← Back to Archive

Critical SharePoint RCE Exploited as Qilin Ransomware Leverages PAN-OS Bypass; CISA Issues 10 ICS Advisories

Date: Wednesday, July 22, 2026

Prepared for: Critical Infrastructure Owners, Operators, and Security Professionals


1. EXECUTIVE SUMMARY

Major Developments

  • Active Exploitation of Critical Vulnerabilities: Microsoft SharePoint (CVE-2026-50522) and ServiceNow AI Platform (CVE-2026-6875) vulnerabilities are under active exploitation within days of disclosure, with attackers stealing machine keys and achieving unauthenticated remote code execution.
  • Ransomware Operators Weaponizing Network Security Flaws: Qilin ransomware gang is actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability for initial access to victim networks.
  • Significant ICS Advisory Release: CISA published 10 Industrial Control System advisories on July 21, affecting Rockwell Automation, Siemens, and Tycon Systems products deployed across manufacturing, energy, and critical infrastructure sectors.
  • Healthcare Sector Under Siege: Multiple healthcare-related breaches disclosed this week, including Craneware (hospital financial software), Clover Health Investments, and Estée Lauder (health information exposure from 2025 Oracle EBS zero-day).
  • Supply Chain Security Executive Action: New executive order mandates defense contractors map software dependencies and foreign ownership across critical supply chains.

Threat Actor Activity Highlights

  • Qilin Ransomware: Exploiting PAN-OS authentication bypass; claimed responsibility for Coca-Cola Fairlife attack
  • JADEPUFFER: AI-agent-driven operator deploying new ENCFORGE ransomware targeting AI model files
  • North Korean Actors: IT worker scheme funding Russia's war effort; "ClickFake" campaign targeting Web3 professionals
  • Russian Actor "Trim": Built commercial offensive AI pentest tool on jailbroken Claude models

Cross-Sector Concerns

  • WordPress "wp2shell" exploitation affecting websites across all sectors
  • AI agent security vulnerabilities enabling sandbox escapes and unauthorized code execution
  • Cloud infrastructure attacks potentially threatening power grid stability (Bit2Watt research)
  • 79% of ransomware attacks now originate from compromised identities

2. THREAT LANDSCAPE

Nation-State Threat Actor Activities

North Korean Operations

  • IT Worker Scheme Funding Russian Military: DTEX researchers identified payment wallet transactions showing North Korean IT worker salaries flowing to sanctioned entities supporting Russia's military programs. This represents a concerning convergence of adversary interests with implications for sanctions enforcement and supply chain security. (CyberScoop)
  • "ClickFake" Campaign: Famous Chollima (North Korean APT) is targeting cryptocurrency and Web3 professionals using ClickFix social engineering lures to deliver Windows and macOS trojans. Organizations in the financial services and technology sectors should heighten awareness. (Infosecurity Magazine)

Russian-Speaking Threat Actors

  • Weaponized AI for Offensive Operations: A Russian-speaking actor known as "Trim" has developed a commercial offensive AI penetration testing tool built on jailbroken Claude models. This represents an escalation in adversary use of AI for cyber operations. (Infosecurity Magazine)

Ransomware and Cybercriminal Developments

Qilin Ransomware

  • PAN-OS Exploitation: Arctic Wolf reports Qilin operators are actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability for initial network access. Organizations using GlobalProtect VPN should verify patch status immediately. (Bleeping Computer)
  • Fairlife Attack: Anubis ransomware gang claimed the Coca-Cola Fairlife attack, threatening data publication. This attack halted production operations, demonstrating ransomware's continued impact on manufacturing and food/beverage supply chains. (Bleeping Computer)

ENCFORGE Ransomware

  • AI-Targeted Attacks: Sysdig researchers linked JADEPUFFER, an AI-agent-driven operator, to deployment of ENCFORGE ransomware specifically targeting AI model files through Langflow RCE vulnerabilities. Organizations with AI/ML infrastructure should assess exposure. (The Hacker News)

Ransomware Ecosystem Trends

  • Rapid Fragmentation: Black Kite analysis warns a new ransomware threat actor emerges approximately every week, indicating the ecosystem is becoming larger and more fragmented. (Infosecurity Magazine)
  • Identity-Based Initial Access: 79% of ransomware attacks now begin with compromised credentials, emphasizing the critical importance of identity security and access management. (Security Magazine)

Emerging Attack Vectors

AI Agent Vulnerabilities

  • AWS Kiro IDE Flaw: Hidden text on web pages could make AWS's Kiro agentic coding IDE rewrite its configuration and execute attacker code without approval. This highlights risks in AI-assisted development tools. (The Hacker News)
  • Android AI Agent Manipulation: Open-source Android AI agents can be manipulated through invisible screen text to execute code on host PCs, representing a new class of cross-platform attack. (The Hacker News)
  • Sandbox Escape Without Exploitation: Research demonstrates AI agents can escape sandboxes without traditional exploitation techniques, challenging conventional containment strategies. (CSO Online)

Cloud Infrastructure Threats

  • Bit2Watt Attack: Researchers demonstrated that cloud tenants using standard GPU access can manipulate data center power draw rapidly enough to threaten connected power grids—without any exploit or unauthorized access. This represents a novel threat vector for energy sector interdependencies. (The Hacker News)

Social Engineering Evolution

  • Deepfake Impersonation: FBI warned of deepfake videos impersonating IC3 leadership directing users to spoofed complaint sites. This technique could be adapted to impersonate critical infrastructure leadership. (Infosecurity Magazine)

Phishing Infrastructure Disruption

  • Kratos PhaaS Takedown: German and U.S. authorities dismantled the Kratos phishing-as-a-service platform infrastructure, with the developer arrested in Indonesia. This disruption may temporarily reduce phishing campaign volume. (Bleeping Computer)

3. SECTOR-SPECIFIC ANALYSIS

Energy Sector

Grid Stability Concerns

  • Bit2Watt Research Implications: The demonstrated ability to manipulate data center power consumption to affect grid stability has direct implications for energy sector operators. Cloud-connected facilities and data centers should be considered potential vectors for grid disruption.
  • Recommended Actions:
    • Review power consumption monitoring capabilities for anomaly detection
    • Assess grid interconnection points for rapid load fluctuation resilience
    • Coordinate with cloud service providers on power management controls

ICS Vulnerabilities

  • Multiple Rockwell Automation advisories (see Section 4) affect systems commonly deployed in energy sector environments
  • Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW advisory relevant to energy sector network security appliances

Water & Wastewater Systems

Monitoring System Vulnerabilities

  • Tycon Systems TPDIN-Monitor-WEB2: CISA advisory (ICSA-26-202-01) addresses critical vulnerabilities in this monitoring device used in water/wastewater and other critical infrastructure environments. Successful exploitation could allow unauthorized access to monitoring systems. (CISA)

Recommended Actions

  • Inventory Tycon Systems devices and apply available mitigations
  • Ensure SCADA/monitoring systems are segmented from business networks
  • Review remote access controls for operational technology environments

Communications & Information Technology

Enterprise Software Under Attack

  • ServiceNow AI Platform (CVE-2026-6875): Critical vulnerability enabling unauthenticated remote code execution is under active exploitation. Organizations using ServiceNow AI Platform should patch immediately. (The Hacker News)
  • Microsoft SharePoint (CVE-2026-50522): Third SharePoint vulnerability from July Patch Tuesday now under active exploitation. Attackers are stealing machine keys to maintain persistence post-patching. (Bleeping Computer)
  • Zimbra Collaboration: Critical SNMP command injection and four XSS vulnerabilities patched. Organizations should update immediately. (The Hacker News)

WordPress Infrastructure

  • wp2shell Exploitation: Critical WordPress Core vulnerabilities (CVE-2026-63030 and CVE-2026-60137) are being actively exploited to deploy webshells and malicious plugins. This affects websites across all sectors. (Bleeping Computer)

Smart Device Security

  • LG Smart TV Proxy Ban: LG Electronics USA will suspend apps that turn smart TVs into residential proxy nodes, addressing a vector used for malicious traffic routing. (KrebsOnSecurity)

Healthcare & Public Health

Active Breaches and Disclosures

  • Craneware Data Breach: Hospital financial software provider disclosed unauthorized access and data theft affecting healthcare organizations using their platform. (Infosecurity Magazine)
  • Clover Health Investments: Social engineering attacks compromised employee accounts with access to personal and health information. (SecurityWeek)
  • Estée Lauder (Historical): Company disclosed impact from August 2025 Oracle EBS zero-day hack, with exfiltration of personal, financial, and health information. (SecurityWeek)

Sector Recommendations

  • Review third-party software vendor security postures
  • Implement enhanced monitoring for social engineering indicators
  • Ensure incident response plans address PHI/PII exposure scenarios

Financial Services

Cryptocurrency/Web3 Targeting

  • North Korean "ClickFake" campaign specifically targeting Web3 professionals represents continued focus on cryptocurrency sector
  • Organizations should implement enhanced verification for software downloads and job-related communications

Identity Security Priority

  • With 79% of ransomware attacks starting with compromised identities, financial services organizations should prioritize:
    • Multi-factor authentication across all systems
    • Privileged access management
    • Continuous identity monitoring and anomaly detection

Manufacturing

Production Disruption

  • Coca-Cola Fairlife: Cyberattack halted production operations, with Anubis ransomware claiming responsibility. This demonstrates continued ransomware impact on manufacturing operations. (Security Magazine)

ICS/OT Vulnerabilities

  • Multiple Rockwell Automation advisories affect manufacturing automation systems (see Section 4)
  • Siemens Opcenter X vulnerability affects manufacturing execution systems

Defense Industrial Base

Supply Chain Mapping Mandate

  • Executive Order: New directive requires defense contractors to achieve end-to-end visibility into supply chains, including software dependencies, foreign ownership, and cyber-related supplier risks. (SecurityWeek)
  • Implications: Defense contractors should begin:
    • Software Bill of Materials (SBOM) development
    • Foreign ownership assessment of suppliers
    • Cyber risk evaluation of supply chain partners

4. VULNERABILITY & MITIGATION UPDATES

Critical Vulnerabilities Requiring Immediate Attention

CVE/Advisory Product Status Action
CVE-2026-50522 Microsoft SharePoint ACTIVELY EXPLOITED Patch immediately; rotate machine keys
CVE-2026-6875 ServiceNow AI Platform ACTIVELY EXPLOITED Patch immediately
PAN-OS Auth Bypass Palo Alto GlobalProtect ACTIVELY EXPLOITED Verify patch status; monitor for Qilin indicators
CVE-2026-63030/60137 WordPress Core (wp2shell) ACTIVELY EXPLOITED Update WordPress; scan for webshells
Windows LegacyHive Windows (all versions) Zero-day (unofficial patches available) Evaluate unofficial patches; monitor for official fix

CISA ICS Advisories (Published July 21, 2026)

Rockwell Automation (5 Advisories)

Siemens (5 Advisories)

  • ICSA-26-202-03: Opcenter X (versions before V2604) - Advisory Link
  • ICSA-26-202-02: RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW - Advisory Link
  • ICSA-26-202-05: IAM Client (multiple products affected) - Advisory Link
  • ICSA-26-202-04: SIDIS Secured SmartPlug (versions before V7) - Advisory Link
  • ICSA-26-202-06: CADRA (zlib vulnerabilities) - Advisory Link

Tycon Systems

Additional Patches and Updates

  • Zimbra: Critical SNMP command injection and four XSS vulnerabilities patched (9 total security issues addressed)
  • Apple: Fixed Hide My Email bug that exposed real email addresses in Mail logs
  • Meta: Paid $78,000 bounty for broken access control vulnerability in support infrastructure

Mitigation Guidance

For SharePoint Exploitation (CVE-2026-50522)

  1. Apply July 2026 Patch Tuesday updates immediately
  2. Rotate machine keys even after patching (attackers stealing keys for persistence)
  3. Review SharePoint logs for indicators of compromise
  4. Implement network segmentation for SharePoint servers

For Identity-Based Attacks

  • Implement phishing-resistant MFA across all critical systems
  • Deploy privileged access management solutions
  • Enable continuous authentication monitoring
  • Conduct regular access reviews and remove dormant accounts

Windows WSUS Issues

  • Microsoft has shared manual mitigations for WSUS sync delays and timeouts affecting Windows Update scans. (Bleeping Computer)

5. RESILIENCE & CONTINUITY PLANNING

Lessons from Recent Incidents

Fairlife Production Halt

  • Key Takeaway: Ransomware continues to cause operational disruptions in manufacturing environments
  • Recommendations:
    • Ensure OT/IT network segmentation
    • Maintain offline backups of critical production systems
    • Develop and test manual operation procedures
    • Pre-position incident response resources

SharePoint Machine Key Theft

  • Key Takeaway: Patching alone may not eliminate attacker persistence
  • Recommendations:
    • Include credential/key rotation in incident response procedures
    • Implement post-patch verification processes
    • Monitor for persistence mechanisms after remediation

Supply Chain Security Developments

Defense Contractor Requirements

  • New executive order establishes framework for supply chain visibility that may expand to other critical infrastructure sectors
  • Organizations should proactively develop:
    • Software Bill of Materials (SBOM) capabilities
    • Supplier risk assessment programs
    • Foreign ownership tracking mechanisms

Malicious Repository Campaign

  • FakeGit Campaign: 7,600 malicious GitHub repositories pushing SmartLoader and StealC malware accumulated over 14 million downloads. This highlights software supply chain risks. (Bleeping Computer)
  • Recommendations:
    • Verify repository authenticity before use
    • Implement software composition analysis
    • Use private/vetted package repositories where possible

Cross-Sector Dependencies

Cloud-Energy Interdependencies

  • Bit2Watt research demonstrates potential for cloud workloads to affect grid stability
  • Energy sector operators should coordinate with major cloud providers on:
    • Power consumption monitoring
    • Anomaly detection for rapid load changes
    • Emergency load shedding procedures

AI Infrastructure Dependencies

  • ENCFORGE ransomware targeting AI model files indicates emerging risk to AI-dependent operations
  • Organizations should include AI/ML assets in business continuity planning

World Cup Cybersecurity Lessons

  • Analysis of FIFA World Cup 2026 security operations provides insights for major event protection
  • Key lessons: Cyber resilience planning must begin months before events and extend beyond physical perimeters (CyberScoop)
  • U.S. DOJ seized over 1,000 websites and blocked 1,970 domains for unauthorized World Cup streaming (Bleeping Computer)

6. REGULATORY & POLICY DEVELOPMENTS

Federal Actions

Defense Supply Chain Executive Order

  • Scope: Requires defense contractors to map software dependencies, foreign ownership, and cyber-related supplier risks across critical supply chains
  • Implications: Establishes precedent that may extend to other critical infrastructure sectors
  • Timeline: Implementation details pending; contractors should begin preparatory assessments
  • Source: SecurityWeek

House Intelligence Authorization Bill (FY2027)

  • House Intelligence Committee advanced legislation including provisions on:
    • State and local threat intelligence sharing
    • Election security measures
    • AI-related security requirements
  • Source: CyberScoop

AI Regulation Landscape

  • Analysis indicates the Trump administration's approach to AI regulation remains in flux, reflecting both rapid advancement in model capabilities and evolving policy positions
  • Organizations should monitor for regulatory developments while implementing risk-based AI governance frameworks
  • Source: CyberScoop
Disclaimer

This briefing is generated using AI analysis of public news sources. Always verify critical information through authoritative sources before taking action.