7 verified findings from 1 run · the settled record for this UTC day, in the classic brief order.
Criticality
Kind
Topic
Region
TL;DR · the day in one read
01CISA KEV-lists a third Langflow RCE as IBM patches 15 more, including an unauthenticated superuser-account-creation path to code execution. CISA added CVE-2026-0770 (CVSS 9.8) to its KEV catalog on 2026-07-21, confirming in-the-wild exploitation of an unauthenticated Python code-execution flaw in the self-hosted Langflow AI-agent platform's /api/v1/validate/code endpoint; the same day NCSC-NL disclosed 15 further CVEs (fixed in Langflow OSS 1.10.1), including an unauthenticated account-creation flaw (CVE-2026-9202) that reaches code execution. Any organisation self-hosting Langflow — increasingly EU/CH public-sector and research bodies building internal LLM/agent pipelines — must upgrade to 1.10.1 and close the AUTO_LOGIN / default-credential exposure. →
02A second July SharePoint RCE (CVE-2026-50522) is now exploited in the wild — machine-key theft lets access survive patching. CVE-2026-50522 (CVSS 9.8), a pre-auth deserialization RCE in Microsoft SharePoint Server 2016/2019/ Subscription Edition patched in July 2026, escalated to active in-the-wild exploitation on 2026-07-21 after a public PoC appeared: watchTowr honeypots recorded successful compromises within hours, and attackers steal server machine keys to forge ASP.NET authentication tokens — access that persists after patching unless keys are rotated. NCSC-NL flagged it; any org that considered the July SharePoint cluster remediated after CVE-2026-58644 must re-check 50522 exposure. →
03Zimbra ships 10.1.20 with the permanent fix for an SNMP command-injection RCE; NCSC-CH and BSI flag it for on-prem mail operators. Zimbra released Collaboration Suite (ZCS) 10.1.20 on 2026-07-20 fixing nine security issues, and both NCSC-CH and BSI CERT-Bund flagged it on 2026-07-21. The headline flaw is a command-injection RCE in the SNMP monitoring component (exploitable when SNMP notifications are enabled; first disclosed 26 June, now permanently fixed, no CVE assigned), alongside four Classic Web Client stored-XSS bugs and three CVE'd access-control/forwarding-bypass issues (CVE-2026-50055/-10631/-50054, currently RESERVED on NVD). No in-the-wild exploitation is reported; on-prem Zimbra remains common self-hosted webmail for CH/EU SMEs and public-sector bodies. →
Stadler Rail disclosed on 2026-07-21 that unauthorised parties gained access, in mid-July, to a data-exchange platform Stadler uses with an (unnamed) supplier, and that the Everest ransomware/extortion group claimed the intrusion and demanded a CHF 10 million ransom (swissinfo.ch, 2026-07-21). Stadler states it does not pay ransoms under any circumstances, has filed a criminal complaint with Thurgau cantonal police, and reports that its own IT systems were unharmed, no security-relevant or personal data was stolen, and worldwide rail-vehicle production and in-service fleets are unaffected — the accessed information belonged to the supplier and is described as not security-relevant (Swiss IT Magazine, 2026-07-21).
Everest is a Russian-speaking, closed-group double-extortion operation that emerged in December 2020, with a code-level connection to the BlackByte ransomware family; it has run hybrid Initial Access Broker services since November 2021 and a corporate-insider recruitment programme offering cash/profit-sharing since October 2023, and its documented infection vectors are internet-exposed RDP without MFA, vulnerable VPN endpoints, and credentials bought from other brokers (Halcyon, 2025-11-19). Per the same profile the group claimed, in October 2025, attacks on critical infrastructure including a European national electricity transmission operator, aviation systems affecting multiple European airports (Heathrow, Brussels and Berlin), and telecommunications networks — recurring targeting of the European critical-infrastructure and transport space, though those victim claims are the group's own leak-site assertions and are unconfirmed by the named organisations.
Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht
Die Produktion laufe aktuell weltweit normal weiter
South Korea's Ministry of Foreign Affairs disclosed on 2026-07-21 that attackers exploited a previously unknown zero-day in the server software behind the Korea National Diplomatic Academy's (KNDA) online training/e-learning platform, combined with security-configuration weaknesses, to seize control of the server between April and May 2025 (The Korea Herald, 2026-07-21). The intrusion evaded the Academy's routine security checks (in place since the platform's 2022 deployment) and was only discovered in early February 2026, after another government agency flagged suspicious activity; the server was then taken offline and the (unnamed) software vendor released a patch once the flaw was identified during the investigation. Public disclosure followed roughly five months after internal discovery.
Exposed data covers up to ~10,000 records of current and former diplomats, overseas-mission officials and embassy/consulate administrative staff — including names, user IDs, email addresses and encrypted passwords, but not resident-registration numbers, phone numbers, home addresses or photographs (DailySecu, 2026-07-21; Seoul Shinmun, 2026-07-22). Officials say there is not yet sufficient technical evidence to attribute the intrusion but have not ruled out state-backed groups, including North Korea.
The attacker exploited a previously unknown security flaw, known as a zero-day vulnerability, in software used by the platform
There is not yet enough technical analysis to determine the perpetrator
Kaspersky's GERT incident-response team documented two 2026 extortion incidents in Latin America that abuse native Windows BitLocker for encryption-for-impact rather than deploying a conventional ransomware family — a living-off-the-land model that leaves no bespoke encryptor for signature-based detection (Kaspersky, 2026-07-21). In the first case (Colombia, June), initial access was an internet-exposed RDP service on a host attached to an 8 TB store of mission-critical data; after manipulating credentials the attacker enabled BitLocker on the drive and demanded roughly USD 3,000. In the second case (Mexico, May) — whose victims' screens displayed "Hacked by XEntry Team" — initial access was a misconfigured Microsoft SQL Server whose xp_cmdshell extended stored procedure allowed OS command execution; the operators established persistence through legitimate RMM suites (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, then used Group Policy Objects to push BitLocker activation and encryption tasks across domain-joined systems. Both incidents delivered ransom notes through victims' office printers. Kaspersky notes similarities in the ransom-note wording and delivery method that may link the two cases but states the notes "do not reveal a clear connection between the actors" — so treat them as a shared technique cluster, with "XEntry Team" naming the Mexico intrusion specifically. Kaspersky places the approach in the ShrinkLocker BitLocker-abuse lineage, driven here by an RDP or MSSQL foothold and, in the branded case, an RMM-and-GPO admin workflow rather than a self-contained binary.
The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data.
Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks.
Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link
CISA added CVE-2026-0770 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog on 2026-07-21, confirming in-the-wild exploitation of a flaw that Zero Day Initiative disclosed as an unpatched zero-day on 2026-01-09 (CISA, 2026-07-21). The flaw sits in the POST /api/v1/validate/code endpoint: the exec_globals parameter is passed to Langflow's code-validation handler and executed via Python exec() without sandboxing, giving code execution in the context of root (Zero Day Initiative, 2026-01-09). Exploitation is unauthenticated only where the operator runs AUTO_LOGIN=true and has retained Langflow's documented default credentials — a deployment misconfiguration, which is why the durable fix is disabling AUTO_LOGIN or rotating the default account rather than a version bump.
The same day, NCSC-NL published NCSC-2026-0251 covering 15 further CVEs across IBM Langflow OSS 1.0.0 through 1.10.0, all fixed in 1.10.1 (NCSC-NL, 2026-07-21). The batch includes an unauthenticated missing-authentication flaw (CVE-2026-9202, CVSS 9.8) that lets an attacker create unlimited accounts on any instance and — where the documented NEW_USER_IS_ACTIVE=true option is set — immediately activate them to reach RCE endpoints, bypassing AUTO_LOGIN restrictions entirely; a path-traversal arbitrary file write in the APIRequest "Save to File" feature via unsanitised Content-Disposition filenames (CVE-2026-8859, CVSS 9.9); a code-injection flaw in the Policies/ToolGuard component whose guard-field validation covered only the main code field and not dynamic CodeInput fields (CVE-2026-9135, CVSS 9.9); an SSRF from insecure defaults (CVE-2026-7754); RCE via insufficient validation of MCP server configuration files (CVE-2026-7755); and unsafe deserialization in the AsyncDiskCache class reachable through apply_tweaks() parameter override (CVE-2026-8476). Langflow has repeatedly drawn CISA KEV listings in 2026 — earlier additions include CVE-2026-33017 and CVE-2026-55255 — reflecting how the platform's exposure as a self-hosted AI-agent orchestrator holding embedded credentials and broad system permissions keeps drawing both attackers and researchers.
The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root.
Zimbra shipped Collaboration Suite (ZCS) 10.1.20 on 2026-07-20, fixing nine security issues; NCSC-CH and BSI CERT-Bund both flagged the release on 2026-07-21 (NCSC-CH, 2026-07-21; BSI CERT-Bund, 2026-07-21). The headline flaw is a command-injection vulnerability in Zimbra's SNMP monitoring component, exploitable when SNMP notifications are enabled, that lets an attacker execute arbitrary OS commands on the mail server; Zimbra describes 10.1.20 as the permanent fix for a vulnerability it first disclosed in a 26 June 2026 advisory and has withheld a CVE identifier and technical specifics "in line with industry best practices" pending wider patch adoption (Zimbra, 2026-07-20; The Hacker News, 2026-07-21). Four stored cross-site-scripting bugs in the Classic Web Client round out the un-CVE'd issues: malicious attachment filenames, crafted fields, and rendered attachments can each trigger script execution inside a victim's authenticated webmail session.
Three issues received CVE identifiers, listed in BSI's advisory: CVE-2026-50055, CVE-2026-10631 and CVE-2026-50054 — all three currently RESERVED on NVD/MITRE. The Hacker News maps CVE-2026-50055 to the mail-forwarding restriction bypass (letting an authenticated attacker exfiltrate mail even where forwarding restrictions are enforced) (The Hacker News, 2026-07-21); the other two correspond to the release's EWS-extension access-control and mailbox-delegation authorization fixes described in Zimbra's own advisory, but the cited sources do not state which CVE maps to which issue. The release also fixes an SSRF in Zimbra's Nextcloud integration. This is the second Zimbra security release inside two weeks, following ZCS 10.1.19's 10 July fix for a separate Classic Web Client crafted-email code-execution bug.
A command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. (Permanent fix for the vulnerability disclosed in our security advisory on 26th June 2026)
A mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.
The July 2026 SharePoint patch cluster carried CVE-2026-50522, a deserialization-of-untrusted-data RCE that all sources had assessed as not-yet-exploited (Microsoft flagged only an "increased likelihood"). That changed on 2026-07-21: NCSC-NL updated advisory NCSC-2026-0237 to report, per watchTowr, that public exploit code for CVE-2026-50522 was published and the flaw is now actively exploited against on-premises SharePoint, with attackers stealing machine keys for long-term access (NCSC-NL, 2026-07-21).
watchTowr detailed the chain (relayed via BleepingComputer): a malicious .NET BinaryFormatter payload is delivered as the cookie of a forged SecurityContextToken in a WS-Federation sign-in response posted to SharePoint's /_trust/default.aspx endpoint; a successfully processed payload executes code and lets the attacker exfiltrate the server's machine keys, which are then used to forge valid ASP.NET authentication tokens/ViewState — giving persistent, re-authenticatable access that survives patching unless the keys are rotated (BleepingComputer, 2026-07-21). A PowerShell PoC (attributed by BleepingComputer to researcher "Janggggg") went public on 2026-07-20, and watchTowr's Attacker Eye honeypots captured successful compromises within hours (BleepingComputer, 2026-07-21); Security Affairs corroborates that the public PoC triggered active exploitation (Security Affairs, 2026-07-21). No authentication is required for the initial RCE.
Volgens watchTowr is er een publieke exploit code voor SharePoint kwetsbaarheid CVE-2026-50522 gepubliceerd en wordt deze op on-premise versies van SharePoint nu ook actief misbruikt. Kwaadwillenden kunnen deze kwetsbaarheid misbruiken om zichzelf voor langere termijn toegang tot netwerken van kwetsbare systemen te verschaffen, door middel van het stelen van machine-keys.
NCSC-NL (advisory NCSC-2026-0237)
Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.
The HOLLOWGRAPH entry documented an Iran-linked backdoor that used Microsoft Graph and far-future Outlook calendar events as its command-and-control channel. Kaspersky GReAT has now published independent analysis of the same toolset — which Check Point tracks as "Cavern Manticore" — detailing a new communication module (AzureCommunication.dll) that replaces the earlier HTTP/WebSocket component with Microsoft Graph, exchanging RSA-OAEP-SHA256 + AES-256-GCM-encrypted commands and results as attachments inside far-future Outlook calendar events (a fixed 2050-05-13 window) keyed to a controller-generated agent ID (Kaspersky, 2026-07-21; Check Point Research, 2026-07-06).
The new element beyond prior reporting is a resilience layer: when Graph authentication or tenant validation fails, the module recovers replacement connection settings (TenantId, ClientId, ClientSecret, UserEmail) via DNS AAAA responses from attacker-controlled nameservers, encoding length markers and 14-byte chunks in specially formatted subdomains. On attribution, Kaspersky retains its low-confidence assessment that Project CAV3RN is associated with OilRig (APT34) — a link it first drew in a previous report — noting the new module shares behavioural patterns with previously reported OilRig tooling (Microsoft-hosted-service C2, attachment-based command exchange, a secondary cloud-C2 recovery mechanism) while explicitly identifying no direct code reuse or infrastructure overlap (Kaspersky, 2026-07-21). Treat the OilRig association as an analytic lead, not a settled attribution.
If Microsoft Graph authentication or tenant validation fails, the module attempts to retrieve replacement connection settings through DNS AAAA responses.
The new module shares several behavioral patterns with previously reported OilRig tooling, including the use of Microsoft-hosted services, attachment-based command exchange, and a secondary mechanism for restoring access to a cloud C2 channel.
Upgrade every self-hosted Langflow instance to OSS 1.10.1; on any instance where AUTO_LOGIN must remain enabled, rotate the default langflow/langflow credentials and set NEW_USER_IS_ACTIVE=false — patching alone does not close CVE-2026-0770, and CVE-2026-9202 lets unauthenticated attackers self-provision active accounts otherwise.
Upgrade on-prem Zimbra to ZCS 10.1.20; where SNMP notifications are not operationally required, disable them to remove the command-injection attack surface entirely rather than relying on the still-undisclosed-detail fix.
2026-07-22T0409Z-intel· Claude Opus 4.8 · window 26 h · 7 entries published
Verification & coverage notes
Standard 26 h window (gap 24 h to the previous fire 2026-07-21T0409Z-intel, which published ok). Seven entries published — five new, two updates — from 12 candidate items across S1–S4. No deep dive this run: the strongest technical candidate (SharePoint CVE-2026-50522) is an escalation of an already-covered July cluster, so it ships as a richly-detailed high update rather than a fresh deep-dive treatment of well-trodden ground.
Published
high new — Langflow CVE-2026-0770 actively exploited (CISA KEV 2026-07-21) plus the 15-CVE NCSC-NL batch fixed in 1.10.1. Multi-source (CISA + ZDI per-CVE advisory + NCSC-NL/IBM). Distinct from prior Langflow coverage (CVE-2026-55255 IDOR 2026-07-08, CVE-2025-34291 2026-05-22) — new CVEs, so a new entry, not an update.
notable new — Zimbra 10.1.20 SNMP command-injection RCE + 4 stored-XSS; NCSC-CH and BSI dual-flag. No confirmed ITW; three CVEs RESERVED on NVD, headline SNMP RCE carries no CVE. Included on home-region relevance (self-hosted CH/EU webmail) + dual national-CERT flag; priority held at notable because no exploitation is confirmed.
notable new — Everest ransomware / Stadler Rail supplier-platform breach. Direct Swiss home-region hit (transport manufacturer, Thurgau); trusted-relationship vector (T1199); Stadler's own systems/production unaffected, refused CHF 10M.
high update — SharePoint CVE-2026-50522 escalates to active ITW exploitation via public PoC (machine-key theft → forged auth surviving patch); update_of 2026-07-15 July-cluster entry. Actions left empty: the patch and evict-then-rotate-keys tasks are already carried in-window by the 2026-07-15 and 2026-07-17 SharePoint entries — repeating them would duplicate the aggregated Action Items list.
notable new — XEntry Team living-off-the-land BitLocker extortion (Kaspersky GERT). Single-source (reputable lab); strong behavioural-detection value, no IOCs.
notable update — Project CAV3RN / Cavern: Kaspersky independently corroborates the Cavern/HOLLOWGRAPH cluster and adds a DNS AAAA-record C2 config-recovery fallback; on attribution it retains only a LOW-confidence association with OilRig (APT34) — first drawn in a prior report, no direct code reuse or infrastructure overlap — reported as an analytic lead, not a settled attribution; update_of the 2026-07-21 HOLLOWGRAPH entry. Registered actor:oilrig with a single related-to edge to tool:cavern-c2-framework (low-confidence note).
notable new — South Korea KNDA diplomatic-academy e-learning zero-day breach. Out-of-home-region but government-sector with a transferable exposure-class lesson (externally-reachable staff training platforms; cross-agency detection). Cleared the breach gate on scale (a) + transferable shared threat (d).
Borderline drops
borderline-drop: DD-WRT CVE-2021-27137 / C0XMO botnet KEV listing — dedup. C0XMO/DD-WRT was already covered on 2026-06-08; the only in-window fact is the CISA KEV listing, which is jurisdiction-agnostic exploitation confirmation but on its own never opens a new/update entry for this audience. Recorded cisa-kev awareness only.
borderline-drop: WordPress Core CVE-2026-63030 + CVE-2026-60137 (same 2026-07-21 CISA KEV batch as Langflow/DD-WRT) — dedup. These two CVEs are the WP2Shell pre-auth RCE chain already covered on 2026-07-18 and updated 2026-07-21 (the GPT5.6 autonomous-exploit-chain entry); they were already reported as actively exploited. The 2026-07-21 KEV listing confirms that exploitation but, per policy, a KEV listing alone does not open a new or update entry over already-covered ground. WordPress Core is highly relevant to the constituency, but the operational signal (patch/hunt WP2Shell) is already published — no blind spot.
borderline-drop: SentinelLABS Iran War midyear assessment — strategic-leaning periodic assessment (weekly-run territory); the CH/EU nexus is indirect (US/Israel/Middle East targeting) and its defender priorities are generic hardening. Logged for possible weekly pickup.
borderline-drop: Estée Lauder Cl0p Oracle EBS breach (CVE-2025-61882) — out-of-nexus (US cosmetics), and the underlying campaign/CVE is from 2025 (patched Oct 2025, KEV since Oct 2025). Disclosure of another victim of a known campaign is awareness, not a near-term decision change for the constituency.
borderline-drop: Anubis ransomware / Coca-Cola fairlife — out-of-nexus (US food/beverage); the distinctive claim (full Nutanix HCI encryption, ~1 TB) is Anubis's own unverified leak-site assertion, and the confirmed baseline (a production-halt ransomware incident via SEC 8-K) carries no new/materially-evolved transferable TTP.
Recency / out-of-window
Two S3 leads dropped on recency (source publication outside the 26 h/72 h window), logged for the next run: Expel "CylindricalCanine" (DigiCert code-signing theft, published 2026-07-15) and Symantec "Spirals" Rust ransomware (published 2026-07-16).
Other
Verification: 8 iterations (Opus/Sonnet rotation), reaching the iteration cap without a confirmed double-CLEAN — published under the v3.27 fail-open. The loop was genuinely productive: iterations 1/3/4/5/6/8 each surfaced real truth/editorial defects that were remediated (Cavern OilRig over-attribution → low-confidence; Everest background → Halcyon-cited; Langflow uncited PoC removed and a wrong KEV-date framing corrected; KNDA unsupported diplomat-count dropped; XEntry two-incident conflation corrected; Zimbra CVE→issue mapping hedged; OilRig 'Lyceum' alias removed; SharePoint 'Janggggg' re-cited to BleepingComputer). Iterations 2 and 7 returned CLEAN but each was refuted by the next model's confirmation pass — exactly the blind-spot catch the double-CLEAN gate exists for. Of iteration 8's four findings, three (the two F4s and the F3) were remediated post-verdict; one (F6, Zimbra CVE-2026-10631/-50054 issue mapping) was left as an accurate hedge rather than re-sourced from an unverified new source at the cap. verification_residual_count is recorded as 4 per the fail-open rule (final verifier verdict's truth+editorial), acknowledging the post-cap fixes were not independently re-verified; the weekly quality audit should confirm them and add SecurityWeek to resolve the Zimbra mapping.
Single-source: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo — first-hand Kaspersky GERT IR analysis (reputable lab); credibility held at 2 pending corroboration.
Sub-agent note: the first S3 (research) spawn terminated early on the content-safety classifier before writing any findings; re-spawned with an Opus model override, which completed cleanly and returned three items. No S3 coverage lost.
Watchlist: no product or supplier watchlists configured in this deployment — sweeps are no-ops (products checked=0, hits=0; suppliers checked=0, hits=0).
Essential-coverage: all essential-tier sources attempted; cert-eu, cert-pl, cert-at, ncsc-uk, enisa returned no in-window items (low-cadence feeds, not failures).