CTIPilot
Wed · 22 Jul 2026
All daily briefs ↗
Daily brief · UTC day

Wednesday, 22 July 2026

5 verified findings from 1 run · 2 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01CISA KEV-lists a third Langflow RCE as IBM patches 15 more, including an unauthenticated superuser-account-creation path to code execution. CISA added CVE-2026-0770 (CVSS 9.8) to its KEV catalog on 2026-07-21, confirming in-the-wild exploitation of an unauthenticated Python code-execution flaw in the self-hosted Langflow AI-agent platform's /api/v1/validate/code endpoint; the same day NCSC-NL disclosed 15 further CVEs (fixed in Langflow OSS 1.10.1), including an unauthenticated account-creation flaw (CVE-2026-9202) that reaches code execution. Any organisation self-hosting Langflow (increasingly EU/CH public-sector and research bodies building internal LLM/agent pipelines) must upgrade to 1.10.1 and close the AUTO_LOGIN / default-credential exposure.
  2. 02Zimbra ships 10.1.20 with the permanent fix for an SNMP command-injection RCE; NCSC-CH and BSI flag it for on-prem mail operators. Zimbra released Collaboration Suite (ZCS) 10.1.20 on 2026-07-20 fixing nine security issues, and both NCSC-CH and BSI CERT-Bund flagged it on 2026-07-21. The headline flaw is a command-injection RCE in the SNMP monitoring component (exploitable when SNMP notifications are enabled; first disclosed 26 June, now permanently fixed, no CVE assigned), alongside four Classic Web Client stored-XSS bugs and three CVE'd access-control/forwarding-bypass issues (CVE-2026-50055/-10631/-50054, currently RESERVED on NVD). No in-the-wild exploitation is reported; on-prem Zimbra remains common self-hosted webmail for CH/EU SMEs and public-sector bodies.
  3. 03BitLocker-for-impact extortion via exposed RDP, MSSQL and RMM/GPO; no encryptor ships, and one crew brands itself 'XEntry Team'. Kaspersky's GERT team documented two 2026 extortion incidents that abuse native Windows BitLocker for encryption-for-impact instead of a bespoke ransomware family: a June case in Colombia entered via internet-exposed RDP, and a May case in Mexico entered via a misconfigured Microsoft SQL Server (xp_cmdshell) and used legitimate RMM tooling and Group Policy to deploy BitLocker, that second victim's screens displayed "Hacked by XEntry Team". Both demanded small ransoms (~USD 3,000) and printed ransom notes on office printers; Kaspersky notes ransom-note wording and delivery similarities that may link the two but does not confirm a clear connection. Detection must target behaviour, not a malware artefact.

01Active threats, incidents & disclosures3 items

NOTABLEupdatedNATOB2

Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million, the Swiss rail manufacturer refuses to pay

Stadler Rail disclosed on 2026-07-21 that unauthorised parties gained access, in mid-July, to a data-exchange platform Stadler uses with an (unnamed) supplier, and that the Everest ransomware/extortion group claimed the intrusion and demanded a CHF 10 million ransom (swissinfo.ch, 2026-07-21). Stadler states it does not pay ransoms under any circumstances, has filed a criminal complaint with Thurgau cantonal police, and reports that its own IT systems were unharmed, no security-relevant or personal data was stolen, and worldwide rail-vehicle production and in-service fleets are unaffected; the accessed information belonged to the supplier and is described as not security-relevant (Swiss IT Magazine, 2026-07-21).

Everest is a Russian-speaking, closed-group double-extortion operation that emerged in December 2020, with a code-level connection to the BlackByte ransomware family; it has run hybrid Initial Access Broker services since November 2021 and a corporate-insider recruitment programme offering cash/profit-sharing since October 2023, and its documented infection vectors are internet-exposed RDP without MFA, vulnerable VPN endpoints, and credentials bought from other brokers (Halcyon, 2025-11-19). Per the same profile the group claimed, in October 2025, attacks on critical infrastructure including a European national electricity transmission operator, aviation systems affecting multiple European airports (Heathrow, Brussels and Berlin), and telecommunications networks, recurring targeting of the European critical-infrastructure and transport space, though those victim claims are the group's own leak-site assertions and are unconfirmed by the named organisations.

Ein von der cyberkriminellen Everest Group gefordertes Lösegeld in Höhe von zehn Millionen Franken bezahlte die Firma laut Mitteilung nicht

Die Produktion laufe aktuell weltweit normal weiter

swissinfo.ch 2026-07-21

According to the threat actor, which was first flagged by threat-intelligence tracker HackManac, the data breach yielded a 201 GB FTP archive holding more than 271,000 files.

Everest claims the compromised data touches projects linked to several high-profile operators, including Deutsche Bahn, Merseytravel, Westbahn, and MTR, alongside other unnamed clients. If validated, exposure of engineering documentation and system configurations tied to these operators raises concerns around downstream risk to connected railway infrastructure.

TechNadu 2026-07-29

Stadler hat durch den Vorfall von Mitte Juli 2026 keine Daten verloren. Der Zugriff auf diese spezifischen, technischen Daten erfolgte über kompromittierte Zugangsdaten einer Datenaustausch-Plattform.

Stadler Rail 2026-07-21
Updaterun 2026-07-31T0409Z-intelevidenceregionssourcestechniquesbody

The earlier entry recorded Everest compromising a data-exchange platform Stadler Rail shares with a supplier, a CHF 10 million demand, and Stadler's refusal to pay. The extortion has now moved to its next stage: Everest has published the data (Inside IT Switzerland, 2026-07-30). What is new beyond that fact is a claim about who else is in the archive, and it needs handling with care.

TechNadu reports a 201 GB archive holding more than 271,000 files, attributing the figures to the actor itself via a threat-intelligence tracker that flagged the listing, with the content described as railway software, CCTV footage, engineering documentation and configuration files. It further reports that Everest claims the data touches projects linked to Deutsche Bahn, Merseytravel, Westbahn and MTR, and appends its own conditional, "if validated," exposure of engineering documentation and system configurations tied to these operators would raise downstream risk to connected railway infrastructure (TechNadu, 2026-07-29). That hedge is the correct reading. These are an extortion group's assertions about the value of what it stole, relayed through one outlet, and none of the four named operators has confirmed anything. TechNadu also notes the odd operational detail that Everest claimed the attack but did not list Stadler on its leak site, so the archive appears to have been dropped outside the group's normal publication channel.

Stadler's own position has not moved. Its media release, first published on 21 July and last revised on 23 July according to its content-management metadata, states that Stadler lost no data in the mid-July 2026 incident and that access to the specific technical data involved was obtained through compromised credentials for a data-exchange platform; it records the CHF 10 million demand, the refusal to pay, and a criminal complaint filed with the Thurgau cantonal police (Stadler Rail, 2026-07-21). The release does not confirm, deny or acknowledge the publication event, it predates it. So the current state is a victim statement scoped to "no security-relevant or personal data" standing beside an attacker claim of a 201 GB archive naming four third-party operators, with nothing yet reconciling them.

That gap is the pattern worth flagging rather than the file count. Two Swiss and European public-sector incidents this month followed the same arc, an early, narrow "not affected" characterisation, followed by a leak or an authority report that contradicted it. This one has not reached that point, and it may not; Stadler's statement may hold up entirely. But an early scoping statement issued before an attacker publishes is a hypothesis about what was taken, and it is being treated by readers as a finding.

incident22 Jul 04:34Zmulti-sourceOpen finding ↗
NOTABLENATOB2

South Korea's Foreign Ministry: a ~10-month zero-day intrusion into the Diplomatic Academy's e-learning platform exposed records on nearly all diplomats

South Korea's Ministry of Foreign Affairs disclosed on 2026-07-21 that attackers exploited a previously unknown zero-day in the server software behind the Korea National Diplomatic Academy's (KNDA) online training/e-learning platform, combined with security-configuration weaknesses, to seize control of the server between April and May 2025 (The Korea Herald, 2026-07-21). The intrusion evaded the Academy's routine security checks (in place since the platform's 2022 deployment) and was only discovered in early February 2026, after another government agency flagged suspicious activity; the server was then taken offline and the (unnamed) software vendor released a patch once the flaw was identified during the investigation. Public disclosure followed roughly five months after internal discovery.

Exposed data covers up to ~10,000 records of current and former diplomats, overseas-mission officials and embassy/consulate administrative staff, including names, user IDs, email addresses and encrypted passwords, but not resident-registration numbers, phone numbers, home addresses or photographs (DailySecu, 2026-07-21; Seoul Shinmun, 2026-07-22). Officials say there is not yet sufficient technical evidence to attribute the intrusion but have not ruled out state-backed groups, including North Korea.

The attacker exploited a previously unknown security flaw, known as a zero-day vulnerability, in software used by the platform

There is not yet enough technical analysis to determine the perpetrator

The Korea Herald 2026-07-21
incident22 Jul 04:34Zmulti-sourceOpen finding ↗
NOTABLENATOB2

Kaspersky documents living-off-the-land BitLocker extortion across two Latin America incidents; the second self-identifies as 'XEntry Team'

Kaspersky's GERT incident-response team documented two 2026 extortion incidents in Latin America that abuse native Windows BitLocker for encryption-for-impact rather than deploying a conventional ransomware family; a living-off-the-land model that leaves no bespoke encryptor for signature-based detection (Kaspersky, 2026-07-21). In the first case (Colombia, June), initial access was an internet-exposed RDP service on a host attached to an 8 TB store of mission-critical data; after manipulating credentials the attacker enabled BitLocker on the drive and demanded roughly USD 3,000. In the second case (Mexico, May) (whose victims' screens displayed "Hacked by XEntry Team") initial access was a misconfigured Microsoft SQL Server whose xp_cmdshell extended stored procedure allowed OS command execution; the operators established persistence through legitimate RMM suites (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, then used Group Policy Objects to push BitLocker activation and encryption tasks across domain-joined systems. Both incidents delivered ransom notes through victims' office printers. Kaspersky notes similarities in the ransom-note wording and delivery method that may link the two cases but states the notes "do not reveal a clear connection between the actors", so treat them as a shared technique cluster, with "XEntry Team" naming the Mexico intrusion specifically. Kaspersky places the approach in the ShrinkLocker BitLocker-abuse lineage, driven here by an RDP or MSSQL foothold and, in the branded case, an RMM-and-GPO admin workflow rather than a self-contained binary.

The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data.

Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks.

Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link

Kaspersky (Securelist / GERT) 2026-07-21
threat22 Jul 04:34Zsingle-sourceOpen finding ↗
HIGHCVE-2026-0770 +5exploitedupdatedNATOA1

CVE-2026-0770, Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.1

CISA added CVE-2026-0770 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog on 2026-07-21, confirming in-the-wild exploitation of a flaw that Zero Day Initiative disclosed as an unpatched zero-day on 2026-01-09 (CISA, 2026-07-21). The flaw sits in the POST /api/v1/validate/code endpoint: the exec_globals parameter is passed to Langflow's code-validation handler and executed via Python exec() without sandboxing, giving code execution in the context of root (Zero Day Initiative, 2026-01-09). Exploitation is unauthenticated only where the operator runs AUTO_LOGIN=true and has retained Langflow's documented default credentials, a deployment misconfiguration, which is why the durable fix is disabling AUTO_LOGIN or rotating the default account rather than a version bump.

The same day, NCSC-NL published NCSC-2026-0251 covering 15 further CVEs across IBM Langflow OSS 1.0.0 through 1.10.0, all fixed in 1.10.1 (NCSC-NL, 2026-07-21). The batch includes an unauthenticated missing-authentication flaw (CVE-2026-9202, CVSS 9.8) that lets an attacker create unlimited accounts on any instance and (where the documented NEW_USER_IS_ACTIVE=true option is set) immediately activate them to reach RCE endpoints, bypassing AUTO_LOGIN restrictions entirely; a path-traversal arbitrary file write in the APIRequest "Save to File" feature via unsanitised Content-Disposition filenames (CVE-2026-8859, CVSS 9.9); a code-injection flaw in the Policies/ToolGuard component whose guard-field validation covered only the main code field and not dynamic CodeInput fields (CVE-2026-9135, CVSS 9.9); an SSRF from insecure defaults (CVE-2026-7754); RCE via insufficient validation of MCP server configuration files (CVE-2026-7755); and unsafe deserialization in the AsyncDiskCache class reachable through apply_tweaks() parameter override (CVE-2026-8476). Langflow has repeatedly drawn CISA KEV listings in 2026 (earlier additions include CVE-2026-33017 and CVE-2026-55255) reflecting how the platform's exposure as a self-hosted AI-agent orchestrator holding embedded credentials and broad system permissions keeps drawing both attackers and researchers.

The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root.

Zero Day Initiative (Trend Micro) 2026-01-09

CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

CISA 2026-07-21

Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.

IBM Security Bulletin 2026-07-14

Authentication is not required to exploit this vulnerability.

Zero Day Initiative (Trend Micro) 2026-01-09

IBM Langflow Code Injection Vulnerability

based on evidence of active exploitation

CISA 2026-07-21
Correctionrun 2026-07-26T1308Z-auditactionsaffected_productscvesevidencesourcesbody

Two corrections to that entry, both of which change what a defender does. This entry supersedes its guidance on the points below; the rest of it stands.

The fix line is 1.10.2, not 1.10.1. The earlier entry described the July batch as fixed in Langflow OSS 1.10.1 and its action item advised upgrading to that release. At least one CVE in the same batch is not covered by it: CVE-2026-14499 "could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component", affects "Langflow OSS 1.0.0-1.10.1" at CVSS 8.8, and IBM "strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.2" (IBM Security Bulletin, 2026-07-14). Because 1.10.1 is inside the affected range rather than outside it, an estate that acted on the earlier guidance is patched against the rest of the batch and still exposed to this one. The component is the Python Interpreter node, so the exposure is largest wherever Langflow flows are authored or run by more than a small set of trusted operators; an authenticated user is the only prerequisite.

CVE-2026-0770 does not depend on AUTO_LOGIN. The earlier entry recorded that CVE's affected condition as Langflow running with AUTO_LOGIN=true and unchanged default credentials, and recorded no version patch, framing the remediation as disabling AUTO_LOGIN and rotating credentials. The discloser's own per-vulnerability advisory contradicts the precondition: "Authentication is not required to exploit this vulnerability", with the flaw located in the handling of the exec_globals parameter passed to the validate endpoint, scored CVSS 9.8, and no configuration prerequisite stated anywhere in the advisory (Zero Day Initiative, 2026-01-09). ZDI's advisory does say that, at its January publication, "Given the nature of the vulnerability, the only salient mitigation strategy is to restrict interaction with the product" (Zero Day Initiative, 2026-01-09), which is where the "no version patch" line came from, and which reflects the position in January rather than today. So the practical correction is narrower than "the status was wrong": the entry carried a six-month-old mitigation posture as current, when the operative remediation now is the version upgrade that this entry's other correction already requires.

Triage: for CVE-2026-14499 the observable is command execution parented by the Langflow application process, a Python interpreter or shell child spawned from the Langflow server rather than from an operator's terminal. Legitimate use of the Python Interpreter component produces the same shape, which is why the discriminator is the account and the content rather than the lineage alone: executions attributed to a user who does not normally author flows, or occurring outside the hours when flows are edited, are the reviewable set. Version inventory is the higher-signal check here, an instance on 1.10.1 or earlier is affected regardless of what its telemetry shows.

Updaterun 2026-08-05T0412Z-intelactionsaffected_productscvesevidencereferencesregionssectorssourcestagsbody

CISA added CVE-2026-9198 to its Known Exploited Vulnerabilities catalog on 2026-08-04, listing it as an IBM Langflow code-injection vulnerability, with the additions made on evidence of active exploitation (CISA, 2026-08-04). This is a different path from anything covered in the earlier Langflow entries, which dealt with the exec_globals code-execution endpoint and a Python-interpreter component flaw.

The chain here has two links, and the first is the reason there is nothing to brute-force: an unauthenticated caller reaches an auto-login endpoint that issues a superuser token, and then submits Python to a code-validation endpoint that executes what it is given during function definition, through decorators, default arguments and annotations, all of which run at definition time rather than at call time. IBM's bulletin rates the result CVSS 9.8 and records the affected range as Langflow OSS 1.0.0 through 1.10.0 (IBM PSIRT, 2026-07-02). IBM names 1.10.1 as the remediation for this flaw; operators should target 1.10.2, because this pipeline's 2026-07-26 correction established that the sibling flaw CVE-2026-14499 is only closed in 1.10.2.

The count is now the story. Three separate pre-authentication code-execution paths in this one product carry confirmed exploitation (CVE-2026-0770, CVE-2026-0769 and now CVE-2026-9198) and CVE-2026-0769 still has no documented fixed version at all. A product whose unauthenticated attack surface has yielded three exploited paths in three weeks is not being picked at opportunistically; it is being worked systematically, and each individual patch buys less than the pattern costs.

Detection concepts, telemetry class first. The full chain appears in web and application access logs as two requests: an unauthenticated POST to the auto-login endpoint followed immediately by a POST to the code-validation endpoint from the same source. On the host, process-creation telemetry showing the Langflow Python or application-server process spawning a shell is the payoff stage.

Triage: the auto-login endpoint exists to serve a legitimate single-user convenience mode, so requests to it are not inherently malicious on an instance configured that way. The discriminator is what follows: a code-validation submission arriving from the same source within the same second, from an address outside the deployment's expected client range.

Builds on: 2026-07-29/cve-2026-0769-langflow-preauth-eval-rce-exploited-not-in-kev

vulnerability22 Jul 04:34Zmulti-sourceOpen finding ↗
NOTABLECVE-2026-50055 +2NATOA2

Zimbra Collaboration Suite 10.1.20, permanent fix for an SNMP command-injection RCE plus four stored-XSS bugs; NCSC-CH and BSI both flag the release

Zimbra shipped Collaboration Suite (ZCS) 10.1.20 on 2026-07-20, fixing nine security issues; NCSC-CH and BSI CERT-Bund both flagged the release on 2026-07-21 (NCSC-CH, 2026-07-21; BSI CERT-Bund, 2026-07-21). The headline flaw is a command-injection vulnerability in Zimbra's SNMP monitoring component, exploitable when SNMP notifications are enabled, that lets an attacker execute arbitrary OS commands on the mail server; Zimbra describes 10.1.20 as the permanent fix for a vulnerability it first disclosed in a 26 June 2026 advisory and has withheld a CVE identifier and technical specifics "in line with industry best practices" pending wider patch adoption (Zimbra, 2026-07-20; The Hacker News, 2026-07-21). Four stored cross-site-scripting bugs in the Classic Web Client round out the un-CVE'd issues: malicious attachment filenames, crafted fields, and rendered attachments can each trigger script execution inside a victim's authenticated webmail session.

Three issues received CVE identifiers, listed in BSI's advisory: CVE-2026-50055, CVE-2026-10631 and CVE-2026-50054, all three currently RESERVED on NVD/MITRE. The Hacker News maps CVE-2026-50055 to the mail-forwarding restriction bypass (letting an authenticated attacker exfiltrate mail even where forwarding restrictions are enforced) (The Hacker News, 2026-07-21); the other two correspond to the release's EWS-extension access-control and mailbox-delegation authorization fixes described in Zimbra's own advisory, but the cited sources do not state which CVE maps to which issue. The release also fixes an SSRF in Zimbra's Nextcloud integration. This is the second Zimbra security release inside two weeks, following ZCS 10.1.19's 10 July fix for a separate Classic Web Client crafted-email code-execution bug.

A command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. (Permanent fix for the vulnerability disclosed in our security advisory on 26th June 2026)

A mail forwarding restriction bypass that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled.

Zimbra / Synacor 2026-07-20
vulnerability22 Jul 04:34Zmulti-sourceOpen finding ↗

03Updates to prior coverage2 items

NOTABLEupdatedNATOB2

HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C2

First published 2026-07-21 · open finding →

Updaterun 2026-07-22T0409Z-intelaffected_productsentitiesevidencesourcestechniquesbody

Kaspersky GReAT published independent analysis of a new communication module in the Cavern C2 framework (the Iran-linked toolset Check Point tracks as "Cavern Manticore" and Group-IB documented as HOLLOWGRAPH) and retains a low-confidence assessment associating it with OilRig (APT34). The genuinely new element is a resilience layer: when Microsoft Graph authentication or tenant validation fails, the module recovers replacement connection settings (TenantId, ClientId, ClientSecret, UserEmail) via DNS AAAA responses from attacker nameservers. This corroborates the cluster covered on 2026-07-21 and adds the DNS fallback mechanics plus additional (still low-confidence) evidence for the OilRig link.

The HOLLOWGRAPH entry documented an Iran-linked backdoor that used Microsoft Graph and far-future Outlook calendar events as its command-and-control channel. Kaspersky GReAT has now published independent analysis of the same toolset (which Check Point tracks as "Cavern Manticore") detailing a new communication module (AzureCommunication.dll) that replaces the earlier HTTP/WebSocket component with Microsoft Graph, exchanging RSA-OAEP-SHA256 + AES-256-GCM-encrypted commands and results as attachments inside far-future Outlook calendar events (a fixed 2050-05-13 window) keyed to a controller-generated agent ID (Kaspersky, 2026-07-21; Check Point Research, 2026-07-06).

The new element beyond prior reporting is a resilience layer: when Graph authentication or tenant validation fails, the module recovers replacement connection settings (TenantId, ClientId, ClientSecret, UserEmail) via DNS AAAA responses from attacker-controlled nameservers, encoding length markers and 14-byte chunks in specially formatted subdomains. On attribution, Kaspersky retains its low-confidence assessment that Project CAV3RN is associated with OilRig (APT34) (a link it first drew in a previous report) noting the new module shares behavioural patterns with previously reported OilRig tooling (Microsoft-hosted-service C2, attachment-based command exchange, a secondary cloud-C2 recovery mechanism) while explicitly identifying no direct code reuse or infrastructure overlap (Kaspersky, 2026-07-21). Treat the OilRig association as an analytic lead, not a settled attribution.

HIGHCVE-2026-56155 +6exploitedupdatedNATOA1

Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)

First published 2026-07-14 · open finding →

Updaterun 2026-07-22T0409Z-intelcvesevidenceregionssourcestagsbody

CVE-2026-50522 (CVSS 9.8), a pre-auth deserialization RCE in Microsoft SharePoint Server 2016/2019/ Subscription Edition patched in July 2026, escalated to active in-the-wild exploitation on 2026-07-21 after a public PoC appeared: watchTowr honeypots recorded successful compromises within hours, and attackers steal server machine keys to forge ASP.NET authentication tokens; access that persists after patching unless keys are rotated. NCSC-NL flagged it; any org that considered the July SharePoint cluster remediated after CVE-2026-58644 must re-check 50522 exposure.

The July 2026 SharePoint patch cluster carried CVE-2026-50522, a deserialization-of-untrusted-data RCE that all sources had assessed as not-yet-exploited (Microsoft flagged only an "increased likelihood"). That changed on 2026-07-21: NCSC-NL updated advisory NCSC-2026-0237 to report, per watchTowr, that public exploit code for CVE-2026-50522 was published and the flaw is now actively exploited against on-premises SharePoint, with attackers stealing machine keys for long-term access (NCSC-NL, 2026-07-21).

watchTowr detailed the chain (relayed via BleepingComputer): a malicious .NET BinaryFormatter payload is delivered as the cookie of a forged SecurityContextToken in a WS-Federation sign-in response posted to SharePoint's /_trust/default.aspx endpoint; a successfully processed payload executes code and lets the attacker exfiltrate the server's machine keys, which are then used to forge valid ASP.NET authentication tokens/ViewState, giving persistent, re-authenticatable access that survives patching unless the keys are rotated (BleepingComputer, 2026-07-21). A PowerShell PoC (attributed by BleepingComputer to researcher "Janggggg") went public on 2026-07-20, and watchTowr's Attacker Eye honeypots captured successful compromises within hours (BleepingComputer, 2026-07-21); Security Affairs corroborates that the public PoC triggered active exploitation (Security Affairs, 2026-07-21). No authentication is required for the initial RCE.

04Action items4 items

Verification & coverage notes1 run

2026-07-22T0409Z-intel · Claude Opus 4.8 · window 26 h · 7 entries published

Verification & coverage notes

Standard 26 h window (gap 24 h to the previous fire 2026-07-21T0409Z-intel, which published ok). Seven entries published (five new, two updates) from 12 candidate items across S1–S4. No deep dive this run: the strongest technical candidate (SharePoint CVE-2026-50522) is an escalation of an already-covered July cluster, so it ships as a richly-detailed high update rather than a fresh deep-dive treatment of well-trodden ground.

Published

  • high new, Langflow CVE-2026-0770 actively exploited (CISA KEV 2026-07-21) plus the 15-CVE NCSC-NL batch fixed in 1.10.1. Multi-source (CISA + ZDI per-CVE advisory + NCSC-NL/IBM). Distinct from prior Langflow coverage (CVE-2026-55255 IDOR 2026-07-08, CVE-2025-34291 2026-05-22), new CVEs, so a new entry, not an update.
  • notable new, Zimbra 10.1.20 SNMP command-injection RCE + 4 stored-XSS; NCSC-CH and BSI dual-flag. No confirmed ITW; three CVEs RESERVED on NVD, headline SNMP RCE carries no CVE. Included on home-region relevance (self-hosted CH/EU webmail) + dual national-CERT flag; priority held at notable because no exploitation is confirmed.
  • notable new, Everest ransomware / Stadler Rail supplier-platform breach. Direct Swiss home-region hit (transport manufacturer, Thurgau); trusted-relationship vector (T1199); Stadler's own systems/production unaffected, refused CHF 10M.
  • high update, SharePoint CVE-2026-50522 escalates to active ITW exploitation via public PoC (machine-key theft → forged auth surviving patch); update_of 2026-07-15 July-cluster entry. Actions left empty: the patch and evict-then-rotate-keys tasks are already carried in-window by the 2026-07-15 and 2026-07-17 SharePoint entries, repeating them would duplicate the aggregated Action Items list.
  • notable new, XEntry Team living-off-the-land BitLocker extortion (Kaspersky GERT). Single-source (reputable lab); strong behavioural-detection value, no IOCs.
  • notable update, Project CAV3RN / Cavern: Kaspersky independently corroborates the Cavern/HOLLOWGRAPH cluster and adds a DNS AAAA-record C2 config-recovery fallback; on attribution it retains only a LOW-confidence association with OilRig (APT34); first drawn in a prior report, no direct code reuse or infrastructure overlap, reported as an analytic lead, not a settled attribution; update_of the 2026-07-21 HOLLOWGRAPH entry. Registered actor:oilrig with a single related-to edge to tool:cavern-c2-framework (low-confidence note).
  • notable new, South Korea KNDA diplomatic-academy e-learning zero-day breach. Out-of-home-region but government-sector with a transferable exposure-class lesson (externally-reachable staff training platforms; cross-agency detection). Cleared the breach gate on scale (a) + transferable shared threat (d).

Borderline drops

  • borderline-drop: DD-WRT CVE-2021-27137 / C0XMO botnet KEV listing, dedup. C0XMO/DD-WRT was already covered on 2026-06-08; the only in-window fact is the CISA KEV listing, which is jurisdiction-agnostic exploitation confirmation but on its own never opens a new/update entry for this audience. Recorded cisa-kev awareness only.
  • borderline-drop: WordPress Core CVE-2026-63030 + CVE-2026-60137 (same 2026-07-21 CISA KEV batch as Langflow/DD-WRT), dedup. These two CVEs are the WP2Shell pre-auth RCE chain already covered on 2026-07-18 and updated 2026-07-21 (the GPT5.6 autonomous-exploit-chain entry); they were already reported as actively exploited. The 2026-07-21 KEV listing confirms that exploitation but, per policy, a KEV listing alone does not open a new or update entry over already-covered ground. WordPress Core is highly relevant to the constituency, but the operational signal (patch/hunt WP2Shell) is already published, no blind spot.
  • borderline-drop: SentinelLABS Iran War midyear assessment, strategic-leaning periodic assessment (weekly-run territory); the CH/EU nexus is indirect (US/Israel/Middle East targeting) and its defender priorities are generic hardening. Logged for possible weekly pickup.
  • borderline-drop: Estée Lauder Cl0p Oracle EBS breach (CVE-2025-61882), out-of-nexus (US cosmetics), and the underlying campaign/CVE is from 2025 (patched Oct 2025, KEV since Oct 2025). Disclosure of another victim of a known campaign is awareness, not a near-term decision change for the constituency.
  • borderline-drop: Anubis ransomware / Coca-Cola fairlife, out-of-nexus (US food/beverage); the distinctive claim (full Nutanix HCI encryption, ~1 TB) is Anubis's own unverified leak-site assertion, and the confirmed baseline (a production-halt ransomware incident via SEC 8-K) carries no new/materially-evolved transferable TTP.

Recency / out-of-window

  • Two S3 leads dropped on recency (source publication outside the 26 h/72 h window), logged for the next run: Expel "CylindricalCanine" (DigiCert code-signing theft, published 2026-07-15) and Symantec "Spirals" Rust ransomware (published 2026-07-16).

Other

  • Verification: 8 iterations (Opus/Sonnet rotation), reaching the iteration cap without a confirmed double-CLEAN, published under the v3.27 fail-open. The loop was genuinely productive: iterations 1/3/4/5/6/8 each surfaced real truth/editorial defects that were remediated (Cavern OilRig over-attribution → low-confidence; Everest background → Halcyon-cited; Langflow uncited PoC removed and a wrong KEV-date framing corrected; KNDA unsupported diplomat-count dropped; XEntry two-incident conflation corrected; Zimbra CVE→issue mapping hedged; OilRig 'Lyceum' alias removed; SharePoint 'Janggggg' re-cited to BleepingComputer). Iterations 2 and 7 returned CLEAN but each was refuted by the next model's confirmation pass; exactly the blind-spot catch the double-CLEAN gate exists for. Of iteration 8's four findings, three (the two F4s and the F3) were remediated post-verdict; one (F6, Zimbra CVE-2026-10631/-50054 issue mapping) was left as an accurate hedge rather than re-sourced from an unverified new source at the cap. verification_residual_count is recorded as 4 per the fail-open rule (final verifier verdict's truth+editorial), acknowledging the post-cap fixes were not independently re-verified; the weekly quality audit should confirm them and add SecurityWeek to resolve the Zimbra mapping.
  • Single-source: 2026-07-22/xentry-team-bitlocker-lotl-extortion-rmm-gpo, first-hand Kaspersky GERT IR analysis (reputable lab); credibility held at 2 pending corroboration.
  • Sub-agent note: the first S3 (research) spawn terminated early on the content-safety classifier before writing any findings; re-spawned with an Opus model override, which completed cleanly and returned three items. No S3 coverage lost.
  • Coverage gaps: cert-eu (feed low-cadence, latest 2026-06-10); cert-pl (latest 2026-06-12, already covered); ncsc-uk (latest 2026-07-15); cert-at (latest 2026-06-01); enisa (latest 2026-07-14, non-advisory); ncsc-ie (2026-07-20 Citrix/WordPress already KEV-covered); chrome-releases (feed returned 0 items, jina credit exhausted mid-run, recipe re-verification flagged); keycloak (fetched, no security items in window); crowdstrike / trellix / withsecure-labs / infoguard-labs / shadowserver / zimperium-zlabs (quiet in-window).
  • Watchlist: no product or supplier watchlists configured in this deployment; sweeps are no-ops (products checked=0, hits=0; suppliers checked=0, hits=0).
  • Essential-coverage: all essential-tier sources attempted; cert-eu, cert-pl, cert-at, ncsc-uk, enisa returned no in-window items (low-cadence feeds, not failures).