Newsletter 2026-07-21

Posted on Jul 21, 2026

Another week, another round. There’s been a lot of AI content again this time, though it does make up a large portion of the news.


Elastic has analyzed a rapidly spreading new Malware-as-a-Service campaign. Teleputz relies on the increasingly popular ClickFix scheme for initial compromise. Reverse engineering is slowed down through garbage instructions in the code, and so far only a handful of C2 domains have been observed.


Mindgard has published a vulnerability in Codex (as of 16.07. it is still unpatched after a seven-month disclosure timeline). Codex searches for a Git executable in multiple locations within a project. If that executable is malicious, the consequences are fairly obvious.


OWASP has released a threat modeling bot for LLMs.


Unit42 from Palo Alto presents a chain of three vulnerabilities enabling full compromise of ROX II OT switches, walking through each CVE individually.


Two new WordPress CVEs were recently published by AssetNote. Andy Gill walks through both vulnerabilities in his article and shows how they can be chained together. He also demonstrates an AI-assisted exploit development process.


Quentin Kaiser shows off his setup for AI-guided security testing of IoT devices.


Adam Kues from Searchlight Cyber shares the prompt he used to find/reproduce wp2Shell. There are likely a few points worth adapting for a solid base prompt.


In his blog, Kostas Koutroumpouchos shows which events show up in Event Viewer and how to determine what MDE has detected.


That’s all for this week, read you next week.