ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-07-17
▶The Wire — Daily Briefing

The Wire — Friday, July 17, 2026

The Perfect Storm: Legacy Cliffs, Zero-Days in the Wild, and AI Breaking the Rules

45 stories analyzed

The Perfect Storm: Legacy Cliffs, Zero-Days in the Wild, and AI Breaking the Rules

The threat landscape just shifted. We're watching four simultaneous crises converge in ways our security playbooks weren't built to handle: mission-critical systems running out of support deadlines within ninety days, industrial infrastructure under sustained ransomware assault, artificial intelligence systems escaping traditional security controls, and coordinated exploitation of zero-days across the entire stack—all happening right now.

Today's story count tells the story. We're tracking at least seven critical vulnerabilities under active exploitation, two major infrastructure attacks, three distinct malware frameworks targeting enterprises, and two separate operating system support deadlines looming this October. The thread connecting them isn't just severity—it's that each represents a fundamental failure of legacy defense assumptions. The defenses we built for last decade's threats don't detect or stop what's happening today.

Start with the patch avalanche. SharePoint's critical RCE didn't sit in disclosure purgatory—it went from announced to actively exploited within seventy-two hours. That's not a surprise anymore; it's the baseline. Fortinet's unauthenticated RCE and auth bypass in FortiGate firewalls is being weaponized against enterprise perimeters right now. Oracle's critical EBS flaw is so trivial to exploit—minimal technical effort, HTTP-only—that CISA just gave federal agencies forty-eight hours to patch. Zoom's account takeover vulnerability requires no user interaction at all. F5's NGINX heap overflow enables RCE on non-ASLR systems. And lurking beneath it all, legacy UEFI shims signed by Microsoft years ago can still bypass Secure Boot entirely, letting attackers inject code at firmware level before any operating system protection activates.

Most organizations won't patch all of these in time. That's not pessimism—it's mathematics applied to enterprise scale.

But the patch tidal wave is almost secondary to what's happening in operational technology and critical infrastructure. Nichirei, Japan's largest frozen food producer, got hit and had to take systems offline nationwide. Coca-Cola's Fairlife dairy unit got ransomware-encrypted and halted US milk production. These aren't theoretical incidents—they're real supply chain disruption affecting millions of people. Then look at Anubis ransomware, which doesn't just encrypt your data and hold it ransom—it permanently wipes files too, converting ransomware from a negotiation problem into irreversible data loss. That changes the game for attackers. Encryption was always recoverable if you had backups or refused to pay. Permanent destruction on an industrial scale? That's psychological warfare. And it's working on healthcare and critical infrastructure operators who face the choice between losing everything or paying everything.

Then there's Spirals, the Rust-based ransomware that breached a South Asian IT firm and encrypted the entire network in under twenty-four hours after systematically disabling antivirus, Veeam, VMware, and twenty-three other critical services. Fast. Precise. Practiced. This isn't script-kiddie ransomware—this is industrial-grade infrastructure takeover.

Industrial control systems themselves are under direct attack. Rockwell Automation's communication modules contain a critical DoS flaw allowing unauthenticated network attackers to disrupt connections repeatedly. Their PLC controllers have three critical DoS vulnerabilities triggered by malicious files. Siemens SICAM 8 has four critical flaws enabling authentication bypass and firmware compromise on power grids and manufacturing worldwide. These are the systems controlling electricity, manufacturing, and infrastructure. They were designed decades ago without security in mind, and as one piece today noted, restarting them to patch is often more dangerous than leaving them vulnerable. You can't security-theater your way out of that contradiction.

Now layer in artificial intelligence, and traditional security frameworks collapse entirely. Agentic AI systems are untamable by design—they operate at machine velocity making autonomous decisions that existing threat detection can't predict or control. Agent data injection corrupts the trusted data fed to AI agents rather than hijacking their instructions, letting attackers redirect shopping agents, trick coding assistants, and inject malicious code into production while evading modern defenses. A critical vulnerability in Claude for Chrome lets malicious extensions hijack AI operations and access Gmail, Drive, Calendar, and Salesforce without any user interaction. Meanwhile, over one million phishing emails now use text salting to confuse AI security filters, and attackers are using LLMs to generate retail scams at scale. The one bright spot here is OpenAI's GPT-Red—an autonomous red-team system that reduced prompt injection vulnerabilities sixfold in GPT-5.6 Sol by automating vulnerability discovery. At least someone's building defenses as fast as new attack surfaces emerge.

On the endpoint front, the threats are getting more sophisticated and more aggressive. ClickLock, a new macOS stealer, doesn't politely ask for your password—it crashes applications every two hundred and ten milliseconds until you surrender it. TELEPUZ spreads via ClickFix lures on compromised websites, stealing data and executing commands. OkoBot deploys twenty-plus payloads to steal crypto keys and financial credentials. Russian threat actors are trojanizing Webex and Zoom installers to deploy Starland RAT across the US, Europe, and Latin America.

Then comes the calendar cliff. Windows Server 2022 mainstream support ends October 13. Windows 11 24H2 Home and Pro editions lose support on the same date. Ninety days. Millions of devices will stop receiving patches, becoming targets for every unpatched exploit, ransomware variant, and credential theft campaign in circulation. Organizations haven't finished planning Windows Server 2025 upgrades yet. This isn't coming—it's here.

There are some wins worth noting. Two Scattered Spider members got five and a half years for orchestrating the Transport for London attack that compromised critical infrastructure and affected nine million commuters. 23andMe paid eighteen million dollars settling with forty-three states over a credential-stuffing breach. Spanish police disrupted a €140 million cyber fraud ring spanning multiple European countries. And on the vendor side, Risk Ledger raised thirty-two million in Series B to expand supply chain risk assessment, while Oak emerged from stealth with sixty million to consolidate fractured identity governance across human, machine, and AI identities. The defense ecosystem is accelerating too.

But acceleration isn't enough if it's still building for last decade's threat model. We need fundamentally different thinking about industrial systems that can't safely restart, about AI systems that operate at machine speed, about the fact that legacy support cliffs and zero-day exploitation timelines are now synchronized. Watch what happens in October. Watch whether organizations actually complete those OS upgrades before support ends. Watch whether the next Spirals variant learns from this one and goes faster. The question isn't whether the security industry is moving fast enough—it's whether it's moving differently enough.

Key Takeaways

The Wire is HackWire's daily editorial briefing, published every morning.