Weekend desk: wp2shell in the open, 27 DigiCert EV certs
Sunday desk. wp2shell shipped with a working PoC. 7-Zip closed the XZ hole, DigiCert's April intrusion is attributed, Abbott and E&Y remain open.
- WordPress Core received CVE-2026-63030 (wp2shell) on 2026-07-17 — an unauthenticated remote code execution flaw with a working public PoC. NVD scores it 9.8; the GitHub Security Advisory scores it 7.5. Cite both if you're briefing up. Not on KEV yet
- 7-Zip 26.02 (2026-07-18) closes a heap overflow in the XZ decoder — ZDI-26-444 — triggered by opening a malicious archive. No auto-update in 7-Zip; patch is manual, per BleepingComputer
- Microsoft Defender Experts documented an April-through-June ACR Stealer campaign delivered via ClickFix run-box paste-and-run lures, WebDAV shares, and blockchain-hosted C2 (EtherHiding). Volume is up materially over the prior quarter, per Microsoft's own telemetry
- Expel attributes the April 2 DigiCert intrusion to CylindricalCanine, a subgroup of Chinese cluster GoldenEyeDog / APT-Q-27. Twenty-seven of the 60 revoked EV code-signing certificates were used to sign Zhong Stealer samples in the wild before revocation caught up
- Abbott confirmed two cyber incidents on 2026-07-17 and is disputing a ShinyHunters extortion claim tied to Exact Sciences and LabCentral. Confidence on the incidents: as-disclosed by Abbott. Confidence on the extortion-group tie: disputed
- Ernst & Young disclosed a breach of a third-party support-ticket system covering a March through April 2026 window. As-disclosed by E&Y; scope pending
- Checkmarx documented ViteVenom / ChainVeil — seven malicious npm packages riding the Vite ecosystem, using the TRON blockchain as command-and-control resolver. Fresh operator, familiar pattern
- Rapid7 published a proof-of-concept for a Windows User Profile Service local privilege escalation dubbed LegacyHive — a zero-day at disclosure, no vendor patch at press time
Two days between briefings and the queue backed up. Not because any single item broke bigger than the FortiSandbox pair or the fourth SharePoint — those were Thursday’s briefing — but because the mid-week Patch Tuesday tail, a WordPress Core disclosure, and a couple of breach filings all landed in the same 48-hour window. The through-line for the weekend is that most of these were foreseeable in outline weeks or months ago. What broke this weekend is the specifics.
wp2shell in the open
Confirmed: CVE-2026-63030 was assigned to WordPress Core on 2026-07-17, under the researcher tag wp2shell, for an unauthenticated remote code execution primitive that runs against a bare install with no plugins in the picture. Rapid7’s Emergent Threat Response write-up and The Hacker News’s reporting went out the same day, and by Friday afternoon the working PoC was circulating publicly.
The oddity is the scoring split. NVD lists 9.8. The GitHub Security Advisory that carried the assignment lists 7.5. Both source severities land at Critical; the numeric gap is unresolved as of this filing. Our position: cite both if you’re briefing up, note the split explicitly, and remediate on the higher of the two. There is no defensive posture in which 7.5 is the number you want to be quoting to a board when NVD is publishing 9.8 and the primitive is anonymous-request-to-RCE. Full wp2shell write-up here.
WordPress Core RCEs are rare in a way that plugin-side RCEs are not. Australia’s ACSC catalogued eighteen plugin CVEs under exploitation just last week, which is a story about ecosystem sprawl. wp2shell is a story about the core project itself. Different blast radius, different remediation.
Patch and cleanup
- 7-Zip 26.02 closes a heap overflow in the XZ decoder — ZDI-26-444 — triggered by opening a malicious archive. There is no auto-update in 7-Zip; a large installed base is going to sit on the vulnerable build for months by default. If your endpoint fleet has 7-Zip, this is a package-management problem, not a user-training problem.
- LegacyHive — Rapid7 published a proof-of-concept for a User Profile Service local privilege escalation dubbed LegacyHive. Zero-day at disclosure; no vendor patch at press time. LPE is the second half of every intrusion, so a public PoC on a Microsoft service that runs on every desktop is not the low-severity story its raw CVSS would suggest. Track for a Microsoft advisory.
- DigiCert — Expel attributes the April 2 DigiCert intrusion to CylindricalCanine, a subgroup of the Chinese cluster GoldenEyeDog / APT-Q-27. Twenty-seven of the 60 revoked EV code-signing certificates were used to sign Zhong Stealer samples in the wild before revocation caught up. Revocation is not detection: if a signed artifact landed on a box in March, the list published in April does not remove it. This is a look-back exercise, not a defence posture.
Breach queue
Two open disclosures at press time. Both were filed inside the same 48-hour window, which is a coincidence rather than a pattern.
- Abbott confirmed two cyber incidents on 2026-07-17. A ShinyHunters extortion claim tied to Exact Sciences and LabCentral is in dispute, with Abbott’s public statement declining to confirm the tie. Confidence on the incidents themselves: as-disclosed. Confidence on the extortion-group attribution: disputed.
- Ernst & Young disclosed a breach of a third-party support-ticket system covering a March through April 2026 window. As-disclosed by E&Y; scope pending. The recurring story here is that third-party support tools sit at a trust boundary most enterprises do not audit at the same standard as their production environments.
Threat intel of note
- Microsoft ACR Stealer surge — Defender Experts documented an April-through-June campaign delivering ACR Stealer via ClickFix run-box paste-and-run lures, WebDAV file shares as staging, and blockchain-hosted C2 in the EtherHiding pattern. Volume is up materially quarter over quarter, per Microsoft’s telemetry. The technique stack itself is not novel — Elastic Security Labs pinned TELEPUZ on ClickFix and Group-IB documented ClickLock on macOS last week — but ACR Stealer moving to the same delivery family at Microsoft-visible volume is the confirmation that ClickFix is now a standard MaaS delivery mechanism, not a niche.
- ViteVenom / ChainVeil — Checkmarx documented seven malicious npm packages riding the Vite ecosystem, using the TRON blockchain as a command-and-control resolver. The blockchain-C2 idea is not new — the ACR Stealer campaign above uses a similar pattern on Ethereum — but the operator here is new and the packaging ecosystem is a live delivery channel.
- NadMesh — a Go botnet that hunts exposed AI-services endpoints on Shodan (ComfyUI, Ollama, and similar) for cloud keys and Kubernetes tokens. 3,811 AWS keys observed harvested. If you host inference services on the open internet without a front door, this is the operator you should model against.
- Kaspersky’s GoSerpent — a previously undocumented Go RAT against Southeast Asian governments and diplomats, active since late 2025, with TTP overlap on TetrisPhantom. Long-horizon espionage; not a Monday-morning patch story, but if your organisation sits in that victimology, this is the operator to model against.
- Elastic’s OtterCookie SVG steganography — Contagious Interview crew hiding four-stage payloads in SVG flag images shipped as part of fake coding-test project configurations. If your developers accept take-home coding assignments from external sources, treat the project files as untrusted input.
Enforcement and policy
- Aleksandr Ermakov, Yerevan — Armenia has held a Russian tourist named Aleksandr Ermakov since 2026-06-28 on a US extradition request for a REvil suspect of the same name. His lawyer says the paperwork carries a given name and a surname only — no patronymic — which is the defence’s specific basis for the misidentification claim. The Australian and UK sanctions entries on the REvil designee carry the patronymic Gennadievich; the OFAC entry, per reporting, does not. The Russian domestic legal record for the sanctioned figure has him under a two-year restriction of freedom that bars him from leaving Russia. Two years of ransomware-prosecution pipeline stories have followed the same beat: designate, travel, extradite. The pipeline only functions if the person on the plane is the person on the paperwork. If this is a misidentification, it burns the tool.
- DOJ — Chen and Zhang, $43 million — Two defendants charged with laundering $43 million from investment-fraud proceeds through 140 accounts and 45 shell entities across Queens and Brooklyn. The technical mechanism is boring by design; the scale is not.
- EU orders Google to open Android microphone, camera, and screen APIs to rival AI assistants — Competition-driven, not security-driven, but the security implications of mandated API surface expansion on the two most-attacked platforms in consumer computing will not be zero.
What to watch
- Whether CISA adds
wp2shellto KEV. Public PoC plus anonymous-request primitive plus unpatched-adjacent posture is the shape of a KEV addition. The federal clock under BOD 26-04 would then start compressing. - Whether Microsoft ships an out-of-band advisory on LegacyHive. Public LPE PoC on a service that runs on every Windows desktop does not sit for a full month-cycle if the exploitation telemetry moves.
- Whether Abbott’s dispute of the ShinyHunters tie holds through the week. Extortion attribution disputes are usually resolved one of two ways within 7-10 days — a leak-site posting, or a quiet retraction. Neither has happened yet.
- Whether the Ermakov detention produces a US Justice Department public position. The reporting chain currently runs through Russian outlets. A DOJ statement with disambiguating identifiers would close or open the story.
- Whether the Fairlife ransomware crew claims the Coca-Cola incident on a leak site. Thursday’s briefing flagged this at 72 hours; the window is nearly out. Silence past it is itself a signal.
Tip the desk
Source, document, or context on any story we’re tracking? Reach the desk at contact@0daynews.com, or for coordinated-disclosure matters, takedown@0daynews.com.
— kilobaud
- Rapid7 — ETR: CVE-2026-63030 wp2shell WordPress Core RCE
- The Hacker News — New wp2shell WordPress Core Flaw
- NVD — CVE-2026-63030
- BleepingComputer — Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
- BleepingComputer — Microsoft warns of surge in ACR Stealer attacks on customers
- The Hacker News — GoldenEyeDog Subgroup Linked to DigiCert Breach
- BleepingComputer — Abbott probes two cyber incidents amid extortion claims
- BleepingComputer — Ernst & Young discloses data breach after support system hack
- The Hacker News — Seven Malicious Vite npm Packages Use Blockchain C2
- BleepingComputer — New Windows LegacyHive zero-day gives hackers admin privileges
- CISA — Known Exploited Vulnerabilities Catalog