
🛡️ DAILY SECURITY INTELLIGENCE BRIEFING
Published Monday, July 20, 2026 at 09:00 AM PT 20 JUL 2026 BLUF: WordPress pre-authentication RCE (wp2shell, CVE-2026-63030/60137) actively exploited; Hugging Face breach via autonomous AI agent; Russian IP camera compromise targeting NATO logistics; critical water infrastructure cybersecurity expansion underway. CYBER • WordPress Core RCE Chain (wp2shell) — Two chained vulnerabilities (CVE-2026-63030, CVE-2026-60137) enable pre-authentication remote code execution in recent WordPress versions. Unauthenticated attackers can achieve RCE without credentials. [Tenable, CSO Online] [HIGH CONFIDENCE]. Immediate patching required for any WordPress installations in production; REST API endpoints particularly exposed. ...








