Monday, July 20, 2026 | Jonathan Lockhart

ServiceNow exploitation reports have overtaken the vendor’s original assessment

Defused reported over the weekend that attackers had begun targeting CVE-2026-6875, the critical pre-authentication sandbox escape in the ServiceNow AI Platform. The first attempts were reportedly observed on Friday, four days after ServiceNow publicly released patches.

The attacks reached the same unauthenticated endpoint documented by Searchlight Cyber, but used a different path through the sandbox than the published proof of concept. Successful exploitation could expose ServiceNow records, create administrative users and potentially reach proxy servers connected to internal networks.

ServiceNow’s advisory still says the company is unaware of exploitation. The responsible assessment is therefore that third-party sensors have observed credible exploitation attempts, while successful customer compromise has not yet been confirmed publicly by the vendor.

Hosted instances received cloud-side mitigation. Self-hosted customers must verify that they have installed the corrected release for their deployment branch. The CVE record lists Australia Patch 2, Yokohama Patch 12 Hot Fix 1b and Patch 13, Zurich Patch 7b and Patch 9, and Brazil EA and GA among the corrected releases.

Organizations should also inspect pre-patch administrative activity, integration credentials, workflow changes and unexpected requests to the assessment_thanks.do endpoint.

Watch for: Confirmation from ServiceNow or CISA, evidence of successful compromise, or reusable exploitation spreading across self-hosted environments.

Sources: ServiceNow security advisory KB3137947, July 13, 2026; ServiceNow Australia Patch 2 release notes; Searchlight Cyber, “Smashing the ServiceNow Sandbox — Pre Authentication RCE,” July 14, 2026; Defused alert beginning “We are observing in-the-wild exploitation of the ServiceNow pre-auth sandbox-escape RCE,” July 18, 2026; BleepingComputer, July 20, 2026.

WP2Shell has moved from public exploit code into reported WordPress compromises

Several security companies are now reporting exploitation of the WP2Shell vulnerabilities patched in WordPress Core on Friday. Patchstack and watchTowr observed attack attempts, while Hexastrike said it had assisted with incident response in several cases over the weekend.

This materially changes Saturday’s assessment. Public proof-of-concept code was already available, but defenders now have independent reports that attackers are using the chain against real sites. No reliable victim count or evidence of broad automated compromise has yet been published.

WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. Versions 6.9.5 and 7.0.2 contain the fixes, and WordPress enabled forced automatic updates for vulnerable installations.

The important technical distinction is that CVE-2026-60137 provides the SQL-injection component, while CVE-2026-63030 creates the REST API routing condition that makes the complete chain reachable anonymously. It is the combined chain—not necessarily either flaw considered alone—that gives an attacker unauthenticated code execution on a stock installation.

Watch for: Large-scale scanning, confirmed web-shell deployment patterns, hosting-provider cleanup figures or addition of either vulnerability to CISA’s Known Exploited Vulnerabilities Catalog.

Sources: WordPress 6.9.5 and 7.0.2 security releases, July 17, 2026; Patchstack exploitation observations, July 19, 2026; watchTowr and Hexastrike observations; SecurityWeek, “WP2Shell WordPress Vulnerabilities Exploited in the Wild,” July 20, 2026.

The SonicWall investigation now shows what attackers did after reaching root

Volexity has published the incident-response evidence behind exploitation of CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA 1000 appliances. The earliest observed compromise occurred on June 22, weeks before SonicWall disclosed and patched the vulnerabilities.

The actor, tracked provisionally as UTA0533, chained the WorkPlace server-side request-forgery flaw with the Appliance Management Console command-injection vulnerability to obtain root access. It then deployed a privilege-escalation utility, a custom loader called KNUCKLEBALL, proxy tooling and an encrypted Java web shell that Volexity named ORANGETAIL.

On at least one appliance, the attacker used packet capture to collect unencrypted LDAP traffic bound for internal directory servers. That matters because patching the gateway does not invalidate credentials or other identity material already intercepted during the compromise window.

SMA 1000 models 6210, 7210 and 8200v should be running 12.4.3-03453 or 12.5.0-02835. Defenders should preserve evidence before rebuilding, inspect appliance logs for abnormal wsproxy connections and unfamiliar rewritten web paths, and rotate credentials exposed through the appliance.

Volexity found the actor less successful at lateral movement than at compromising the gateways and has not made a firm attribution.

Watch for: Additional victims, reuse of KNUCKLEBALL or ORANGETAIL, or evidence that captured LDAP credentials enabled wider Active Directory compromise.

Sources: Volexity, “Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation,” July 17, 2026; SonicWall advisory SNWLID-2026-0008, July 14, 2026; CISA Known Exploited Vulnerabilities Catalog.

Hugging Face says an autonomous AI agent breached its production infrastructure

Hugging Face disclosed that an attacker used an autonomous agent framework to compromise part of its production environment. The intrusion began with a malicious dataset that exploited two code-execution paths in the company’s processing pipeline. The attacker then reached worker nodes, harvested cloud and cluster credentials and moved into several internal clusters.

Hugging Face recorded more than 17,000 attacker events and described thousands of actions distributed across short-lived sandboxes, with command-and-control infrastructure moving between public services. The company does not know which language model powered the system, so the AI attribution rests on the observed operating pattern rather than identification of a particular model or provider.

The company found unauthorized access to internal datasets and service credentials. It says there is no evidence that public models, datasets, Spaces, container images or published packages were modified, but it is still determining whether partner or customer data was affected.

Hugging Face closed the vulnerable processing paths, rebuilt affected nodes and rotated exposed credentials. Users have been advised to rotate access tokens and review recent account activity.

Watch for: Notification of affected partners, publication of indicators, or evidence that stolen credentials were used against downstream organizations.

Sources: Hugging Face, “Security Incident Disclosure — July 2026,” July 16, 2026; BleepingComputer, July 20, 2026; SecurityWeek, July 20, 2026.

One operator used Gemini CLI to rebuild and run a live botnet in minutes

At the other end of the AI-enabled threat spectrum, Trend Micro analyzed 200 Gemini CLI session logs showing a Russian-speaking actor using the tool to administer eight compromised computers at a dental clinic and access its OpenDental database. The logs covered activity from March 19 through April 21.

When the existing command-and-control system stopped working reliably, the operator gave Gemini a short migration guide. The agent wrote and deployed replacement infrastructure, configured Cloudflare tunnels and debugged failed connections. The initial migration took six minutes.

This was a small botnet operated by one actor, not evidence that autonomous AI is controlling thousands of victims. Its importance lies in how little specialist knowledge the operator needed. The entire operating method was stored in three small text files that could be transferred to another server or another actor.

Taken together, the Hugging Face and Gemini cases show both sides of the same change. Agentic systems are accelerating sophisticated intrusions while also allowing fairly ordinary criminals to maintain disposable infrastructure through natural-language instructions.

Watch for: Reuse of portable AI skill files across criminal forums or further cases in which low-skill operators regenerate infrastructure faster than defenders can disrupt it.

Sources: Trend Micro, “Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet,” July 14, 2026; The Hacker News, July 20, 2026.

HelloNet is turning Russian security software into an espionage foothold

Kaspersky has documented an active campaign that places malicious components inside the local update directory of ViPNet, a Russian security suite used for virtual private networking, certificate management and protected communications. Targeting has included government, energy, transport, education, logistics and industrial organizations in Russia.

The campaign, named HelloNet, has been active since at least May. Attackers place a malicious library where the legitimate ViPNet update executable loads it during startup. The resulting toolset provides proxying, command execution, reconnaissance, file transfer and log deletion.

This should not yet be described as a confirmed compromise of InfoTeCS or its distribution infrastructure. Kaspersky has not established how the malicious file first reaches targeted systems, and its evidence shows abuse of the locally installed update component rather than poisoning of official updates.

Kaspersky tentatively connected the activity to a Chinese-speaking actor, but assigned low confidence and explicitly left open the possibility of planted evidence or a false flag. Defenders should focus on the observed tooling and update-directory persistence rather than the attribution.

Watch for: Evidence identifying the initial-access method or showing that official ViPNet update infrastructure was compromised.

Sources: Kaspersky Securelist, “HelloNet Campaign — New Malicious Modules Launched Through the ViPNet Update System,” July 16, 2026; BleepingComputer, “Hackers Abuse ViPNet Software to Target Russian Government Agencies,” July 19, 2026.

A dangerous NGINX overflow matters only where the vulnerable configuration exists

F5 issued an out-of-band update for CVE-2026-42533, a heap-buffer overflow affecting NGINX’s handling of regular-expression captures in certain map configurations. An unauthenticated attacker can trigger the flaw with a crafted HTTP request when the server already contains the required configuration pattern.

The most reliable outcome is a crashed or restarted worker, creating a denial-of-service condition. Code execution may be possible where Address Space Layout Randomization is disabled or an attacker can bypass it, but that stronger impact has not been demonstrated against ordinary hardened deployments.

NGINX versions 0.9.6 through 1.31.2 are within the vulnerable range. Versions 1.31.3 and 1.30.4 are fixed. Administrators should upgrade and review configurations that combine regex-based map directives, captured variables and string expressions rather than assuming every NGINX server is equally exposed.

As of July 20, there is no known exploitation and no public proof of concept. The vulnerability is not currently in CISA’s Known Exploited Vulnerabilities Catalog.

Watch for: Publication of working exploit code or evidence that the overflow can bypass memory protections on common production builds.

Sources: F5 advisory K000162097, July 15, 2026; NGINX Security Advisories; NVD record for CVE-2026-42533; The Hacker News, July 20, 2026.

SleeperGem poisoned dormant Ruby packages to reach developer workstations

Researchers found malicious releases of three RubyGems packages published between July 18 and 19. The SleeperGem campaign affected git_credential_manager versions 2.8.0 through 2.8.3, Dendreo versions 1.1.3 and 1.1.4, and fastlane-plugin-run_tests_firebase_testlab version 0.3.2.

The first package impersonates Microsoft’s legitimate Git Credential Manager. The other two had been dormant for years before suddenly receiving malicious updates, suggesting that abandoned or weakly protected maintainer accounts were taken over.

The malware checks for roughly thirty environment variables associated with continuous-integration systems and exits if it finds them. On a developer workstation, however, it downloads a native daemon, creates systemd and cron persistence, and can plant a set-user-ID root shell when passwordless sudo is available.

That behavior is deliberately selective. Automated pipeline testing may show nothing while a developer laptop is compromised.

Any workstation that installed and loaded one of the affected versions should be treated as compromised. Removing the package is insufficient; defenders need to eliminate persistence, check for the dropped daemon and privileged shell, and rotate every credential accessible from the machine.

Watch for: Additional dormant package accounts, evidence that the second-stage daemon stole developer secrets, or propagation into production repositories.

Sources: StepSecurity, “SleeperGem: Compromised RubyGems Drop a Persistent Backdoor,” July 19, 2026; Aikido Security SleeperGem analysis, July 19, 2026; The Hacker News, July 20, 2026.

A software supplier serving more than 2,000 hospitals has disclosed data theft

Craneware told investors Monday that attackers gained unauthorized access to part of its internal data environment and copied employee, customer and business-partner information. The Edinburgh-based company provides billing, pricing and pharmacy software to more than 2,000 American hospitals and nearly 10,000 clinics and retail pharmacies.

Craneware says the intrusion has been contained and that neither its operations nor the services supplied to healthcare organizations were disrupted. A large number of file names were viewed and copied, although the company says most of the material was non-sensitive or publicly available regulatory data.

Important questions remain unanswered. Craneware has not disclosed the intrusion vector, access period, responsible actor or whether an extortion demand was made. It also has not confirmed that patient information was stolen. This is therefore a breach of a healthcare supplier—not evidence that 2,000 hospitals or their clinical systems were compromised.

The broader risk is concentration: one vendor can hold operational and business data associated with thousands of healthcare facilities even when hospital networks themselves remain intact.

Watch for: Customer notifications identifying affected hospitals, confirmation of patient-data exposure or an extortion group claiming responsibility.

Sources: Craneware notice of cyber-security incident filed with the London Stock Exchange, July 20, 2026; The Record from Recorded Future News, “Software Provider to More Than 2,000 US Hospitals Says Hackers Stole Employee and Customer Data,” July 20, 2026.

A crafted XZ archive can turn 7-Zip extraction into code execution

Trend Micro’s Zero Day Initiative published technical details for CVE-2026-14266, a heap-buffer overflow in 7-Zip’s processing of chunked XZ-compressed data. A malicious archive can corrupt memory and execute code in the context of the user who opens or extracts it.

This is not an unauthenticated network vulnerability. Exploitation requires the target to visit a malicious page or open a crafted file, and ZDI rates the attack complexity as high. There is no reported exploitation in the wild.

The vulnerability was fixed in 7-Zip 26.02, released June 25, before the coordinated advisory appeared on July 15. Because 7-Zip is frequently installed outside centrally managed software channels—and its components may be bundled into other applications—version inventory may be more difficult than deploying the update itself.

Defenders should update endpoint installations, examine packaged applications that include 7-Zip components and treat unsolicited XZ archives as potentially executable content rather than passive files.

Watch for: Public exploit code, malicious XZ attachments or discovery of vulnerable 7-Zip components embedded in enterprise products.

Sources: Trend Micro Zero Day Initiative advisory ZDI-26-444, July 15, 2026; 7-Zip 26.02 release information, June 25, 2026; BleepingComputer, July 18, 2026.


Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.