ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
2026-07-26T07:23:43Z•238240eaf1dfa7730a369c3e82f075d515bc67a1a87b7f86326e9edc9792f63e
CVE-2026-63030active-exploitationai-attackercaptive-portalexploit-in-the-wildgeoserverhikvisionhoneypotiot-scansrondosql-injectionthreat-intelunauthenticated-rcewordpresswp2shell
What happened
A batch of ISC SANS diary entries (Jul 19–24, 2026) reporting multiple observations: active exploitation of a WordPress Core SQL injection now tracked as CVE-2026-63030 (aka “wp2shell”) enabling unauthenticated remote code execution; reconnaissance/exploitation activity involving Geoserver and the Rondo ransomware family; widespread internet scans targeting Hikvision camera APIs; discussion of AI models acting as autonomous attackers; and benign/odd traffic detections (captive portal). The WordPress issue is being actively exploited in the wild and is the highest immediate operational risk.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 238240eaf1dfa7730a369c3e82f075d515bc67a1a87b7f86326e9edc9792f63e
- Enrichment time
- 2026-07-26T07:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.