Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Sunday's digest covers the final waves of a news-heavy week in cybersecurity. The most significant stories include the disclosure of the wp2shell WordPress Core flaw (CVE-2026-63030 + CVE-2026-60137) โ an unauthenticated RCE chain that puts hundreds of millions of WordPress sites at risk, now with a public PoC. Microsoft's record-smashing Patch Tuesday plugged 570 security holes, nearly triple last month's count, with AI-driven discovery credited for the surge. In legal developments, Illinois became the third US state to enact a frontier AI model law, and CISA announced it plans to finalise Cyber Incident Reporting regulations by September 2026. The joint CISA/ASD/NCSC advisory on Russian state-sponsored targeting of network devices continued to reverberate through the week. On the cybercrime front, two Scattered Spider affiliates were sentenced to 5.5 years for the ยฃ29 million Transport for London hack, while a series of healthcare data breaches โ including All About Women's Care (12,000 patients affected) โ continued to accumulate.
Incident Map
IT / Technology 5 stories
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Two chained vulnerabilities in WordPress core โ CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection) โ allow anonymous HTTP requests to achieve code execution on any unpatched WordPress 6.9 or 7.0 site. WordPress shipped emergency updates (6.9.5/7.0.2) with forced auto-updates, but a public PoC is now on GitHub. A bare install with zero plugins is exploitable.
Microsoft Patches a Record 570 Security Flaws
Microsoft's July Patch Tuesday fixed at least 570 vulnerabilities, nearly triple last month's count and an all-time record. Nearly 60 were rated Critical, including three zero-days, two of which are under active exploitation. Microsoft EVP Rajeesh Davuluri attributed the surge to AI-aided vulnerability discovery.
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
Okta's Red Team disclosed a denial-of-service vulnerability in OpenSSL where an 11-byte TLS handshake message tricks the server into allocating up to 131 KB of memory that is never freed. The fix shipped in June without a CVE or changelog entry. Fixed releases: OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21.
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CISA added CVE-2026-58644 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog โ a deserialisation vulnerability in Microsoft SharePoint Server allowing remote code execution by an attacker with at least Site Owner privileges. FCEB agencies must patch by July 19.
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Expel attributed the April 2026 DigiCert security incident to CylindricalCanine, a sub-group of the Chinese cybercrime group GoldenEyeDog (APT-Q-27). The threat actor accessed a DigiCert support member's device via Gh0st RAT, stealing code-signing certificates intended for customers.
Healthcare 2 stories
All About Women's Care Data Breach Affects Up to 12,000 Patients
All About Women's Care in Colorado notified 12,000 patients that their data was compromised in a data breach. The incident underscores ongoing cybersecurity challenges facing women's healthcare providers.
Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit
Charlotte-Mecklenburg Hospital Authority (doing business as Atrium Health) agreed to pay up to $1,800,000 to settle a class action lawsuit over the use of tracking pixels on its patient portal, which allegedly disclosed protected health information to third parties without consent.
Legal / Regulatory 4 stories
Illinois Governor Signs Frontier AI Model Law
Illinois Governor JB Pritzker signed SB 315, the Artificial Intelligence Safety Measures Act, making Illinois the third US state to enact comprehensive safety and transparency requirements for developers of advanced AI systems. The law covers frontier model testing, incident reporting, and pre-deployment assessments.
CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026
CISA continues to finalise regulations implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). A final rule is expected in September 2026, requiring covered critical infrastructure entities to report significant cyber incidents within 72 hours and ransomware payments within 24 hours.
New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale Restrictions
New Jersey Governor Mikie Sherrill signed a new law requiring data brokers and data collectors to register annually, pay a fee, make specified disclosures, and refrain from selling or licensing sensitive data. The law takes effect in 2027.
European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays
The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to notify full transposition of the NIS2 Directive into national law. The action underscores growing EU enforcement pressure on member states lagging behind the October 2024 deadline.
Financial Services 2 stories
23andMe Reaches $18 Million Settlement with States for Massive Breach
23andMe reached an $18 million settlement with multiple US states over a 2023 data breach that exposed the genetic and personal data of millions of customers. The settlement resolves investigations by state attorneys general into the company's security practices.
Cash App Owner to Pay $45 Million to Settle Allegations of Lax Security
The owner of Cash App agreed to pay $45 million to settle allegations of inadequate security practices following a data security incident. The settlement โ featured in The Record's briefs sidebar โ highlights growing regulatory focus on fintech security.
Government 2 stories
Lessons Learned from CISA's Recent GitHub Leak
CISA issued a postmortem on a data leak where a contractor published internal CISA credentials โ including AWS GovCloud keys โ in a public GitHub repository for nearly six months. The report acknowledges key rotation delays, unclear reporting channels, and nine ignored automated alerts from GitGuardian. KrebsOnSecurity first broke the story and facilitated notification.
Trump Administration Unveils AI-Supported Clearinghouse for Cyber Vulnerabilities
The White House announced a new AI-supported clearinghouse for cyber vulnerabilities, designed to aggregate and prioritise vulnerability disclosures using machine learning. The initiative aims to accelerate federal response times to emerging threats.
Defence 2 stories
Joint Advisory: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
CISA, ASD, NCSC, and international partners released a joint advisory (AA26-194A) outlining persistent malicious cyber activity by Russian state-sponsored actors targeting network devices including routers, firewalls, and VPN gateways. The advisory provides detection and mitigation guidance, emphasising the need for improved router hygiene and firmware updates.
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats
Kaspersky discovered a previously undocumented malware called GoSerpent used since late 2025 targeting government and diplomatic entities in Southeast Asia. The malware enables long-term access and intelligence gathering, with evolved tooling including a Stowaway RAT observed in May 2026.
Manufacturing 2 stories
Cyberattack on Japan's Largest Cold-Chain Operator Disrupts KFC and Supermarket Supplies
A cyberattack on Japan's largest cold-chain logistics operator disrupted KFC and supermarket supply chains across the country. The incident highlights the vulnerability of critical cold-chain infrastructure to operational disruption via cyber means.
Dairy Company Fairlife Suspends Production in US After Cyber Incident
Dairy company Fairlife suspended production at US facilities following a cyber incident. The disruption to a major dairy brand underscores the growing impact of cyber incidents on food manufacturing and supply chains.
Media & Entertainment 2 stories
Madison Square Garden Kept a List of Gay Celebrities
A Wired investigation revealed that Madison Square Garden compiled and maintained a list identifying gay celebrities who attended events at its venues. The story, covered in depth by Wired's security desk, raises significant privacy and data collection concerns about one of America's most prominent entertainment venues.
Hackers Claim to Leak Stolen Madison Square Garden Data
Following the Wired investigation, hackers claimed to have leaked stolen data from Madison Square Garden. The claimed breach adds a cyber dimension to the MSG privacy controversy, with potential exposure of additional sensitive patron information.
General / Cross-Sector 2 stories
Two Scattered Spider Hackers Sentenced to 5.5 Years for ยฃ29 Million TfL Hack
Owen Flowers, 18, and Thalha Jubair, 20, were sentenced to five and a half years each at Woolwich Crown Court for the 2024 Transport for London hack that left 148 systems inoperable and cost ยฃ29 million. They are believed to be the first hackers successfully prosecuted under Section 3ZA of the Computer Misuse Act 1990. Both pleaded guilty on the day their trial was due to start.
EU Commission Unveils Cybersecurity and AI Action Plan
On July 7, the European Commission presented an Action Plan on Cybersecurity and Artificial Intelligence aimed at supporting the safe use of AI while strengthening cyber resilience across the EU. The plan covers AI threat detection, cyber defence investment, and international cooperation frameworks.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |