THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Critical SharePoint RCE (CVE-2026-58644) is actively exploited—patch SharePoint 2016/2019/Subscription Edition immediately

Microsoft disclosed a critical unauthenticated remote code execution flaw in on-premises Microsoft SharePoint Server (CVE-2026-58644, CVSS 9.8) driven by deserialization of untrusted data. Microsoft confirmed active exploitation, and CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog—meaning defenders should treat it as “already in the wild.” Key mitigations include applying the July 14 security updates, verifying they completed across all servers, and ensuring AMSI integration and Defender detections are enabled.

Source: Rapid7


WordPress core hits with unauthenticated RCE (CVE-2026-63030, fixed in 6.9.5 and 7.0.2)

A GitHub security advisory published CVE-2026-63030, an unauthenticated remote code execution vulnerability in WordPress core that can be triggered via the REST API batch endpoint. The affected range spans WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; fixed releases are 6.9.5 and 7.0.2, with additional fixes included in 7.1 Beta 2. Cloudflare noted the vulnerable path can be reached when a persistent object cache is not in use, and researchers warn that public PoCs are likely soon given the open-source core.

Source: Rapid7


Fairlife (Coca-Cola dairy) suspends U.S. production after ransomware incident

Fairlife’s U.S. operations were temporarily suspended following a ransomware attack, according to disclosures tied to Coca-Cola’s reporting. The incident did not impact product quality and safety, but it disrupted production operations across facilities in multiple states. For security teams, the takeaway is operational resilience: ransomware response must include continuity planning, segmented recovery paths, and validated backups that can be used quickly enough to prevent prolonged production downtime.

Source: Help Net Security


Shark robot vacuum vulnerability potentially exposes cameras and Wi‑Fi credentials

A reported flaw affecting Shark robot vacuums raises the risk of cascading compromise: a single infected device can enable attackers to unlock remote access to other devices in the same environment. The downstream impact is serious for home networks, including access to sensitive information such as Wi‑Fi passwords and home maps. This is a reminder that IoT security failures are rarely “single-device” problems—lateral access and poor isolation can turn a minor issue into a broader privacy and account-takeover event.

Source: Malwarebytes Blog


Spirals ransomware locks down systems in under 24 hours after gaining a foothold

Symantec researchers described a previously unknown ransomware strain (“Spirals”) used in an attack against an IT services company in South Asia, with attackers moving from initial access to data theft and encryption in less than a day. The description highlights how quickly modern crews chain discovery and exploitation into extortion-ready outcomes. For defenders, the critical insight is time-to-containment—monitoring and response should be tuned for rapid lateral movement and “short dwell” workflows, not just long, slow intrusion patterns.

Source: Help Net Security


CISA/industry spotlight: “Gold Eagle” aims to centralize AI-discovered vulnerabilities—will it avoid patch fatigue?

Reporting on the U.S. government’s “Gold Eagle” initiative frames it as an attempt to manage the flood of vulnerabilities identified by frontier LLMs, including verification and remediation prioritization. Analysts caution that success depends on validation and decision-making—if the clearinghouse merely dumps unfiltered findings, it could create patch fatigue and confusion. The push for evidence standards (and prioritizing likely active exploitation) is the key policy/operational hinge for whether the program reduces risk or increases noise.

Source: TechTarget


You May Also Be Interested In...

Attackers target critical FortiSandbox flaws as CISA issues patch order
Google fixing Android lock screen bug that lets Gemini send SMS without a PIN
Capital One releases VulnHunter, an open-source AI tool that finds exploitable flaws

Cybersecurity — July 18, 2026 | Briefing24