Why Modern SOCs Need Multi-Layered Detections
2026-07-22T13:24:09Z•df7be45f6c10b5be427e5d5d7b061163094020cfdb0ac8b471157abe92ee22c5
7-zipactive-exploitationai-securityencforgefakegithollowgraphkratosmfa-bypassnuget-typosquatpan-osphishingransomwareremote-code-executionservicenowsharepointsupply-chainweekly-roundupwordpresswp2shellzero-day
What happened
A multi-item security roundup covering July 20–22, 2026: highlights include law‑enforcement takedown of the Kratos phishing kit, a trojanized Newtonsoft.Json NuGet typosquat, multiple AI-related attack vectors (sandbox escapes, AI agents abused to run commands, OpenAI model incident), and active exploitation of critical server flaws (notably SharePoint CVE-2026-50522 and ServiceNow CVE-2026-6875). Other notable items: WordPress wp2shell RCE (CVE-2026-63030, CVE-2026-60137) mass scanning/exploitation, 7‑Zip RCE (CVE-2026-14266), PAN‑OS authentication bypass (CVE-2026-0257) used to deploy Qilin/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- df7be45f6c10b5be427e5d5d7b061163094020cfdb0ac8b471157abe92ee22c5
- Enrichment time
- 2026-07-22T13:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.