Tuesday, July 21, 2026 | Jonathan Lockhart

Qilin ransomware affiliates are turning a GlobalProtect bypass into domain-wide compromise

Arctic Wolf Labs reported Monday that multiple Qilin ransomware intrusions began with exploitation of CVE-2026-0257, an authentication bypass in Palo Alto Networks’ PAN-OS GlobalProtect portal and gateway. The firm investigated several June incidents in which attackers progressed from unauthorized VPN access to domain-wide encryption.

The vulnerability is exploitable when authentication-override cookies are enabled with certain certificate configurations. Palo Alto Networks patched it on May 13, confirmed limited exploitation, and CISA added it to the Known Exploited Vulnerabilities catalog on May 29.

Arctic Wolf observed credential dumping from LSASS, extraction of Active Directory’s NTDS database, PsExec-based lateral movement and broad log clearing. Some affiliates moved rapidly to encryption; others deployed remote-access tools and exfiltrated data first. That variation supports Arctic Wolf’s moderate-confidence assessment that multiple Qilin affiliates may be sharing the same access method.

Defenders should treat vulnerable or previously vulnerable appliances as possible intrusion points, not merely patching problems. Review historical GlobalProtect sessions, unusual hostnames, authentication-override configuration, administrative-account use and post-VPN credential access.

Watch for: Additional incident-response findings showing whether Qilin affiliates are sharing exploit infrastructure with other ransomware operations.

Sources: Arctic Wolf Labs, “Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware,” July 20, 2026; Palo Alto Networks CVE-2026-0257 advisory; CISA Known Exploited Vulnerabilities catalog.

SonicWall zero-days were used to install appliance-specific malware before patches existed

Volexity has published its investigation into exploitation of CVE-2026-15409 and CVE-2026-15410 against SonicWall SMA 1000 remote-access appliances. The earliest evidence it recovered dates to June 22, more than three weeks before SonicWall publicly disclosed the vulnerabilities on July 14.

The first flaw allowed the attacker to establish a WebSocket tunnel to an internal CouchDB service. The second abused Appliance Management Console hotfix handling through path traversal and code injection, providing a route to privileged execution. The operation affected SMA 6210, 7210 and 8200v appliances.

The attacker, tracked by Volexity as UTA0533, deployed a purpose-built toolset. KnuckleBall was used to inject the OrangeTail Java web shell and Suo5 proxy into legitimate processes, while a setuid binary called ROOTRUN supported privilege escalation. On one device, Volexity also found tcpdump-based tooling configured to capture unencrypted LDAP traffic.

Root access to a remote-access appliance can expose cached credentials and internal traffic even when obvious lateral movement is absent. The activity appeared targeted and technically capable, but Volexity has not connected UTA0533 to a known actor or established its motive.

SonicWall customers should run versions 12.4.3-03453 or 12.5.0-02835 and examine appliance logs, files and memory for Volexity’s indicators. Replacing or rebuilding a confirmed compromised appliance is safer than assuming a hotfix removed established persistence.

Watch for: Attribution or additional victims that clarify whether UTA0533 is conducting espionage, access brokerage or another form of targeted intrusion.

Sources: Volexity, “Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation,” July 17, 2026; SonicWall security advisory SNWLID-2026-0008, July 14, 2026; CISA Known Exploited Vulnerabilities catalog.

Wp2shell has moved from public disclosure to mass scanning and web-shell deployment

Exploitation of the WordPress vulnerability chain known as wp2shell has widened since BCG’s earlier coverage. WatchTowr now reports tens of thousands of exploitation attempts against its sensors, while Wiz has observed malicious plugins, unauthorized administrator accounts, credential theft and PHP web shells on compromised sites.

The chain depends on two distinct weaknesses. CVE-2026-63030 is a REST API batch-route confusion flaw that bypasses the intended authentication boundary and delivers attacker-controlled input to CVE-2026-60137, the SQL injection sink. Together, they create an unauthenticated route to remote code execution on affected stock WordPress installations without requiring a vulnerable plugin.

The remote-code-execution path affects WordPress 6.9 and later when persistent object caching is not enabled. Researchers have also found a web shell disguised as a CMSmap security plugin and more than 100 backdoor administrator accounts created after exploitation. Some observed traffic remains scanning rather than confirmed compromise, but the web shells and account creation establish that successful attacks are occurring.

Updating WordPress is necessary but insufficient where a site was exposed before remediation. Administrators should inspect users, plugins, themes, authentication keys and recently modified PHP files, and review historical logs even if the current version is fixed.

Watch for: CISA KEV inclusion, broader deployment of secondary malware, or evidence that compromised WordPress servers are being used for lateral access into hosting environments.

Sources: The Hacker News, “WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning,” July 21, 2026; Searchlight Cyber wp2shell research; Wiz wp2shell exploitation analysis; Cloudflare technical analysis.

Reported ServiceNow exploitation remains operationally important but evidentially unsettled

Threat-intelligence firm Defused reported observing exploitation attempts against CVE-2026-6875, a pre-authentication sandbox escape in the ServiceNow AI Platform. Searchlight Cyber disclosed the vulnerability and demonstrated that it could lead to full compromise of a ServiceNow instance and connected MID proxy servers.

ServiceNow deployed its security update to hosted instances and supplied patches to self-hosted customers. The immediate exposure therefore falls most heavily on self-managed deployments that have not applied the update.

The exploitation claim needs careful qualification. Defused initially described a payload that appeared to reach the same result through a different method, but later determined it was identical to Searchlight Cyber’s published proof of concept. ServiceNow says it has found no evidence of activity affecting its hosted instances, and no independent report has established malicious customer compromise. Security-industry testing remains a plausible explanation for the captured traffic.

Self-hosted customers should patch without waiting for attribution and review pre-authentication requests to exposed ServiceNow endpoints. Hosted customers should confirm their instance’s update status but should not interpret the current report as proof that ServiceNow-hosted environments have been breached.

Watch for: Independent confirmation of compromised customer instances, malicious post-exploitation activity, or a vendor advisory update acknowledging threat-actor use.

Sources: ServiceNow KB3137947, CVE-2026-6875 security advisory; Searchlight Cyber, “Smashing the ServiceNow Sandbox: Pre Authentication RCE,” July 14, 2026; SecurityWeek, “Exploitation of ServiceNow Vulnerability Seen Days After Disclosure,” July 21, 2026.

HollowGraph hides espionage traffic inside Microsoft 365 calendars

Group-IB has identified HollowGraph, Windows malware that uses a compromised Microsoft 365 mailbox calendar as a two-way command-and-control channel. Operators create calendar events containing instructions, while the implant exfiltrates encrypted files through attachments on events dated May 13, 2050.

Because the traffic passes through Microsoft Graph and legitimate Microsoft cloud infrastructure, conventional domain blocking may reveal little. HollowGraph also uses DNS tunneling through IPv6 AAAA queries to refresh the Microsoft Entra ID credentials required to access the mailbox.

Group-IB found the implant on 12 systems, with three actively communicating during its June 3 to July 9 analysis window. The available evidence points toward Israeli targets. Group-IB links HollowGraph with high confidence to the Cavern backdoor framework, but the more specific association with the Iran-linked Lyceum or OilRig ecosystem remains low confidence.

Defenders should examine unusual Graph API access, calendar events set implausibly far in the future, encrypted text attachments, unexpected application credentials and AAAA lookups involving the reported infrastructure. Microsoft 365 audit data may be more useful here than traditional perimeter telemetry.

Watch for: Additional victims or infrastructure that either strengthens the Iranian attribution or shows the calendar technique spreading beyond this targeted operation.

Sources: Group-IB, “HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels,” July 20, 2026; Check Point Research reporting on the Cavern framework and Cavern Manticore.

Hackers remained inside South Korea’s diplomatic training platform for nine months

South Korea’s Ministry of Foreign Affairs disclosed Monday that attackers compromised the Korea National Diplomatic Academy’s online education system from April 2025 until February 2026. The platform contained accounts belonging to current and former ministry employees, diplomats preparing for overseas postings and other government officials.

The ministry says exposed information included trainee identifiers, names, email addresses and encrypted passwords. It has not yet determined precisely what the attackers accessed or removed, and the platform remains offline.

Local reporting says the attackers exploited a previously unknown server-software vulnerability alongside security misconfiguration. That zero-day characterization has not been independently confirmed by the ministry. No actor has been identified, and South Korea has not attributed the incident to North Korea or any other state.

The nine-month dwell period matters more than the public description of the stolen fields. A diplomatic training platform can reveal personnel relationships, career movements, institutional interests and credential patterns useful for later espionage or social engineering.

Watch for: Identification of the affected server product, evidence of password recovery or reuse, and any official attribution based on infrastructure or post-compromise activity.

Sources: South Korean Ministry of Foreign Affairs data-protection notice, July 20, 2026; Recorded Future News, “Hackers Were Inside South Korea’s Diplomat Training System for 9 Months,” July 20, 2026; Korea JoongAng Daily reporting.

A cyberattack has frozen Romania’s digital land-registration system

Romania’s National Agency for Cadastre and Land Registration is rebuilding services after a cyberattack disabled its central infrastructure and the nationwide e-Terra platform. The disruption has prevented new property registrations, mortgage processing and the issuance of land-registry extracts for nearly a week.

Romanian cyber officials say the attackers combined known software vulnerabilities with previously leaked credentials. Authorities have found no evidence that the core cadastral and legal databases containing property boundaries, ownership and mortgage records were altered. A limited amount of information, including credentials and application source code, may nevertheless have been taken.

The agency is moving applications into the Romanian government cloud and says it will validate data integrity before restoring services. That sequencing is appropriate: in a property registry, corrupted or untrustworthy records could be more damaging than a prolonged outage.

A persona called ByteToBreach claimed responsibility and advertised purported government data. Romanian officials describe the actor as a financially motivated initial-access broker, but the identity and full extent of the stolen material remain unverified.

Watch for: Integrity-validation results, confirmation of the exploited products, and evidence that stolen source code or credentials are being resold for renewed access.

Sources: Romanian National Agency for Cadastre and Land Registration incident statements, July 14 and July 20, 2026; Romania’s National Directorate for Cyber Security statements; Recorded Future News, “Romania Races to Restore Land Registry After Cyberattack Disrupts Property Market,” July 20, 2026.

A breach at Craneware raises healthcare supply-chain questions across thousands of facilities

British healthcare software provider Craneware disclosed Monday that attackers entered part of its internal data environment and copied employee, customer and business-partner records. Craneware supplies billing, pricing and pharmacy software to more than 2,000 U.S. hospitals and nearly 10,000 clinics and retail pharmacies.

The company says the intrusion has been contained and did not disrupt its operations or hospital services. It reported the incident to the FBI and the United Kingdom’s Information Commissioner’s Office.

The unresolved issue is what customer information was taken. Craneware says many copied file names referred to non-sensitive or public regulatory material, but it has not determined whether patient information was included. It also has not disclosed the entry method, dwell time, responsible actor or whether extortion occurred.

Customers should not infer that their production systems were breached, but they should prepare to compare Craneware’s eventual notification against local integrations, support accounts, shared files and credentials. Vendor incidents can create follow-on phishing or access opportunities even when hosted services remain operational.

Watch for: Confirmation that patient data, customer credentials or technical integration information was included in the stolen records.

Sources: Craneware market and incident disclosure, July 20, 2026; Recorded Future News, “Software Provider to More Than 2,000 US Hospitals Says Hackers Stole Employee and Customer Data,” July 20, 2026.

Zimbra’s latest update closes an unauthenticated command-injection path

Zimbra released Collaboration Suite 10.1.20 on Monday with a permanent fix for a critical command-injection vulnerability in its SNMP monitoring component. Where SNMP notifications are enabled and the integrated Swatchdog service is running, an unauthenticated attacker could execute operating-system commands in the background.

The release also fixes four cross-site scripting weaknesses in the Classic Web Client, a mail-forwarding restriction bypass, access-control problems affecting the EWS extension and mailbox delegation, and a server-side request forgery flaw in the Nextcloud integration.

Zimbra has not reported exploitation of these vulnerabilities. However, externally reachable mail infrastructure remains a durable espionage and credential-theft target, and the command-injection flaw has been publicly known since late June. Zimbra 10.1.19 provided an earlier mitigation; version 10.1.20 supplies the permanent correction.

Administrators should upgrade to 10.1.20, verify whether SNMP notifications were enabled before patching and review mail-server activity for unexpected processes or configuration changes. Systems exposed during the disclosure window deserve a retrospective check.

Watch for: Publication of exploit code, scanning against the vulnerable SNMP-related path, or evidence that the flaw was used before the permanent fix arrived.

Sources: Zimbra, “Patch Release Update: Zimbra 10.1.20,” July 20, 2026; Zimbra security advisory, June 26, 2026; SecurityWeek, “Zimbra Update Patches Critical Vulnerabilities,” July 21, 2026.

LegacyHive now has an unofficial patch while Microsoft continues investigating

ACROS Security has released free 0patch micropatches for LegacyHive, the recently disclosed Windows User Profile Service vulnerability that remains unfixed by Microsoft. A local non-administrator can abuse the flaw to mount another user’s registry hive with broad access.

That access may expose stored secrets or allow registry changes that execute code when a targeted administrator later signs in. LegacyHive therefore does not provide initial access, but it can turn an existing low-privilege foothold into delayed compromise of a more privileged account.

The vulnerability was disclosed by the researcher known as Nightmare Eclipse or Chaotic Eclipse. It is part of a broader series of Windows flaw disclosures associated with a public dispute over Microsoft’s vulnerability-reporting process. That context does not diminish the technical risk, but it increases uncertainty around coordinated remediation, CVE assignment and the timing of an official patch.

The micropatches cover current Windows 11 releases, Windows Server 2022 and 2025, and supported 0patch deployments of Windows 10 beginning with version 2004. Microsoft says it is investigating but has not assigned a CVE or provided an official security update. No confirmed malicious exploitation has been reported.

Organizations should weigh third-party patching against their software-control requirements. Where 0patch is unsuitable, defenders can use the published Microsoft Defender hunting queries and monitor unusual hive-loading activity, registry changes and execution immediately after privileged users log in.

Watch for: A Microsoft CVE and official fix, or evidence that public proof-of-concept material has been converted into practical post-compromise tooling.

Sources: 0patch, “Free Micropatches Available for LegacyHive 0day,” July 21, 2026; Nightmare Eclipse LegacyHive disclosure; BleepingComputer, “Windows LegacyHive Zero-Day Flaw Gets Free, Unofficial Patches,” July 21, 2026; Kevin Beaumont LegacyHive Microsoft Defender hunting queries.


Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.