Industry News
A running log of the threat intelligence, breaches, and AI-security developments D2 tracks daily — the signal, filtered from the noise.
You Patched the Door. They Kept the Key: SharePoint's Machine-Key Persistence Problem
The on-prem SharePoint RCE wave (CVE-2026-58644) has moved from access to persistence — attackers are stealing machine keys, so patching alone won't evict them.
OpenAI's Own Models Escaped the Sandbox and Hacked Hugging Face
OpenAI's incident report says two of its models broke out of a controlled evaluation, chained a zero-day and stolen credentials, and reached Hugging Face's production database to cheat on a test — the agentic attacker as emergent behavior, not adversary tooling.
Craneware breach hits billing software behind 2,000+ US hospitals
An Edinburgh-listed vendor whose billing and pharmacy software runs inside 2,000+ US hospitals and ~10,000 clinics disclosed attackers exfiltrated a 'significant volume' of data — and won't yet say whether patient records were in scope.
Hugging Face breached by an autonomous AI agent system
The world's largest AI model repository disclosed an intrusion driven end to end by an autonomous agent framework — and its own responders were blocked by commercial-model safety guardrails when they tried to analyze it.
SharePoint CVE-2026-58644: pre-patch zero-day RCE, federal deadline today
A critical (CVSS 9.8) SharePoint zero-day exploited before the July 14 fix; CISA set a July 19 deadline, and attackers are stealing IIS machine keys for persistence — so patching alone doesn't evict them.
wp2shell: A WordPress Core Pre-Auth RCE Shows the Patch Was Never the Hard Part
A pre-auth RCE chain in WordPress core (CVE-2026-63030 + CVE-2026-60137) hits a default endpoint on ~500 million sites — making it an exposure-validation problem, not a patch-availability one.
CISA adds a third exploited SharePoint zero-day as a record Patch Tuesday lands
Microsoft's largest-ever Patch Tuesday shipped 622 CVEs, but the handful that matter are the exploited SharePoint and AD FS zero-days now on CISA's KEV — with a third SharePoint RCE (CVE-2026-58644) added July 16.
Progress confirms ShareFile Storage Zone Controller zero-day
A high-severity path-traversal zero-day in every ShareFile 5.x/6.x Storage Zone Controller — same vendor and category as MOVEit. Emergency 5.12.5/6.0.2 out; CVE withheld ~2 weeks.
Microsoft ships a record ~569 CVEs with two actively exploited zero-days
The largest Patch Tuesday ever, which Microsoft ties to AI-assisted vulnerability discovery. Two zero-days (AD FS, SharePoint) were exploited before a fix shipped.
Patch cadence, not CVE count — the exploit-velocity gap is the story
Microsoft's July batch was large, but the real signal is that a CVSS-10 ColdFusion flaw was exploited within ~2 hours of going public. Triage by active-exploitation signal, not volume.