ISC Stormcast For Wednesday, July 22nd, 2026 https://isc.sans.edu/podcastdetail/10018, (Wed, Jul 22nd)

2026-07-22T13:23:44Zb37595370338b6e206f17c960765fd75b22813f455180ce03356aed997d69729
captive-portalcve-2026-63030dshieldexploitationhikvisionhoneypotiotreconnaissanceremote-code-executionscanningsecurity-updatesiemsql-injectionwordpresswp2shell

What happened

SANS ISC diary roundup (Jul 14–22, 2026): Active exploitation observed for a newly assigned WordPress Core vulnerability (wp2shell, CVE-2026-63030) — an SQL injection in core that can lead to unauthenticated remote code execution. ISC notes exploitation activity following disclosure. Other items: internet-wide scans targeting Hikvision Intelligent Security API and continued targeting of IoT/camera devices; benign-looking captive portal detection traffic seen by honeypots; and a DShield SIEM update (ELK 8.19.15) with added dashboards/logs. Multiple Stormcast podcast entries also published.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
b37595370338b6e206f17c960765fd75b22813f455180ce03356aed997d69729
Enrichment time
2026-07-22T13:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.