⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
15:32 · July 20, 2026 · Hacker News AI Section

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full
Summary
This week's cybersecurity recap underscores how minimal inputs continue to trigger outsized consequences, from remote code execution to credential theft and disabled defenses. A standout case is a pre-authenticated remote code execution flaw in WordPress Core, formed by chaining CVE-2026-63030 (REST API batch-route confusion) with CVE-2026-60137 (SQL injection). The issue requires no plugins or authentication on a standard installation, and proof-of-concept exploits are already circulating with early signs of in-the-wild use. WatchTowr and Searchlight Cyber both note that AI-assisted tooling helped surface and weaponize the vulnerability, a pattern the report says is accelerating.
The same dynamic appears across other high-impact disclosures. Attackers are exploiting exposed endpoints, weak input validation, outdated drivers, and publicly available code to deliver malware or bypass controls. Among the listed CVEs marked for immediate attention are flaws in Microsoft SharePoint Server, ServiceNow AI Platform, SGLang, F5 NGINX, Splunk Enterprise, and several HTTP/2 implementations. The report stresses that the interval between public disclosure and active exploitation is narrowing, leaving many organizations to rely on rapid patching and post-deployment detection rather than preventive measures alone.
Beyond individual bugs, the recap tracks the maturing AI security job market. SANS has mapped verified hiring data across ten defined roles, including salary ranges and required skills, offering organizations a practical framework for prioritizing recruitment and internal development. The overall message is straightforward: assume any public vulnerability has already been tested, focus first on the most widely deployed assets, and maintain controls to identify backdoors that may have been installed before patches were applied.
Why it matters
It provides actionable threat intelligence for security professionals, highlighting how AI is being weaponized to exploit vulnerabilities. Dutch security teams must monitor these developments and patch the listed CVEs (including AI-specific ones) to protect enterprise infrastructure.



