// daily digest ยท 2026-07-21
Tuesday·21 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

14 stories6 sectors4 sourcesGlobal focus

Executive Summary

A surge in WordPress exploitation dominates today's threat landscape as public exploit code for the critical wp2shell vulnerability chain (CVE-2026-63030 + CVE-2026-60137) fuels mass scanning and RCE attacks across organisations of every size. Separately, the JADEPUFFER operator expanded its AI-infrastructure targeting with a new Golang ransomware called ENCFORGE, designed to encrypt AI model weights and training datasets. Healthcare faces a wave of breach disclosures: a software provider serving 2,000+ US hospitals confirmed data theft, Abbott is investigating claims from two threat actors, and Centers Laboratory disclosed a breach affecting 542,000 individuals. On the legal/regulatory front, the DOJ seized over 1,000 domains illegally streaming World Cup matches, and Illinois became the third US state to enact comprehensive frontier AI safety legislation.

5
IT / Technology
5
Healthcare
1
Government
1
Media & Entertainment
1
Legal / Regulatory

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
5
Germany
1
Mexico
1
Romania
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 6

4 countries ยท 14 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 4/14 stories located directly from text (29%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 4/14 stories located directly from text (29%). Low-confidence (region-bucket only, check): United States.

IT / Technology 5 stories

1

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers are actively exploiting two chained critical WordPress vulnerabilities (CVE-2026-63030, CVE-2026-60137) โ€” codenamed wp2shell โ€” enabling unauthenticated remote code execution. Telemetry from KEVIntel shows 13 unique IP addresses from Switzerland, Germany, the UK, Indonesia, Lithuania, the Netherlands, and Singapore conducting mass scanning. Public exploit code was released early Saturday, with credential exfiltration and RCE following rapidly.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
2

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Sysdig researchers linked a second attack on the same Langflow server to the JADEPUFFER AI-agent-driven operator. The operator now deploys ENCFORGE, a compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files. Entry point remains CVE-2025-3248 (CVSS 9.8), in CISA's KEV catalog since May 2025.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
3

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Threat actors are actively exploiting CVE-2026-6875 (CVSS 9.5), a sandbox escape vulnerability in the ServiceNow AI Platform. Patches were released throughout June across multiple versions. ServiceNow is restricting the type of code that can run in sandbox contexts to enhance security.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
4

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Researchers at Island discovered nearly 7,600 malicious GitHub repositories โ€” over 800 posing as AI skills or MCP servers โ€” delivering SmartLoader malware. The campaign uses copied projects, lookalike developer profiles, and convincing READMEs. SmartLoader establishes persistence and delivers StealC info-stealer as a secondary payload.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-20
5

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

Rapid7 discovered an open delivery server containing 1,048 files of a malware operator's development toolkit โ€” lure templates, droppers, builder notes, and two campaign chains. One live campaign targeted Windows users in Mexico via a fake government ID-lookup site over WebDAV exploiting CVE-2025-33053. Evidence suggests generative AI was used to produce, test, and document the phishing delivery infrastructure.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-20

Healthcare 5 stories

1

Software Provider to More Than 2,000 US Hospitals Says Hackers Stole Employee and Customer Data

A software provider serving over 2,000 US hospitals confirmed that hackers stole employee and customer data in a cyber incident. The breach underscores the systemic risk of supply-chain attacks in the healthcare sector, where third-party vendor access to sensitive health information creates broad exposure.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-20
2

ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit

ApolloMD Business Services, a practice management provider, agreed to settle a data breach class action lawsuit for $4.02 million. The settlement covers claims related to a breach of protected health information.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-21
3

Abbott Investigating Cyberattack Claims From Two Threat Actors

Healthcare giant Abbott is investigating claims from two separate threat groups alleging cyberattacks and data theft, one involving legacy systems. The incident is ongoing with no confirmation of data exfiltration at this stage.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-20
4

Centers Laboratory Discloses Data Breach Affecting 542,000 Individuals

Centers Lab NJ LLC disclosed a data breach affecting approximately 542,000 individuals. The New Jersey-based diagnostic testing laboratory notified affected patients and regulators.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-20
5

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe over its 2023 data breach that exposed genetic and personal data of millions of users.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-20

Government 1 story

1

Romania Races to Restore Land Registry After Cyberattack Disrupts Property Market

Romania is working to restore its national land registry system after a cyberattack disrupted property transactions nationwide. The attack has created significant delays in real estate processing and legal uncertainty for property owners.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-21

Media & Entertainment 1 story

1

More Than 1,000 Domains Illegally Streaming World Cup Games Seized, DOJ Says

The US Department of Justice announced the seizure of over 1,000 domains used to illegally stream World Cup matches, in one of the largest anti-piracy operations coordinated with international law enforcement.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-21

General / Cross-Sector 1 story

1

Flock Safety Kills Acoustic System Designed to Detect 'Human Distress'

Flock Safety shut down its acoustic detection system following privacy and civil liberties concerns. The system was designed to detect sounds of 'human distress' but raised significant surveillance and ethical questions.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-21

Analytics

Sector distribution

IT / Technology
5
Healthcare
5
Government
1
Media & Entertainment
1
Legal / Regulatory
1
General / Cross-Sector
1

Source breakdown

The Hacker News
5
The Record from Recorded Future News
4
HIPAA Journal
4
Hunton Andrews Kurth Blog
1
14stories
IT / Technology 5
Healthcare 5
Government 1
Media & Entertainment 1
Legal / Regulatory 1
General / Cross-Sector 1

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified