hook that drops a native infostealer on Windows, macOS, and Linux alike. Socket flagged it just six minutes after publish β€” a good reminder of why supply-chain monitoring matters. Read more β†’

πŸ› οΈ Patches, Tools & Defense Strategy

Microsoft logo surrounded by patch and shield icons representing a record-breaking Patch Tuesday

Microsoft's biggest Patch Tuesday on record β€” 570+ flaws fixed

Microsoft patched over 570 vulnerabilities this month (Talos put the fuller count at 622, with 57 critical and two exploited in the wild) β€” nearly triple the prior record, with AI-assisted vulnerability discovery credited for the surge. Talos called it fittingly: the Patch Wars have begun. Prioritize testing and rollout this week. Read more β†’

7-Zip logo with a shield icon representing the patched remote code execution flaw

Update now: 7-Zip patches an RCE flaw in malicious archives

7-Zip 26.02 fixes a remote code execution bug triggered simply by opening a specially crafted compressed file. If you or your org still rely on 7-Zip, push the update. Read more β†’

Icons for WolfSSL, GeoVision, and VTK software with vulnerability warning symbols

Cisco Talos discloses 18 vulnerabilities across WolfSSL, GeoVision, VTK

Three in WolfSSL, fourteen in GeoVision, one in VTK-DICOM β€” all responsibly disclosed and patched by vendors. A clean example of coordinated disclosure working as intended. Read more β†’

Global map icon with warning symbols over CMS platform logos

Australia warns of a global campaign hitting vulnerable CMS platforms

The Australian Cyber Security Centre flagged active exploitation of outdated CMS platforms and plugins worldwide. Regular patching and a web application firewall go a long way here. Read more β†’

πŸ“° Industry & Policy

White House building icon with AI and cybersecurity shield graphics

White House launches an AI cybersecurity clearinghouse

A new centralized hub aims to speed up threat-intel sharing between government, private industry, and international partners on AI-driven cyber threats. Read more β†’

Oak startup logo with identity and AI agent icons

Oak raises $60M to fix the identity mess AI agents are making worse

As autonomous AI agents multiply, so do the identity and access problems they create. Israeli startup Oak just came out of stealth with serious backing to tackle it β€” a space worth watching. Read more β†’

Map graphic highlighting Nigeria with cybersecurity shield icon

Nigeria deepens cybersecurity efforts as cybercrime profits climb

New mandatory-disclosure rules for cyberattacks are part of a broader global trend toward transparency β€” a policy shift worth tracking if you work in compliance or GRC. Read more β†’

Portrait-style icon representing a cybersecurity policy advocate bridging tech and government

Jen Ellis honored with an MBE for security researcher advocacy

Ellis has spent years bridging the security research community and policymakers, pushing for legal protections and responsible disclosure norms. A good reminder that policy work is cybersecurity work too. Read more β†’

Silhouette icons representing a controversial cybersecurity startup's leadership

Felons, fraudsters flog an offensive cybersecurity startup

A new startup offering big payouts for zero-days is run by founders with a history of fake intelligence companies and false identities. Vet who you're selling vulnerabilities to β€” reputation and legitimacy matter as much as the paycheck. Read more β†’


Sponsored

πŸ”— Build your project pages fast with Carrd

Need a clean landing page for a CTF write-up hub, tool release, or personal portfolio? Carrd is the lightweight builder I use to spin up project and portfolio pages in minutes, no full CMS required. Check it out β†’

Transparency: this is an affiliate link β€” if you sign up, it may support CyberShield at no extra cost to you.

🎨 Level up your reports with this Canva pack for blue/red teamers

A ready-to-edit Canva pack with incident-timeline templates, IR one-pagers, threat-model diagrams, and CTF write-up layouts β€” built so your technical work looks as sharp as your analysis. Free Canva account works. Get the pack β†’

Transparency: this is an affiliate link β€” if you sign up, it may support CyberShield at no extra cost to you.


That's the week. Patch what you can, question what you can't, and keep building your skills one CVE at a time.

Stay sharp,
The CyberShield Team πŸ›‘οΈ

CyberSHIELD | CybersecurityOS πŸ›‘οΈ

Engineering security from first principles. I'm d0uble 3L, I write CybersecurityOS, where I break down secure-by-design architecture, DevSecOps, cloud security, and emerging-tech risk into practical frameworks for engineers, leaders, and teams. Weekly perspectives, clarity over complexity.

Share this page