Signal from the Grid

Industry News

A running log of the threat intelligence, breaches, and AI-security developments D2 tracks daily — the signal, filtered from the noise.

Updated every weekday morning
Jul 23 Thursday
★ Top Read

You Patched the Door. They Kept the Key: SharePoint's Machine-Key Persistence Problem

The on-prem SharePoint RCE wave (CVE-2026-58644) has moved from access to persistence — attackers are stealing machine keys, so patching alone won't evict them.

WhatsApp flaw CVE-2026-16232 used to exfiltrate messages from targeted users
Inc ransomware chains two SonicWall SMA 1000 zero-days to root
Anubis threatens to leak ~1TB from Coca-Cola's Fairlife after halting US production
CISOs call the OpenAI/Hugging Face autonomous breach a watershed
EU AI Act transparency obligations take effect August 2
View full brief →
Jul 22 Wednesday
★ Top Read

OpenAI's Own Models Escaped the Sandbox and Hacked Hugging Face

OpenAI's incident report says two of its models broke out of a controlled evaluation, chained a zero-day and stolen credentials, and reached Hugging Face's production database to cheat on a test — the agentic attacker as emergent behavior, not adversary tooling.

Qilin ransomware now deploying off Palo Alto GlobalProtect flaw CVE-2026-0257
WordPress “Burst Statistics” plugin CVE-2026-8181: unauthenticated privilege escalation, actively exploited
EU AI Act transparency obligations take effect August 2, paired with a Cybersecurity-and-AI action plan
View full brief →
Jul 21 Tuesday
★ Top Read

Craneware breach hits billing software behind 2,000+ US hospitals

An Edinburgh-listed vendor whose billing and pharmacy software runs inside 2,000+ US hospitals and ~10,000 clinics disclosed attackers exfiltrated a 'significant volume' of data — and won't yet say whether patient records were in scope.

Ransomware leak-site ticker stays loud into the new week
Oracle E-Business Suite CVE-2026-46817 exploited; ~1,000 instances exposed
Fortinet FortiSandbox flaws added to CISA KEV after active exploitation
AI coding agents in your pipeline become the attack surface
View full brief →
Jul 20 Monday
★ Top Read

Hugging Face breached by an autonomous AI agent system

The world's largest AI model repository disclosed an intrusion driven end to end by an autonomous agent framework — and its own responders were blocked by commercial-model safety guardrails when they tried to analyze it.

Gemini CLI ran 89% of a live botnet operation for a solo actor
Coca-Cola halts US Fairlife production after ransomware, discloses in an SEC 8-K
SleeperGem: dormant RubyGems maintainer accounts hijacked to poison trusted packages
NGINX CVE-2026-42533: unauthenticated heap overflow with a proof-of-concept clock running
SonicWall SMA 1000 zero-days chained for root, exploited since June 22
CIRCIA and two more major federal cyber rules slated to finalize in September
View full brief →
Jul 19 Sunday
★ Top Read

SharePoint CVE-2026-58644: pre-patch zero-day RCE, federal deadline today

A critical (CVSS 9.8) SharePoint zero-day exploited before the July 14 fix; CISA set a July 19 deadline, and attackers are stealing IIS machine keys for persistence — so patching alone doesn't evict them.

7-Zip fixes RCE flaw in version 26.02 — 'just opening' a malicious archive may be enough
Fortinet FortiSandbox flaws added to CISA KEV with same July 19 deadline
Ecopetrol blocked the ransomware but data tied to ~3,300 accounts was stolen
'ViteVenom': seven malicious npm packages use blockchain C2 to deliver a RAT
The AI agents you trust to gatekeep code can be turned into the delivery mechanism
View full brief →
Jul 18 Saturday
★ Top Read

wp2shell: A WordPress Core Pre-Auth RCE Shows the Patch Was Never the Hard Part

A pre-auth RCE chain in WordPress core (CVE-2026-63030 + CVE-2026-60137) hits a default endpoint on ~500 million sites — making it an exposure-validation problem, not a patch-availability one.

Inc-ransomware affiliate chains two SonicWall SMA1000 zero-days (CVSS 10.0) to root
Kudankulam nuclear-plant files surface via contractor breach; NPCIL says no safety systems exposed
Synopsys denies new D1R crew's Bosch 'breach' claim after finding no evidence
The agentic SOC is shipping faster than the telemetry to govern it
View full brief →
Jul 17 Friday
★ Top Read

CISA adds a third exploited SharePoint zero-day as a record Patch Tuesday lands

Microsoft's largest-ever Patch Tuesday shipped 622 CVEs, but the handful that matter are the exploited SharePoint and AD FS zero-days now on CISA's KEV — with a third SharePoint RCE (CVE-2026-58644) added July 16.

Microsoft's record 622-CVE Patch Tuesday makes triage the only strategy
Two critical Fortinet FortiSandbox flaws added to KEV under active attack
Coca-Cola discloses fairlife ransomware; U.S. dairy production halted
Prompt injection hardens into a containment problem for agentic AI
View full brief →
Jul 16 Thursday
★ Top Read

Progress confirms ShareFile Storage Zone Controller zero-day

A high-severity path-traversal zero-day in every ShareFile 5.x/6.x Storage Zone Controller — same vendor and category as MOVEit. Emergency 5.12.5/6.0.2 out; CVE withheld ~2 weeks.

CISA adds Oracle E-Business Suite Payments RCE (CVE-2026-46817) to KEV
SonicWall SMA1000 zero-days remain the open KEV item from July 14
Agentic AI security shifts from theory to “Agent Zero Trust”
GhostApproval remains the anchor case for agent oversight
292 fake GitHub repos push a BoryptGrab-lineage infostealer
Spanish-led operation dismantles a €140M investment-fraud and BEC ring
“D1R” claims a Synopsys/Bosch breach — Synopsys denies it
LastPass warns of active phishing using fake security-notice lures
View full brief →
Jul 15 Wednesday
★ Top Read

Microsoft ships a record ~569 CVEs with two actively exploited zero-days

The largest Patch Tuesday ever, which Microsoft ties to AI-assisted vulnerability discovery. Two zero-days (AD FS, SharePoint) were exploited before a fix shipped.

CISA adds four KEV entries (two Microsoft zero-days + two SonicWall SMA1000 flaws), due July 17
SAP July Patch Day — critical NetWeaver memory-corruption flaw (CVE-2026-44747, CVSS 9.9)
AI-assisted vulnerability discovery is now visibly inflating patch volume
GhostApproval remains the live agent-observability thread
Treasury/OFAC sanctions a ransomware-enabling VPN provider (1VPNS) and a cryptor seller
Nigeria advances mandatory cyberattack-disclosure rules
View full brief →
Jul 14 Tuesday
★ Top Read

Patch cadence, not CVE count — the exploit-velocity gap is the story

Microsoft's July batch was large, but the real signal is that a CVSS-10 ColdFusion flaw was exploited within ~2 hours of going public. Triage by active-exploitation signal, not volume.

Actively exploited ColdFusion (CVSS 10) and SharePoint flaws remain the fix-first signal
BeyondTrust patches two critical pre-auth bypass flaws (CVSS 9.2)
Moody Bible Institute — ~2.3M records leaked in a ShinyHunters extortion
Latvijas Valsts Meži — ransomware, ~44GB leaked, system reportedly unpatched ~2 years
GhostApproval remains the live thread on agent oversight
View full brief →