WEEKLY TOP TEN: July 27, 2026, 16:00 GMT
- Check Point Patches SmartConsole Zero-Day Under Active Attack
Check Point Software released a hotfix for CVE-2026-16232, an actively exploited authentication bypass in the SmartConsole administrative interface used to manage Security Management and Multi-Domain Management deployments. An unauthenticated attacker able to reach the management server can obtain administrative access, then read and modify firewall policy, add or remove access rules, change VPN gateway configuration, push policy to every managed gateway at once, and export the full managed security configuration including certificate authorities. CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 22 with a federal remediation deadline of July 25. Management-plane exposure makes this a priority patch. - Qilin Ransomware Gang Exploits Critical Palo Alto GlobalProtect Flaw
Arctic Wolf reports the Qilin ransomware operation, also tracked as Agenda, is exploiting CVE-2026-0257, an authentication bypass affecting the Palo Alto Networks PAN-OS GlobalProtect portal and gateway, to gain privileged footholds in enterprise networks. Investigators traced multiple intrusions beginning with exploitation of the VPN flaw and escalating quickly to full ransomware deployment. Because the entry point sits at the network perimeter, defenders often have little dwell time before encryption and data theft occur. Organizations that have not applied Palo Alto Networks fixes remain directly exposed, and those that patched late should hunt for prior access, added accounts and persistence mechanisms. - WP2Shell WordPress Flaws Open Millions Of Sites To Remote Takeover
Two critical WordPress Core vulnerabilities collectively nicknamed wp2shell, tracked as CVE-2026-60137 and CVE-2026-63030, can be chained for unauthenticated remote code execution and complete site compromise. Public exploit code emerged shortly after disclosure, and mass scanning followed within hours, with successful exploitation observed over the weekend that followed. Because WordPress underpins a large share of corporate marketing sites, campaign microsites and customer portals, the flaws create a broad and often poorly inventoried attack surface. Successful exploitation allows web shell installation, credential theft and pivoting into adjacent hosting infrastructure. Administrators are urged to patch immediately and inspect sites for injected files. - Federal Agencies Update Warning On Iranian Targeting Of PLCs
CISA, the FBI, the EPA, and other government partners published an update to a joint advisory on Iranian-affiliated actors exploiting programmable logic controllers across US critical infrastructure, adding guidance for detecting malicious changes in reusable code modules used within Rockwell Automation PLC programs and expanding recommended mitigations. The activity has disrupted PLCs across water and wastewater systems, energy, and government services and facilities, including local municipalities, through malicious project file interactions and manipulation of HMI and SCADA display data. Critical infrastructure operators should inventory internet-exposed OT devices, apply the detection guidance, and validate that ladder logic matches approved baselines. - SonicWall SMA1000 Zero-Days Exploited For Weeks Before Patches Shipped
Two vulnerabilities in SonicWall SMA1000 secure access appliances, tracked as CVE-2026-15409 and CVE-2026-15410, were exploited as zero-days for several weeks before fixes became available. Volexity attributes the activity to a threat actor it tracks as UTA0533, which used the flaws to install custom malware directly on vulnerable VPN appliances, giving persistent network-edge access that survives normal remediation. Organizations running SMA1000 should assume compromise if patches were applied late, hunt for attacker-planted implants rather than relying on patching alone, and rotate credentials and certificates handled by the appliance. Edge access devices remain among the most heavily targeted enterprise assets. - Attackers Exploit Critical ServiceNow AI Platform Vulnerability Days After Disclosure
Threat intelligence firm Defused observed in-the-wild exploitation of CVE-2026-6875, a critical remote code execution vulnerability in the ServiceNow AI Platform, only days after the flaw was publicly disclosed. ServiceNow deployments typically sit at the center of IT service management, holding credentials, asset inventories, ticket histories and privileged integrations with the rest of the estate, which makes code execution on the platform unusually valuable to attackers. The compressed window between disclosure and exploitation illustrates how quickly weaponization now follows publication for widely deployed enterprise SaaS and self-hosted platforms. Administrators are urged to apply vendor fixes immediately and review platform logs for anomalous activity. - Russian Group Laundry Bear Exploits Zimbra Zero-Click Flaw To Steal Email
CISA warned that the Russian state-sponsored group tracked as Laundry Bear, also known as Void Blizzard, is targeting organizations running Zimbra Collaboration email servers. The campaign pairs phishing with exploitation of a now-patched Zimbra vulnerability that requires no user interaction, allowing operators to read mailboxes and capture two-factor authentication codes. Reporting indicates the group harvested roughly ninety days of message history from compromised environments. Government bodies, defense-adjacent suppliers and NGOs have featured prominently in prior operations by the same actor. Organizations still running unpatched Zimbra instances should update urgently, force credential resets and audit mailbox delegation and forwarding rules. - Cl0p Affiliates Exploit PTC Windchill And FlexPLM In Mass Data Theft Campaign
Affiliates tied to the Cl0p extortion operation are attacking internet-exposed PTC Windchill and FlexPLM product lifecycle management servers, chaining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with CVE-2026-12569, a critical deserialization flaw in the Windchill login servlet. The chain yields unauthenticated remote code execution and hex-named JSP web shells planted under the login directory, followed by filesystem enumeration and exfiltration of engineering and design data. Victims across manufacturing, automotive, aerospace and retail have received extortion emails sent from compromised accounts to hundreds of internal recipients. PTC has shipped fixed builds, and CISA added the flaw to its Known Exploited Vulnerabilities catalog. - Ernst & Young Discloses Breach Of Third-Party Platform
Ernst & Young is notifying individuals after hackers stole names, addresses, Social Security numbers, credit and debit card numbers, and other information from a third-party management platform. The firm detected anomalous activity in April 2026 and determined an unauthorized third party accessed the platform between late March and mid-April, downloading documents belonging to multiple clients, including tax preparation materials, financial account codes, and investment records. The incident illustrates how professional services firms concentrate highly regulated client data inside support and ticketing systems that often sit outside core security monitoring. CISOs should inventory where client documents accumulate in vendor platforms and enforce retention limits on attachments. - Ostium Loses $23.7 Million In Off-Chain Infrastructure Attack
The Ostium trading platform said an attacker stole $23.75 million from its liquidity provider vault after compromising off-chain infrastructure used to feed prices into the protocol. Rather than exploiting smart contract logic, the attacker targeted the supporting oracle pipeline, manipulating the data the protocol trusted to value positions. The pattern is directly relevant beyond crypto: any automated financial or operational system that acts on an external data feed inherits the security posture of that feed. Security leaders should map which business-critical automations consume third-party data, apply integrity checks and sanity bounds on inbound values, and monitor for anomalous feed behavior.
Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.