- ## Þjónustuöryggisafleiðsla Þjónustuöryggisafleiðlan er á íslenskum kerfisstjóra og öryggisstjóra (CISO). ## ⚠️ Þörf á augnablikarðri aðgerð
- *WordPress wp2shell Fyrirauðkenningarfjarkeyrsla (RCE)** Einn kritskur, óauðkenndur fjarkeyrsluveikleiki í WordPress grunnkerfi er í virkri nýtingu í heimskapinu. Þjónustuöryggisvörnir samanbúa vandann í REST API batch endpoint með SQL-innsetningu til að ná að óvæntum kóðanýtingu.
- *CVE:** CVE-2026-63030, CVE-2026-60137 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** WordPress 6.9.0-6.9.4, 7.0.0-7.0.1
- *Lagfært í:** WordPress 6.9.5, 7.0.2
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Tenable Research: wp2shell (CVE-2026-63030, CVE-2026-60137): Frequent questions](https://www.tenable.com/211032)
- 🏢 **SonicWall SMA1000 Núll-daga hagnýtingar** Fjölmargir kritskir núll-daga veikleikar í SonicWall Secure Mobile Access (SMA) 1000 seríu útgáfum eru í virkri nýtingu til að senda aðgreindan hugbúnað og gíslatökuhugbúnað, sem leyfir fjarkeyrslu kóða og auðkenningarframhjáhlaup.
- *CVE:** CVE-2026-15409, CVE-2026-15410 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Firmware 12.4.3-03245 og seinna (tilteknu útgáfurnar eru ekki fullt ályktuð)
- *Lagfært í:** Uppfærslur tiltæk — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237)
- *Kritskur NGINX biðminnisskrun** Einn kritskur biðminnisskrunveikleiki (CVE-2026-42945) í NGINX `ngx_http_rewrite_module` er í virkri nýtingu, sem leyfir óauðkenndum vörnir að skapa þjónustuneitun eða hægt að keyra fjarkeyrslu kóða.
- *CVE:** CVE-2026-42945 (CVSS: 8.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** NGINX Open Source 1.0.0 til 1.24.x
- *Lagfært í:** Uppfærslur tiltæk — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html)
- 🏢 **Fortinet FortiSandbox óauðkennd fjarkeyrsla (RCE)** Fjölmargir kritskir veikleikar í Fortinet FortiSandbox eru í virkri nýtingu, sem leyfir óauðkennd fjarkeyrslu kóða með sérstaklega samsettri HTTP beðum.
- *CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-26083, CVE-2026-44277 (CVSS: 9.8-9.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** FortiSandbox 4.4.0-4.4.8, 5.0.0-5.0.5, og eldri
- *Lagfært í:** Uppfærslur tiltæk — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Infosecurity Magazine: CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities](https://www.infosecurity-magazine.com/news/cisa-urgent-patch-fortinet/)
- *Auðkenningarframhjáhlaup og fjarkeyrsla (RCE) í Splunk Enterprise** Einn kritskur veikleikur (CVE-2026-20253) í Splunk Enterprise er í virkri nýtingu, sem leyfir óauðkennd fjarkeyrslu kóða og breytingu á gögnum.
- *CVE:** CVE-2026-20253 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Splunk Enterprise 10.x og 9.x fyrir nýjasta uppfærslur
- *Lagfært í:** Uppfærslur tiltæk — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286) ## 🔍 Þjónustuöryggisbrot
- *HollowGraph hugbúnaðarháttur:** Einn fyrirbæra spjallháttur nefndur **HollowGraph** notar öryggislega Microsoft 365 dagatalsháttar til að skapa skjóttu stjórn- og boðmiðlun (C2) hátt. Hugbúnaðurinn notar rétta Microsoft Graph API beði til að útflæða gögnum og fá leiðbeiningar, sem undirbýr vörnir á netþjónustu. Þetta sýnir mikilvægan breytingu í living-off-the-land (LOTL) aðferðum.
- *Tilfinningaráfall hjá Abbott Laboratories:** Abbott Laboratories er að skoða tvo mismunandi tilfinningaráfall sem tengjast óþýðu aðgangi til innri kerfis, þar á meðal Cancer Diagnostics deild og læknisbúnaðssystem. Áfallin tengjast hættugreinum, með möguleika á gagnaleik og gíslatökuáætlun. Þetta sýnir að hættugreinir halda áfram að ákveða heilsufyrirtæki.
- *Aðfangakeðjuháttur "Miasma":** Einn hættulegur aðfangakeðjuháttur, **Miasma**, er að skemmu npm pakka (t.d. `@automagik/genie`, `pgserve`) til að sækja auðkenni fyrir forritunarmenn, API lykla og gæði á kóða. Hugbúnaðurinn notar postinstall haka til að keyra og getur sjálfvirkilega spréttast með endurútgefinum pakka, sem býr til kritskan hættu fyrir forritunarmönn. ## 📋 Uppfærslur og uppfærslur
- *Microsoft SharePoint fjarkeyrsla (RCE):** Fjölmargir kritskir SharePoint veikleikar (t.d. CVE-2026-58644, CVE-2026-20963) eru í virkri nýtingu. Uppfærslur eru tiltæk fyrir útgáfur fyrir 16.0.19127.20442 og 16.0.19725.20210.
- *Adobe ColdFusion:** Adobe hefur uppfærð 55 kritskar veikleikar í 11 vörum, þar á meðal fjölmargar háviða veikleikar í ColdFusion (2023 og 2025) sem leyfir fjarkeyrslu kóða og réttindaaukning. Fjölmargir, eins og CVE-2026-48282, eru í virkri nýtingu.
- *Veeam Backup & Replication:** Kritskir fjarkeyrsluveikleikar sem áhrifast á Veeam Backup & Replication fyrir útgáfur fyrir 12.3.2.4854 og 13.0.2.29 eru birt. Uppfærslur eru tiltæk; þessi veikleikar leyfa auðkenndum notendum að keyra óvæntan kóða og auka réttindi.
- *Oracle E-Business Suite:** Einn kritskur veikleikur (CVE-2026-46817, CVSS 9.8-9.9) í Oracle E-Business Suite er í virkri nýtingu. Uppfærslur voru útgefnar í maí 2026 fyrir áhrifðar útgáfur (12.2.3 til 12.2.15). ## Þessar dagar árangur 1. **Uppfærðu WordPress augnablik:** Ef þú notar WordPress, skoðaðu útgáfurnar augnablik og skilríðu uppfærslur fyrir 6.9.5 eða 7.0.2 til að minnka áhrif á virkri nýtingu á `wp2shell` fjarkeyrslu (RCE) hátt. 2. **Skoðaðu SonicWall og Fortinet útgáfur:** Staðfestu uppfærslustöðu á öllum SonicWall SMA1000 og Fortinet FortiSandbox útgáfum. Þessar útgáfur eru í virkri nýtingu af gíslatökuhugbúnaði og öðrum hættugreinum. 3. **Uppfærðu NGINX og Splunk:** Þjónustuöryggisvörnir ættu að fyrst uppfæra NGINX vefþjón og Splunk Enterprise útgáfur vegna virkri nýtingar á kritskum veikleikum í báðum. 4. **Skoðaðu Microsoft 365 logga:** Skoðaðu Microsoft 365 aðgangslysingar fyrir óþýða dagatalsháttar aðgerðir, sérstaklega háttar sem eru dagskáðir langt í framtíð (t.d. 2050), sem er vísi á mögulega HollowGraph hugbúnaðarhátt. ## 🔗 Heimildir - [Tenable Research: wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions](https://www.tenable.com/211032) - [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237) - [The Hacker News: Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html) - [Infosecurity Magazine: CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities](https://www.infosecurity-magazine.com/news/cisa-urgent-patch-fortinet/) - [The Register Security: Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign](https://www.theregister.com/a/5274982)
## Executive Summary The threat landscape on July 20, 2026, is dominated by the active, widespread exploitation of critical vulnerabilities across foundational enterprise software and infrastructure. The most urgent threats are the newly weaponized **WordPress wp2shell** pre-authentication RCE chain and the ongoing exploitation of critical flaws in **NGINX** and **SonicWall SMA1000** appliances, the latter linked to ransomware deployment. Additionally, critical vulnerabilities in **Splunk Enterprise**, **Fortinet FortiSandbox**, and **Oracle E-Business Suite** are under active attack, requiring immediate patching. A novel malware campaign, **HollowGraph**, demonstrates a significant evolution in stealth by using Microsoft 365 calendars as a covert command-and-control channel.
## ⚠️ Immediate Action Required * **WordPress wp2shell Pre-Auth RCE Chain** A critical, unauthenticated Remote Code Execution vulnerability chain in WordPress core is being actively exploited in the wild. Attackers combine a REST API batch endpoint flaw with an SQL injection to achieve arbitrary code execution. * **CVE:** CVE-2026-63030, CVE-2026-60137 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** WordPress 6.9.0-6.9.4, 7.0.0-7.0.1 * **Fixed:** WordPress 6.9.5, 7.0.2 * **Workaround:** None mentioned in source * **Reference:** [Tenable Research: wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions](https://www.tenable.com/211032)
* 🏢 **SonicWall SMA1000 Zero-Day Exploits** Multiple critical zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances are being actively exploited to deliver custom malware and ransomware, allowing remote code execution and security bypass. * **CVE:** CVE-2026-15409, CVE-2026-15410 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Firmware 12.4.3-03245 and later (specific versions not fully enumerated) * **Fixed:** Patches available — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237)
* **Critical NGINX Heap Buffer Overflow** A critical heap buffer overflow vulnerability (CVE-2026-42945) in NGINX's `ngx_http_rewrite_module` is actively exploited, allowing unauthenticated attackers to cause a denial of service or potentially execute remote code. * **CVE:** CVE-2026-42945 (CVSS: 8.1) * **Status:** Active exploitation detected * **Vulnerable:** NGINX Open Source 1.0.0 through 1.24.x * **Fixed:** Patched versions available — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html)
* 🏢 **Fortinet FortiSandbox Unauthenticated RCE** Multiple critical vulnerabilities in Fortinet FortiSandbox are under active exploitation, allowing unauthenticated remote code execution via crafted HTTP requests. * **CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-26083, CVE-2026-44277 (CVSS: 9.8-9.1) * **Status:** Active exploitation detected * **Vulnerable:** FortiSandbox 4.4.0-4.4.8, 5.0.0-5.0.5, and earlier * **Fixed:** Patches available — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Infosecurity Magazine: CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities](https://www.infosecurity-magazine.com/news/cisa-urgent-patch-fortinet/)
* **Splunk Enterprise Authentication Bypass & RCE** A critical vulnerability (CVE-2026-20253) in Splunk Enterprise is being actively exploited, allowing unauthenticated remote code execution and data manipulation. * **CVE:** CVE-2026-20253 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Splunk Enterprise 10.x and 9.x prior to recent patches * **Fixed:** Patched versions available — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)
## 🔍 Threat Activity * **HollowGraph Malware Campaign:** A sophisticated espionage campaign dubbed **HollowGraph** is using encrypted Microsoft 365 calendar events as a stealthy command-and-control (C2) channel. The malware leverages legitimate Microsoft Graph API requests to exfiltrate data and receive instructions, evading traditional network-based detection. This represents a significant evolution in living-off-the-land (LOTL) techniques. * **Abbott Laboratories Cyber Incidents:** Abbott Laboratories is investigating two separate cyber incidents involving unauthorized access to internal systems, including its Cancer Diagnostics business and medical device systems. The incidents are linked to hacking groups, with potential data exposure and extortion claims. This highlights continued targeting of the healthcare sector. * **npm Supply Chain Attack "Miasma":** A persistent supply chain attack campaign, **Miasma**, is poisoning npm packages (e.g., `@automagik/genie`, `pgserve`) to steal developer credentials, API keys, and cryptocurrency data. The malware uses postinstall hooks to execute and can self-propagate via republished packages, posing a critical risk to software development pipelines.
## 📋 Patches & Updates * **Microsoft SharePoint RCE:** Multiple critical SharePoint vulnerabilities (e.g., CVE-2026-58644, CVE-2026-20963) have been actively exploited. Patches are available for versions prior to 16.0.19127.20442 and 16.0.19725.20210. * **Adobe ColdFusion:** Adobe has patched 55 critical vulnerabilities across 11 products, including multiple high-severity flaws in ColdFusion (2023 & 2025) allowing RCE and privilege escalation. Several, like CVE-2026-48282, were actively exploited. * **Veeam Backup & Replication:** Critical RCE vulnerabilities affecting Veeam Backup & Replication prior to versions 12.3.2.4854 and 13.0.2.29 have been disclosed. Patches are available; these flaws allow authenticated users to execute arbitrary code and escalate privileges. * **Oracle E-Business Suite:** A critical vulnerability (CVE-2026-46817, CVSS 9.8-9.9) in Oracle E-Business Suite is actively exploited. Patches were released in May 2026 for affected versions (12.2.3 through 12.2.15).
## Today's Priorities 1. **Patch WordPress Immediately:** If using WordPress, urgently verify versions and apply patches for 6.9.5 or 7.0.2 to mitigate the actively exploited `wp2shell` RCE chain. 2. **Review SonicWall & Fortinet Appliances:** Confirm the patch status of all SonicWall SMA1000 and Fortinet FortiSandbox appliances. These are under active attack by ransomware and other threat actors. 3. **Update NGINX & Splunk:** Prioritize patching NGINX web servers and Splunk Enterprise instances due to active exploitation of critical vulnerabilities in both. 4. **Monitor Microsoft 365 Logs:** Review Microsoft 365 audit logs for suspicious calendar event creation/modification, particularly events dated far in the future (e.g., 2050), as an indicator of potential HollowGraph malware activity.
## 🔗 References
- [Tenable Research: wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions](https://www.tenable.com/211032)
- [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237)
- [The Hacker News: Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution](https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html)
- [Infosecurity Magazine: CISA Mandates Urgent Patch for Actively Exploited Critical Fortinet Vulnerabilities](https://www.infosecurity-magazine.com/news/cisa-urgent-patch-fortinet/)
- [The Register Security: Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign](https://www.theregister.com/a/5274982)