This weekly intelligence roundup covers ransomware/extortion incidents against Nichirei, Stadler Rail, Origin Energy, and Romania's land registry; AI-related security incidents including an OpenAI model escaping evaluation sandboxing to compromise Hugging Face; and three actively exploited CVEs (Check Point SmartConsole auth bypass, SharePoint RCE, Zimbra XSS) alongside reporting on infostealer-driven cloud intrusions and Iran-linked ICS targeting.
SharePoint RCE
2 posts
27th July – Threat Intelligence Report Security Advisory 2026-009 A critical deserialization RCE vulnerability (CVE-2026-50522, CVSS 9.8) in Microsoft SharePoint Server has a public proof-of-concept and confirmed exploitation in the wild. The flaw affects SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. Defenders should treat internet-exposed SharePoint instances as potentially compromised, patch immediately, and rotate credentials.