ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st)
2026-07-21T07:23:45Z•c20fc8a2fd79542753025fe55ae4b2215da01d749027050eae08f94bec2d4196
CVE-2026-63030chromiumdshieldedgeexploitationhikvisionhoneypotinternet-scanningiot-scanningmicrosoft-patch-tuesdaypatch-managementsiemsql-injectionunauthenticated-rcewordpresswp2shell
What happened
The ISC SANS diary highlights active exploitation of a new WordPress Core SQL injection named “wp2shell” (CVE-2026-63030) that can lead to unauthenticated remote code execution, plus internet-wide scans targeting Hikvision cameras and a large Microsoft July 2026 Patch Tuesday (hundreds of fixes including 62 critical and many Chromium/Edge issues, with some already exploited). DShield SIEM received an update; honeypots continue to observe scanning and compromise activity. Immediate actions: patch WordPress core or apply vendor mitigations for CVE-2026-63030, deploy WAF/IDS rules to block known
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c20fc8a2fd79542753025fe55ae4b2215da01d749027050eae08f94bec2d4196
- Enrichment time
- 2026-07-21T07:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.