ctipilot.ch
STREAMING · updated 18 Jul 13:30 UTC

Everything verified in the last 24 hours, held to a constant relevance bar. Read top to bottom, or load older findings to reach further back.

FROM 17.07.2026 13:30 TO 18.07.2026 13:30 now
last 24h · UTC
9findings
0critical
3high
1exploited in the wild
1updates to prior coverage
Categories4 vulnerability2 incident2 threat1 research

Latest findings

Criticality
Kind
Topic
Region
18 Jul 13:23Z· run · 3 findings
18 Jul 13:30ZNEW
NOTABLECVE-2026-54733NATOA2

Moodle local_o365 plugin: unverified JWT signature on the Teams SSO endpoint lets anyone authenticate as any user (CVE-2026-54733)

CVE-2026-54733 in local_o365, the official Microsoft 365 / Entra ID integration plugin for Moodle, lets an unauthenticated attacker forge a JWT for the Teams SSO endpoint sso_login.php: the code authenticated users from the token's upn claim without ever verifying the JWT signature, so knowing or enumerating any user's email address — an administrator's included — yields that user's session and "effectively full site takeover". Fixed in 4.5.6, 5.0.5 and 5.1.1; CVSS 4.0 9.3 (GitHub CNA); no exploitation reported. Relevant to the wider European public sector: Moodle is the dominant LMS across education and public-sector training. The fix shipped in April 2026 releases and the vendor advisory published 2026-07-06; BSI CERT-Bund surfaced it in-window (2026-07-16/17) and the daily fires swept BSI and passed over it, so it is recovered here.

vulnerability18 Jul 13:30Zsingle-sourceopen ↗
18 Jul 13:20ZNEW

WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137) — out-of-band 7.0.2 patch, exploitation expected short-term

WordPress shipped an out-of-band security release on 2026-07-17 (7.0.2, with backports 6.9.5 and 6.8.6) fixing "WP2Shell": a route-confusion flaw in the unauthenticated REST API batch endpoint (CVE-2026-63030) chained with an SQL injection in WP_Query's author__not_in parameter (CVE-2026-60137) to reach pre-auth remote code execution on a stock install with no plugins. Discoverer Searchlight Cyber withheld exploit details but published a public checker; public proof-of-concept code is already on GitHub, and NCSC-NL assesses short-term exploitation is expected. No confirmed in-the-wild exploitation as of 2026-07-18. Published as an audit-recovered item: the disclosure was public ~9 h before the day's single intel fire, which missed it.

vulnerability18 Jul 13:20Zmulti-sourceopen ↗
18 Jul 13:05ZNEW
NOTABLENATOB2

GoSerpent evolves: staged collect-then-return espionage against Southeast Asian government and diplomatic targets

Kaspersky GReAT published (2026-07-16) a full analysis of the evolved GoSerpent backdoor, a Go-based RAT used since 2021 against government and diplomatic entities in Southeast Asia. The current chain decrypts its C2 address from AES-CBC-encrypted command-line arguments, talks ChaCha20 to its C2, deploys a document-harvesting Windows service plus Mimikatz and QuarksDumpLocalHash, deliberately waits a few weeks while files accumulate, then returns with the Stowaway proxy and a dedicated exfiltration toolset. Kaspersky notes a potential — not confirmed — link to the TetrisPhantom actor. Published as an audit-recovered item: the primary fell below the visible fold of the Securelist listing sweep on the publication date.

threat18 Jul 13:05Zsingle-sourceopen ↗
18 Jul 05:48Z· run · gap 8h · 6 findings
18 Jul 04:35Z

CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround

Broadcom advisory VMSA-2026-0005 (2026-07-14) discloses seven flaws in VMware Avi Load Balancer (formerly NSX Advanced Load Balancer); the headline flaw CVE-2026-47865 (CVSS 9.8) lets an unauthenticated remote attacker reach the Avi Controller control plane by bypassing authentication entirely, with no workaround available. Affected: 22.1.1–22.1.7, 30.1.1–30.2.6, 31.1.1–31.2.2 and 32.1.1; fixed in 32.1.2, 31.2.2-2p3 and 30.2.7. No in-the-wild exploitation is reported, but the bug was reported by NATO NCSC and the control plane governs traffic routing and TLS termination for whatever sits behind the load balancer.

vulnerability18 Jul 04:35Zmulti-sourceopen ↗
18 Jul 04:35ZUPD
HIGHCVE-2026-15409 +1exploitedupdateNATOB1

SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533's full appliance-to-network kill chain

Volexity has reconstructed the intrusion behind the actively-exploited SonicWall SMA 1000 zero-days (CVE-2026-15409 SSRF, CVE-2026-15410 path-traversal command injection), attributing it to an actor it tracks as UTA0533 with the earliest compromise on 2026-06-22. The chain: an unauthenticated /wsproxy request tunnels to a localhost-only service for initial code execution, a hotfix-rollback path traversal escalates to root, then the actor injects a proxy (Suo5) and a Java webshell (ORANGETAIL) into the appliance's legitimate workplace process, persists via an init script, captures cleartext LDAP credentials with tcpdump, and pivots into the internal network. Stolen credentials survive patching — the hotfix alone does not remediate a pre-patch compromise.

threat18 Jul 04:35Zmulti-sourceopen ↗
18 Jul 04:35Z
NOTABLECVE-2025-40948 +2NATOB1

CVE-2025-40948/-40947/-40949 — Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root

Palo Alto Unit 42 published (2026-07-17) a three-stage exploit chain against Siemens RUGGEDCOM ROX II operational-technology switches: CVE-2025-40948 (CVSS 6.8) misuses a root-privileged xz invocation to read any file on the device, CVE-2025-40947 (CVSS 7.5) is command injection in the feature-key signature-verification path, and CVE-2025-40949 (CVSS 9.1) lets an authenticated attacker inject commands into the web-management task scheduler for persistent, reboot-surviving root code execution. Siemens patched all three in firmware V2.17.1 (advisories SSA-973901/-078743/-081142); no in-the-wild exploitation is reported. ROX II sits as a network-security/routing boundary inside rail, utility, water and manufacturing networks across Europe.

vulnerability18 Jul 04:35Zmulti-sourceopen ↗
18 Jul 04:35Z
NOTABLENATOB2

TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD

Metro Mondego, the public operator of the Metrobus light-rail service between Lousã and Coimbra (Portugal), confirmed on 2026-07-17 that a ransomware attack on 6 July affected part of its internal systems without compromising transport operation. The RaaS group TheGentlemen (Microsoft: Storm-2697) claimed the attack and data theft on its leak site. Metro Mondego activated incident response with external experts and notified Portugal's national cyber authority (CNCS), the data-protection authority (CNPD) and criminal investigators; it cannot yet confirm whether personal data was copied, but says passenger payment data was not affected. A clean EU public-transport incident showing IT/OT segmentation holding.

incident18 Jul 04:35Zmulti-sourceopen ↗
18 Jul 04:35Z
NOTABLENATOB2

Contagious Interview (DPRK) hides an OTTERCOOKIE-aligned payload in SVG-comment steganography inside fake coding-interview repos

Elastic Security Labs documented (2026-07-18) a new instance of the DPRK-aligned Contagious Interview campaign (tracked REF9403) after the operators targeted Elastic's own community Slack with a fake job posting and take-home coding project. The trojanized Next.js repo hides its payload as Base64 fragments inside HTML comments across every SVG flag image in an assets directory; a loader script reassembles them alphabetically and runs them with eval(), deliberately evading scanners that do not parse SVG comment bodies. On project startup it runs a four-stage OTTERCOOKIE-aligned payload — browser/wallet credential theft, sensitive-file exfiltration, a Socket.IO RAT and a clipboard stealer — with zero AV detection at publication. Relevant to any team that runs candidate or contractor take-home coding tests.

research18 Jul 04:35Zsingle-sourceopen ↗
18 Jul 04:35Z
NOTABLENATOA3

Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records

Abbott Laboratories confirmed (2026-07-16) unauthorized access to a limited number of internal systems in its Cancer Diagnostics business (the acquired Exact Sciences unit) only. Separately, the ShinyHunters extortion group claims the intrusion began with a vishing call that compromised a Microsoft Entra ID single-sign-on account, then used it to pull 30M+ records from Entra, ServiceNow, SharePoint, Databricks and Coupa — a claim Abbott has neither confirmed nor attributed. The confirmed incident plus the same vishing-to-cloud-SSO tradecraft this actor uses against SaaS-integrated enterprises makes it relevant to healthcare and any SharePoint/Entra-dependent estate.

incident18 Jul 04:35Zmulti-sourceopen ↗