Confirmed exploitation of a pre-auth WordPress Core chain drives pressure this week; identity abuse and intrusion tempo hold at elevated levels.
WEEK OF JULY 27, 2026
ACTIVE EXPLOITATION↑
RISING
A pre-auth remote-code-execution chain in WordPress Core (wp2shell) is confirmed exploited in the wild, alongside three further KEV additions.
CONFIDENCE · HIGH
RATIONALE & SOURCE TYPES
CISA added the wp2shell pair (CVE-2026-63030, CVE-2026-60137) plus Langflow CVE-2026-0770 and DD-WRT CVE-2021-27137 to the KEV catalog on July 21 (anchor). WordPress shipped fixed versions 6.8.6 / 6.9.5 / 7.0.2 on July 17 and enabled forced automatic updates; public research reports honeypot-captured exploitation attempts. Confidence is high: three independent public source classes.
CISA KEVVENDOR ADVISORYPUBLIC RESEARCH
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
Credential-stuffing and OAuth device-code phishing activity continue at elevated levels without a verified step-change this week.
CONFIDENCE · MEDIUM
RATIONALE & SOURCE TYPES
Chick-fil-A disclosed on July 22 that credential-stuffing attacks compromised Chick-fil-A One loyalty accounts in June (campaign disclosure); vendor research documents an ongoing Kali365 phishing-as-a-service campaign hijacking Microsoft 365 sessions via OAuth device-code flows. Confidence is medium: activity is elevated but no verified step-change.
CAMPAIGN DISCLOSUREVENDOR RESEARCH
INTRUSION / RANSOMWARE TEMPO→
STEADY
High-impact ransomware disclosures continue, including a production-halting incident at a major consumer brand.
CONFIDENCE · MEDIUM
RATIONALE & SOURCE TYPES
Coca-Cola's SEC 8-K disclosed a ransomware event at its fairlife subsidiary that temporarily suspended US production; the responsible actor listed the victim publicly on July 20. Corroborated by credible incident reporting. Confidence is medium: disclosure lag limits week-level precision.
PUBLIC DISCLOSUREINCIDENT REPORTING
THREE MOVES THIS WEEK
01Update every WordPress instance to 6.8.6, 6.9.5, or 7.0.2 and verify the forced automatic update actually applied.
02Restrict or monitor OAuth device-code sign-in flows and rate-limit customer-facing logins against credential stuffing.
03Rehearse isolating production systems from IT compromise and validate offline backups.