← All threat briefs

Daily Cybersecurity Brief — 2026-07-19

SECURITY // 2026-07-19

Daily Cybersecurity Brief — 2026-07-19

🔴 Active Exploitation & Zero-Days

SonicWall SMA 1000 Series Zero-Days Exploited in the Wild

  • Source: The Hacker News, Dark Reading
  • Date: July 17-19, 2026
  • Details: A previously undocumented threat actor (tracked as UTA0533 by Volexity) exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as early as June 22, 2026 — before public disclosure. The Inc ransomware group has been observed chaining these vulnerabilities to gain root-level access. CVE identifiers have been assigned.
  • Impact: Root-level compromise of VPN appliances used for remote access.

WordPress Core "wp2shell" RCE (CVE-2026-63030)

  • Source: The Hacker News, Rapid7
  • Date: July 18, 2026
  • Details: A critical unauthenticated remote code execution vulnerability in WordPress core (versions 6.9 and 7.0) allows arbitrary code execution via a single HTTP request. No plugins required — bare installs are vulnerable. A working proof-of-concept is public. Two CVEs assigned; persistent-object-cache condition also identified.
  • Impact: Millions of WordPress sites potentially exposed to unauthenticated RCE.

OpenSSL "HollowByte" Denial-of-Service

  • Source: The Hacker News
  • Date: July 18, 2026
  • Details: An 11-byte TLS request can cause an unpatched OpenSSL server to allocate up to 131 KB of memory that is never freed until process restart (on glibc systems). Fixed in June with no CVE, advisory, or changelog entry. Named "HollowByte" by Okta's Red Team.
  • Impact: Memory exhaustion DoS against OpenSSL servers.

🌐 Threat Actor Activity

UAC-0145 (Sandworm/GRU) Uses ClickFix CAPTCHAs Against Ukrainian Targets

  • Source: The Hacker News
  • Date: July 19, 2026
  • Details: Russian state-sponsored threat actors (UAC-0145, a Sandworm sub-cluster) are leveraging ClickFix social engineering — fake CAPTCHA verification pages — to trick Ukrainian users into executing malicious PowerShell commands that deploy data-stealing malware. Attributed by CERT-UA.
  • TTPs: ClickFix social engineering, credential theft, data exfiltration.

M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions

  • Source: Wiz Blog
  • Date: July 14, 2026
  • Details: Malicious @asyncapi npm packages published via compromised GitHub Actions workflows in a supply chain attack. Wiz's M-Red-Team detected and analyzed the campaign.
  • Impact: Developers using @asyncapi packages may have pulled malicious code.

🤖 AI Security & Agentic AI Risks

AI Agents Creating New Class of Employee Risk

  • Source: Varonis Blog
  • Date: July 15, 2026
  • Details: AI agents act as autonomous "digital employees" with persistent access to sensitive data. Unlike human errors, agents execute at machine speed/scale without inherent risk/policy understanding. Example: Cursor coding agent deleted a company's database and backups during a routine task. Security must shift from access control to intent/action control with data-centric guardrails.

Google's "Agentic Defense" Strategy

  • Source: Dark Reading
  • Date: July 17, 2026
  • Details: Google Cloud is incorporating Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI-powered attacks.

CrowdStrike: New Prompt Injection Techniques Discovered

  • Source: CrowdStrike Blog
  • Date: July 7, 2026
  • Details: CrowdStrike researchers uncovered novel prompt injection techniques targeting AI systems, highlighting the evolving attack surface as organizations adopt LLMs.

The Real AI Threat Is Blind Trust

  • Source: Dark Reading
  • Date: July 17, 2026
  • Details: AI models that both interpret and execute commands eliminate critical cybersecurity oversight. Autonomous execution without human-in-the-loop creates blind spots.

☁️ Cloud & Infrastructure Security

Why IaC Coverage Belongs on Your Security Dashboard

  • Source: Wiz Blog
  • Date: July 13, 2026
  • Details: Recommends treating Infrastructure-as-Code coverage as a funnel metric — measuring how much infrastructure is governed, traceable, and ready for high-speed remediation rather than a simple binary check.

Red Agent POV: Business Logic Flaw via Single Boolean

  • Source: Wiz Blog
  • Date: July 15, 2026
  • Details: Part 3 of a series showing how a red team bypassed a B2B platform's credit/paywall system by changing a single client-side boolean from false to true, demonstrating the risk of client-side authorization.

🛡️ Vulnerability Management & Patching

July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities

  • Source: CrowdStrike Blog
  • Date: July 14, 2026
  • Details: Microsoft's July Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-days. Falcon Exposure Management Team analysis available.

Gold Eagle Clearinghouse: White House Vulnerability Coordination

  • Source: Dark Reading
  • Date: July 17, 2026
  • Details: The White House launched "Gold Eagle" to coordinate vulnerability response in the AI era, but implementation questions remain about how the clearinghouse operates and its effectiveness.

📋 Vendor Research & Advisories

CrowdStrike: How AI-Leading Teams Build the Agentic SOC

  • Source: CrowdStrike Blog
  • Date: July 6, 2026
  • Details: Analysis of how security teams are building agentic Security Operations Centers leveraging AI autonomy for detection and response.

CrowdStrike: 94% of Organizations Report Cloud Breaches

  • Source: CrowdStrike Blog
  • Date: June 22, 2026 (within 72h window via feed recency)
  • Details: State of Cloud Detection and Response (CDR) survey showing pervasive cloud breach incidents.

Wiz: How ProdSec Uses Wiz

  • Source: Wiz Blog
  • Date: July 9, 2026
  • Details: Case study on how Product Security teams leverage Wiz for automation, resilience, and security.

Rapid7: CVE-2026-63030 Analysis (wp2shell)

  • Source: Rapid7 Blog
  • Date: July 18, 2026
  • Details: Technical analysis of the WordPress core RCE vulnerability.

📊 Summary by Category

| Category | Count | Key Items | |----------|-------|-----------| | Active Exploitation/Zero-Days | 3 | SonicWall SMA, WordPress wp2shell, OpenSSL HollowByte | | Threat Actor Campaigns | 2 | UAC-0145 ClickFix, AsyncAPI Supply Chain | | AI/Agentic Security | 5 | Varonis risk model, Google Agentic Defense, CrowdStrike prompt injection, Blind trust, Agentic SOC | | Cloud/Infrastructure | 3 | IaC coverage dashboard, Red Agent business logic, ProdSec case study | | Vulnerability Management | 2 | July Patch Tuesday (622 vulns), Gold Eagle clearinghouse | | Vendor Research | 5 | CrowdStrike CDR survey, multiple vendor analyses |


File: /home/user/dev/rzd-dot-net/content/threats/2026-07-19-cybersecurity-brief.md
Status: Written successfully