logo

WordPress, 7-Zip RCE exploited; NadMesh steals AWS keys; ACR Stealer surge

ID: 3ee44421-d606-5353-b3a9-632ba32bf2bb

STIX ID: report--3ee44421-d606-5353-b3a9-632ba32bf2bb

Feed Name: defend.network

Threat Score
78/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

Author: defend.network

...
...

THREAT LEVEL: HIGH — Multiple actively exploited vulnerabilities and active malware campaigns require immediate remediation: WordPress 'wp2shell' RCE now has public exploits and needs urgent patching; NadMesh botnet is harvesting exposed AI services to steal AWS keys at scale; Microsoft reports a surge in ACR Stealer infostealer activity; 7‑Zip fixed a critical RCE and should be updated; Abbott is investigating two separate breaches. Recommended actions include immediate patching, rotating keys/tokens, deploying or enhancing EDR and WAF protections, segmenting exposed AI services, and auditing logs for unauthorized activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.