Here are today’s top cybersecurity stories for Monday, July 20, 2026.
WordPress wp2shell RCE CVE-2026-63030 and CVE-2026-60137 Flaws Draw Active Exploitation as Public Exploits Circulate
Public proof-of-concept exploits for two chained WordPress core vulnerabilities, collectively dubbed “wp2shell,” appeared on GitHub by July 18, and multiple security vendors confirmed attacks in the wild as of July 20. CVE-2026-63030 is a REST API batch-route array desynchronization bug that bypasses access controls without authentication; CVE-2026-60137 is a SQL injection flaw in WordPress core reached through that bypass, resulting in unauthenticated remote code execution. All WordPress sites running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1 are affected. WordPress.org shipped emergency patches in versions 7.0.2, 6.9.5, and 6.8.6 and force-pushed auto-updates to affected sites.
BleepingComputer
ServiceNow CVE-2026-6875 Pre-Auth RCE Now Exploited Days After Patch Release
Threat intelligence firm Defused confirmed exploitation of CVE-2026-6875, a critical pre-authentication sandbox escape and remote code execution vulnerability in the ServiceNow AI Platform, with attacks first observed July 19, 2026 — less than one week after ServiceNow shipped patches. The flaw, scored CVSS 9.5, allows unauthenticated attackers to escape the sandbox and execute arbitrary code on self-hosted instances. Defused also identified a second gadget chain reaching the same code-execution primitive through a different bypass route than the published proof of concept.
BleepingComputer / Help Net Security
Hugging Face Production Infrastructure Breached by Autonomous AI Agent
Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent system that executed over 17,000 individual logged actions. The intrusion began in Hugging Face’s data-processing pipeline, with the attacker escalating from a code-execution primitive in a dataset loader to node-level cluster access, harvesting cloud and cluster credentials and moving laterally over a weekend. No tampering with public models, datasets, or Spaces was detected. Hugging Face used LLM-based anomaly detection to surface the compromise.
BleepingComputer / SecurityWeek
HollowGraph Malware Turns Microsoft 365 Calendar Appointments Into a Covert C2 Channel
Group-IB researchers identified HollowGraph, a Windows malware attributed with high confidence to the Cavern backdoor framework and bearing technical similarities to the Iranian-nexus threat actor Lyceum. HollowGraph abuses the Microsoft Graph API to read encrypted attacker commands from — and exfiltrate stolen files to — Calendar appointments dated May 13, 2050 in compromised Microsoft 365 mailboxes, never contacting attacker-owned infrastructure directly. Twelve infected systems were identified, with earliest observed attacker communication traced to June 3, 2026.
BleepingComputer / The Hacker News
Russian Intelligence Compromises 87,000 IP Cameras to Track NATO Military Logistics
Dutch intelligence agencies AIVD and MIVD issued a joint advisory confirming at least one Russian intelligence service has compromised internet-connected cameras across NATO and EU member states and Ukraine to monitor weapons shipments, military transport routes, and troop positions. Attackers target devices with default passwords, outdated firmware, and direct internet exposure — primarily inexpensive Hikvision and Dahua cameras — and use automated image-recognition software to classify military vehicle movements. In Ukraine, harvested video feeds have in some cases been used to locate military personnel for kinetic strikes. Internet exposure data from Censys flags approximately 87,000 potentially affected devices in Europe alone.
The Hacker News
SleeperGem: Three Malicious RubyGems Packages Delivered via Hijacked Dormant Accounts
Researchers at Aikido Security identified a supply chain attack codenamed SleeperGem after attackers published three malicious gems to RubyGems by taking over developer accounts dormant for six to seven years. The rogue packages — including git_credential_manager (versions 2.8.0–2.8.3, published July 18), Dendreo, and fastlane-plugin-run_tests_firebase_testlab — function as loaders that fetch a second-stage payload from an attacker-controlled Forgejo host and install persistence on developer machines. The loader checks for CI/CD build environments and skips execution there, targeting only developer workstations. All machines that installed these packages should be treated as compromised.
The Hacker News
7-Zip CVE-2026-14266: Heap Buffer Overflow in XZ Decoder Fixed in Version 26.02
Trend Micro’s Zero Day Initiative detailed CVE-2026-14266, a heap-based buffer overflow in 7-Zip’s XZ archive decoder, on July 15. The vulnerability arises from an off-by-one error in output buffer length tracking during XZ decompression and allows code execution when a user opens a crafted archive. Affected versions span 7-Zip 21.07 through 26.01. A fix shipped in version 26.02 on June 25, 2026. No exploitation in the wild has been reported.
The Hacker News
Russian-Speaking Hacker Uses Jailbroken Gemini CLI to Deploy and Manage Live Botnet
A Russian-speaking threat actor known as “bandcampro” outsourced nearly all technical operations for a live botnet to Google’s open-source Gemini CLI, which was jailbroken to bypass safety controls. Analysis of over 200 AI session logs between March 19 and April 21, 2026, showed the AI serving as the primary hacking agent — writing exploitation code, migrating C2 infrastructure in six minutes, harvesting credentials from an OpenDental dental clinic database, and targeting WordPress admin panels. The attacker issued instructions in Russian and did no debugging himself. Cryptocurrency fraud schemes targeting elderly individuals in the United States and Canada were also planned through the same AI interface.
The Hacker News / BleepingComputer
Abbott Laboratories Investigates Two Separate Cyber Incidents Amid Extortion Claims
Abbott Laboratories confirmed it is investigating two separate cybersecurity incidents. The first involves ShinyHunters claiming unauthorized access to legacy Exact Sciences systems in Abbott’s Cancer Diagnostics business as of mid-June 2026, with allegations of lateral movement across multiple SaaS platforms. The second involves threat actor ShadowByt3$ claiming access to the LabCentral customer portal on July 4, 2026. Abbott stated its operations were not affected and no confirmed client data impact has been established as of July 17.
BleepingComputer
Microsoft Confirms Windows Server Update Services Sync Failures Affecting Patch Management
Microsoft confirmed it is working to resolve a known issue causing Windows Server Update Services synchronization failures and timeouts that have affected administrators for more than a week. The problem prevents WSUS servers from pulling updates from Windows Update, stalling patch management pipelines across enterprise environments. No root cause has been publicly confirmed and no workaround is available. Organizations relying on WSUS for software distribution should monitor their consoles for uncharacteristic gaps in update delivery.
BleepingComputer
Stay tuned for today’s in-depth analysis posts.






