ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)

2026-07-21T07:23:45Zc20fc8a2fd79542753025fe55ae4b2215da01d749027050eae08f94bec2d4196
CVE-2026-63030chromiumdshieldedgeexploitationhikvisionhoneypotinternet-scanningiot-scanningmicrosoft-patch-tuesdaypatch-managementsiemsql-injectionunauthenticated-rcewordpresswp2shell

What happened

The ISC SANS diary highlights active exploitation of a new WordPress Core SQL injection named “wp2shell” (CVE-2026-63030) that can lead to unauthenticated remote code execution, plus internet-wide scans targeting Hikvision cameras and a large Microsoft July 2026 Patch Tuesday (hundreds of fixes including 62 critical and many Chromium/Edge issues, with some already exploited). DShield SIEM received an update; honeypots continue to observe scanning and compromise activity. Immediate actions: patch WordPress core or apply vendor mitigations for CVE-2026-63030, deploy WAF/IDS rules to block known

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c20fc8a2fd79542753025fe55ae4b2215da01d749027050eae08f94bec2d4196
Enrichment time
2026-07-21T07:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) · Baitaphish