~/greenteam/nerd

Sunday, July 19, 2026

Daily digest

cybersec BleepingComputer

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 patches a remote code execution vulnerability that can be triggered by opening a specially crafted compressed archive. No authentication or special privileges are required beyond convincing a user to open a malicious file.

Why it matters: 7-Zip is widely deployed on Windows endpoints as a default archive handler; if it's present on your Intune-managed fleet, push the update via Winget or a remediation script promptly — this is exactly the user-interaction RCE vector that NIST 800-171 SI-2 patch management controls are designed to close.

cybersec BleepingComputer

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Critical remote code execution vulnerabilities in WordPress Core, tracked as "wp2shell," now have public proof-of-concept exploits available, significantly raising the likelihood of in-the-wild exploitation. Administrators running any WordPress instance are urged to apply patches immediately.

cybersec BleepingComputer

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has issued a warning about a significant increase in ACR Stealer malware campaigns targeting enterprise customers. The infostealer harvests browser-stored credentials, authentication tokens, and sensitive documents from infected endpoints.

Why it matters: Browser-stored credentials and auth tokens are a direct path to your M365 GCC High tenancy — even with MFA, stolen session tokens can bypass it. Verify Intune endpoint detection policies are tuned to flag infostealer behavior, and confirm Conditional Access requires compliant device state for GCC High access.