ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)

2026-07-24T07:23:47Z6d0efacf340fe805e0845eb53e948fb44e152593c0f00b61868904fa79e3ebfe
CVE-2026-63030ai-attackercaptive-portalexploitationgeoserverhikvisionhoneypotintrusion-analysisiot-cameraisc-sansremote-code-executionscanningsql-injectionwordpresswp2shell

What happened

Feed of ISC SANS diary entries (Jul 19–24, 2026) covering multiple observations and advisories: active exploitation of a WordPress Core SQL injection vulnerability dubbed “wp2shell” now assigned CVE-2026-63030 (unauthenticated SQLi leading to remote code execution); internet-wide scans targeting Hikvision Intelligent Security API (IoT/camera devices); examples of non-malicious honeypot detections such as captive-portal checks; an incident analysis piece on adversarial/AI model misuse; and miscellaneous logs about interactions with GeoServer and daily Stormcast summaries. Immediate action is to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
6d0efacf340fe805e0845eb53e948fb44e152593c0f00b61868904fa79e3ebfe
Enrichment time
2026-07-24T07:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th) · Baitaphish