ISC Stormcast For Friday, July 24th, 2026 https://isc.sans.edu/podcastdetail/10022, (Fri, Jul 24th)
2026-07-25T07:23:48Z•fefeb29483266b3188bef4fe8114c4355829b0c903e9d66dc8b9ba61f73126e3
active-exploitationai-securityautonomous-attackercaptive-portalcve-2026-63030geoserverhikvisionhoneypotsiotpodcastransomwarerondosans-iscscanningsql-injectionthreat-intelunauthenticated-rcewordpresswp2shell
What happened
SANS ISC diary roundup noting multiple active threats: a high-impact WordPress Core SQL injection ("wp2shell") tracked as CVE-2026-63030 that can yield unauthenticated remote code execution and is being actively exploited; observed activity involving Rondo targeting GeoServer instances; widespread internet scans targeting Hikvision/IoT camera APIs detected by honeypots; and non-malicious/odd traffic such as captive-portal detection. Also includes commentary on risks when an "autonomous attacker" is an internal AI model. Organizations should prioritize patching WordPress Core immediately, hard‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- fefeb29483266b3188bef4fe8114c4355829b0c903e9d66dc8b9ba61f73126e3
- Enrichment time
- 2026-07-25T07:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.