Back to Blog
Weekly CISO Digest — Week of 2026-07-20: NGINX, SonicWall, and SaaS Exposures
security-guides

Weekly CISO Digest — Week of 2026-07-20: NGINX, SonicWall, and SaaS Exposures

breachwire TeamJul 20, 20264 min read

Headline Incident: Critical NGINX Vulnerability CVE-2026-42533 Allows Remote Code Execution and Denial of Service

A critical heap buffer overflow vulnerability (CVE-2026-42533) in NGINX was patched on July 15, 2026, impacting all versions from 0.9.6 through 1.31.2. This flaw allows remote, unauthenticated attackers to crash worker processes and potentially achieve remote code execution if ASLR is disabled or bypassed. Both F5 and NGINX deployments worldwide are affected, making this a high-impact risk for organizations relying on NGINX as a web server or reverse proxy. Exploitation could result in widespread denial of service or full system compromise, especially in environments with weak memory protections. Immediate patching is critical, and organizations should audit their deployments for exposure and review system hardening against memory attacks.

This Week's Incidents

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

What: UTA0533 exploited SonicWall SMA 1000 VPN zero-days (CVE-2026-15409, CVE-2026-15410) pre-disclosure to gain root, persistence, and deploy malware.
Who's at risk: All SonicWall SMA 1000 series VPN appliance users globally.
Action: Patch immediately, hunt for listed IOCs, and review VPN device logs for compromise.

2023 Salesforce Community Data Exposure Due to Misconfiguration

What: Over 150,000 Salesforce customer orgs, including banks and government, leaked sensitive data via misconfigured guest user profiles.
Who's at risk: Any organization using Salesforce Community sites with guest access.
Action: Audit and restrict guest user permissions; review API endpoint exposures.

WordPress wp2shell Core Vulnerability Allows Unauthenticated Remote Code Execution

What: WordPress core flaw (wp2shell) in versions 6.9.0–6.9.4 and 7.0.0–7.0.1 allowed unauthenticated RCE via REST API batch endpoint.
Who's at risk: All WordPress sites running affected core versions.
Action: Upgrade to WordPress 6.9.5 or 7.0.2 without delay.

Spirals ransomware attack on South Asian IT services company

What: New Spirals ransomware encrypted and stole data from a South Asian IT services firm in under 24 hours.
Who's at risk: Regional IT service providers and their downstream clients.
Action: Review ransomware response plans and monitor for rapid privilege escalation.

Ernst & Young Investigates Data Breach Involving Third-Party Support Tickets

What: EY is investigating a July 2026 breach involving third-party support tickets with possible sensitive data exposure.
Who's at risk: Organizations sharing sensitive data with third-party ticketing/support vendors.
Action: Assess third-party data flows and enforce least-privilege access.

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices with Malware

What: Russian APT UAC-0145 used fake ClickFix CAPTCHAs on Ukrainian sites to deliver PowerShell-based malware to Windows and Android devices.
Who's at risk: Organizations and users in Ukraine; any site using third-party CAPTCHA services.
Action: Block known malicious domains and educate users on phishing lures.

Daxin Malware Found Active on Multinational Manufacturer’s Network After 13 Years

What: China-linked Daxin rootkit and Stupig backdoor found on a Taiwan-based manufacturer’s network, undetected since 2013.
Who's at risk: High-tech manufacturers and organizations with legacy infrastructure.
Action: Conduct deep forensic reviews and network traffic analysis for stealthy persistence.

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

What: Seven npm packages targeting Vite ecosystem used blockchain-based C2 to deliver RATs, enabling credential theft and persistent access.
Who's at risk: Developers using Vite JavaScript tooling and npm packages (@uw010010/vite-tree, etc.).
Action: Audit npm dependencies for listed IOCs and block suspicious packages.

Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei

What: Nichirei suffered a cyberattack on July 13, 2026, disrupting refrigerated warehouse and shipping operations across Asia-Pacific.
Who's at risk: Food logistics, cold chain, and supply chain operators in the region.
Action: Review OT/IT segmentation and incident response for operational continuity.

GoSerpent Malware Targets Southeast Asian Governments for Espionage

What: GoSerpent malware, active since late 2025, targeted Southeast Asian government and diplomatic entities for credential theft and data exfiltration.
Who's at risk: Government agencies and diplomatic missions in Southeast Asia.
Action: Monitor for GoSerpent toolkits and enhance endpoint detection.

Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords

What: SharkNinja robot vacuums have an unpatched AWS IoT policy flaw allowing lateral device compromise and data exposure.
Who's at risk: Organizations and consumers using SharkNinja cloud-connected vacuums.
Action: Restrict device network access and monitor for unauthorized MQTT activity.

Global phishing campaign employs fake TTF files to deliver stealthy malware

What: Phishing campaign uses fake TTF files as Lua-based loaders to deliver RATs (Agent Tesla, Remcos, XWorm) via business-themed lures.
Who's at risk: Any organization receiving business/payment-themed emails with attachments.
Action: Block suspicious TTF files and update email security filters with latest IOCs.

Armenia Detains Russian Tourist on U.S. Warrant for REvil Ransomware Suspect

What: Armenia detained Aleksandr Ermakov at U.S. request, alleging REvil ransomware ties to the 2022 Medibank Private breach.
Who's at risk: Healthcare and critical infrastructure targeted by ransomware groups.
Action: Review ransomware TTPs and coordinate with law enforcement on threat actor tracking.

Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack

What: Coca-Cola paused Fairlife US production after ransomware compromised production systems; full impact still under investigation.
Who's at risk: Food and beverage manufacturers with interconnected production networks.
Action: Isolate production environments and validate backup/restoration procedures.

This Week's Pattern

  • Zero-day exploitation and critical vulnerabilities (NGINX CVE-2026-42533, SonicWall CVEs, WordPress core) are driving urgent patching cycles and increasing risk of mass compromise.
  • SaaS misconfigurations and supply chain attacks (Salesforce Community, npm Vite packages) continue to expose sensitive data and developer ecosystems at scale.
  • Ransomware and APT activity remain persistent across sectors, with rapid privilege escalation (Spirals), stealthy long-term intrusions (Daxin), and operational disruption (Coca-Cola, Nichirei) highlighting the need for layered defense and robust incident response.

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: