Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A surge in WordPress exploitation dominates today's threat landscape as public exploit code for the critical wp2shell vulnerability chain (CVE-2026-63030 + CVE-2026-60137) fuels mass scanning and RCE attacks across organisations of every size. Separately, the JADEPUFFER operator expanded its AI-infrastructure targeting with a new Golang ransomware called ENCFORGE, designed to encrypt AI model weights and training datasets. Healthcare faces a wave of breach disclosures: a software provider serving 2,000+ US hospitals confirmed data theft, Abbott is investigating claims from two threat actors, and Centers Laboratory disclosed a breach affecting 542,000 individuals. On the legal/regulatory front, the DOJ seized over 1,000 domains illegally streaming World Cup matches, and Illinois became the third US state to enact comprehensive frontier AI safety legislation.
Incident Map
IT / Technology 5 stories
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are actively exploiting two chained critical WordPress vulnerabilities (CVE-2026-63030, CVE-2026-60137) โ codenamed wp2shell โ enabling unauthenticated remote code execution. Telemetry from KEVIntel shows 13 unique IP addresses from Switzerland, Germany, the UK, Indonesia, Lithuania, the Netherlands, and Singapore conducting mass scanning. Public exploit code was released early Saturday, with credential exfiltration and RCE following rapidly.
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Sysdig researchers linked a second attack on the same Langflow server to the JADEPUFFER AI-agent-driven operator. The operator now deploys ENCFORGE, a compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files. Entry point remains CVE-2025-3248 (CVSS 9.8), in CISA's KEV catalog since May 2025.
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Threat actors are actively exploiting CVE-2026-6875 (CVSS 9.5), a sandbox escape vulnerability in the ServiceNow AI Platform. Patches were released throughout June across multiple versions. ServiceNow is restricting the type of code that can run in sandbox contexts to enhance security.
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Researchers at Island discovered nearly 7,600 malicious GitHub repositories โ over 800 posing as AI skills or MCP servers โ delivering SmartLoader malware. The campaign uses copied projects, lookalike developer profiles, and convincing READMEs. SmartLoader establishes persistence and delivers StealC info-stealer as a secondary payload.
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Rapid7 discovered an open delivery server containing 1,048 files of a malware operator's development toolkit โ lure templates, droppers, builder notes, and two campaign chains. One live campaign targeted Windows users in Mexico via a fake government ID-lookup site over WebDAV exploiting CVE-2025-33053. Evidence suggests generative AI was used to produce, test, and document the phishing delivery infrastructure.
Healthcare 5 stories
Software Provider to More Than 2,000 US Hospitals Says Hackers Stole Employee and Customer Data
A software provider serving over 2,000 US hospitals confirmed that hackers stole employee and customer data in a cyber incident. The breach underscores the systemic risk of supply-chain attacks in the healthcare sector, where third-party vendor access to sensitive health information creates broad exposure.
ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit
ApolloMD Business Services, a practice management provider, agreed to settle a data breach class action lawsuit for $4.02 million. The settlement covers claims related to a breach of protected health information.
Abbott Investigating Cyberattack Claims From Two Threat Actors
Healthcare giant Abbott is investigating claims from two separate threat groups alleging cyberattacks and data theft, one involving legacy systems. The incident is ongoing with no confirmation of data exfiltration at this stage.
Centers Laboratory Discloses Data Breach Affecting 542,000 Individuals
Centers Lab NJ LLC disclosed a data breach affecting approximately 542,000 individuals. The New Jersey-based diagnostic testing laboratory notified affected patients and regulators.
23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit
A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe over its 2023 data breach that exposed genetic and personal data of millions of users.
Government 1 story
Romania Races to Restore Land Registry After Cyberattack Disrupts Property Market
Romania is working to restore its national land registry system after a cyberattack disrupted property transactions nationwide. The attack has created significant delays in real estate processing and legal uncertainty for property owners.
Media & Entertainment 1 story
More Than 1,000 Domains Illegally Streaming World Cup Games Seized, DOJ Says
The US Department of Justice announced the seizure of over 1,000 domains used to illegally stream World Cup matches, in one of the largest anti-piracy operations coordinated with international law enforcement.
Legal / Regulatory 1 story
Illinois Governor Signs Frontier AI Model Law
Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act (SB 315) into law, making Illinois the third US state to enact comprehensive safety and transparency requirements for developers of advanced AI systems.
General / Cross-Sector 1 story
Flock Safety Kills Acoustic System Designed to Detect 'Human Distress'
Flock Safety shut down its acoustic detection system following privacy and civil liberties concerns. The system was designed to detect sounds of 'human distress' but raised significant surveillance and ethical questions.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |