Cybersecurity Brief
Stealer malware surge and high-risk RCE patches urged
Today’s reporting clusters around credential and session theft plus multiple exploit-ready RCE paths and targeted infrastructure abuse. For cyber defense leaders, the immediate decision focus is patch prioritization for externally exposed software (WordPress Core and 7-Zip) and rapid containment/controls to reduce the blast radius from password/token theft campaigns (ACR Stealer). Separately, activity targeting ViPNet update mechanisms against Russian government-linked organizations underscores that even “private networking” ecosystems can be abused through trusted update flows.
Operationally, these signals point to a narrow window where attackers can monetize both initial access and post-compromise persistence: public exploits for WordPress “wp2shell,” an RCE fix in 7-Zip for malicious archive-driven code execution, and a reported spike in ACR Stealer stealing browser-stored secrets. Executives should ensure patch SLAs are enforced where exposure is highest, and that identity/session protections, endpoint monitoring, and credential hygiene are tightened for affected environments.
Top Signals
1. ACR Stealer attacks surge for token and password theft
Signal strength: Early
A reported increase in theft of browser-stored passwords and authentication tokens can rapidly convert compromise into account takeover and lateral movement. Organizations should treat this as an active escalation requiring stronger session controls, credential monitoring, and incident-ready detection.
Supporting evidence
- Microsoft warns of surge in ACR Stealer attacks on customers — BleepingComputer, 2026-07-18. The report describes a surge in ACR Stealer malware targeting enterprise customers to steal browser-stored passwords, authentication tokens, and documents—indicating momentum in credential theft techniques.
2. WordPress wp2shell RCE—public exploits make patch urgency
Signal strength: Early
Publicly available exploits for critical WordPress Core RCE (“wp2shell”) materially increase attacker capability and reduce time-to-exploitation. Executives should ensure high-velocity patching, validation, and compensating controls for internet-facing WordPress deployments.
Supporting evidence
- WordPress Core “wp2shell” RCE flaws get public exploits, patch now — BleepingComputer, 2026-07-18. The story states public exploits have been released for the critical wp2shell RCE vulnerabilities, explicitly prompting administrators to patch immediately—signal of exploitation readiness.
3. 7-Zip RCE patch for malicious archive delivery
Signal strength: Early
An RCE flaw fixed in 7-Zip that is exploitable via malicious archives creates a high-likelihood delivery route through common file sharing and phishing workflows. Leaders should prioritize updating 7-Zip and reducing risky archive handling pathways.
Supporting evidence
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives — BleepingComputer, 2026-07-18. The report describes a remote code execution vulnerability fixed in 7-Zip that attackers can trigger by convincing users to open specially crafted compressed files—indicating an actionable, widely relevant attack vector.
4. ViPNet update mechanism abuse targets Russian government-linked orgs
Signal strength: Early
Abusing a trusted product update mechanism indicates attackers can compromise environments through supply-chain-like pathways, increasing stealth and lowering barriers to execution. Security leadership should review update integrity controls and threat monitoring for ViPNet-adjacent deployments and related trust chains.
Supporting evidence
- Hackers abuse ViPNet software to target Russian govt agencies — BleepingComputer, 2026-07-19. The report claims an advanced threat actor is abusing the update mechanism for ViPNet software to target Russian organizations including government agencies—signaling targeted exploitation of trusted update workflows.
Sources
- Microsoft warns of surge in ACR Stealer attacks on customers — BleepingComputer
- WordPress Core “wp2shell” RCE flaws get public exploits, patch now — BleepingComputer
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives — BleepingComputer
- Hackers abuse ViPNet software to target Russian govt agencies — BleepingComputer