ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)

2026-07-25T19:23:46Z424b9da67c5682302f63623c4e5f310ddde0c130c3adb2a44f4274a809bacd3f
CVE-2026-63030active-exploitationai-securitycaptive-portalexploitationgeoserverhikvisionhoneypotiot-scanningrcerondosans-iscsql-injectionthreat-intelwordpresswp2shell

What happened

SANS ISC diary entries (19–24 Jul 2026) cover multiple observations: most notably active exploitation of a WordPress Core SQL injection (wp2shell) now tracked as CVE-2026-63030 that can lead to unauthenticated remote code execution and is being actively exploited. Other items include detections of Rondo activity against GeoServer, widespread internet scans targeting Hikvision devices, an incident discussion about attackers emerging from AI models, captive-portal detection noise in honeypots, and daily Stormcast summaries.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
424b9da67c5682302f63623c4e5f310ddde0c130c3adb2a44f4274a809bacd3f
Enrichment time
2026-07-25T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) · Baitaphish