ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-07-19
▶The Wire — Daily Briefing

The Wire — Sunday, July 19, 2026

When Exploitability Converges: The Week of No Friction

4 stories analyzed

When Exploitability Converges: The Week of No Friction

We're watching a dangerous convergence unfold in real time. This week has surfaced not one but two critical remote code execution vulnerabilities that require minimal technical effort to exploit, arriving at precisely the moment when sophisticated credential-stealing malware is surging across enterprise networks. The pattern is becoming clearer, and it should concern every security leader: attackers are building a toolkit where each piece makes the others more effective.

Start with the obvious problem. 7-Zip's critical RCE flaw carries a CVSS score of 9.8, and the exploitation method is about as friction-free as it gets. An attacker sends a malicious archive file. A user opens it. Code executes with the user's privileges. No authentication required. No social engineering required beyond the assumption that people use their archive tool when they receive an archive. This is the kind of vulnerability that security teams have nightmares about because the attack surface is so sprawling—any file transfer mechanism becomes a potential weapon.

The 7-Zip situation alone would be noteworthy. But it arrives alongside something potentially more dangerous: the public disclosure of working exploits for WordPress's "wp2shell" RCE chain. Here we have a pre-authentication vulnerability affecting 500 million sites. Let that sink in for a moment. No login required. No valid credentials. Just a web request. And unlike 7-Zip, which requires a user to actively trigger the vulnerability by opening a file, WordPress attacks can be automated at scale, systematically probing web servers for unpatched instances.

What connects these two incidents is their accessibility to attackers with minimal sophistication. These are not targeted exploits requiring deep knowledge of internals. They are spray-and-pray attacks that reward speed and scale. The organizations getting hit first are simply the ones without rapid patch deployment processes.

But here's where this week's threat picture becomes genuinely alarming. Microsoft's warning about surging ACR Stealer attacks isn't arriving in a vacuum. ACR Stealer is a credential-harvesting malware that combines social engineering with exploitation of legitimate Windows tools—tools already present on every Windows machine. It's not asking for much. It's asking for what's already there. And its value to an attacker multiplies substantially when paired with the ability to gain initial access through something like a malicious 7-Zip archive or an unpatched WordPress site.

Consider the attack chain that's becoming available to even moderately capable threat actors: Use a 7-Zip archive or WordPress vulnerability to establish initial access on a target system. Deploy ACR Stealer to harvest credentials, browser session tokens, and Microsoft 365 documents. Now you own both the machine and the credentials needed to move laterally through cloud infrastructure and collaborative platforms. The vulnerability gives you entry. The malware gives you persistence and credential access. The two together give you a complete compromise.

This convergence matters because it flattens the attack curve. Organizations that once felt they had time to patch after a vulnerability disclosure now find themselves in a race against automated exploit scanners. Organizations that invested in endpoint detection and response tools are discovering that legitimate Windows tools used by legitimate administrators look identical to those same tools being abused by ACR Stealer.

There's also a second-order problem in this week's news that's worth examining. The discussion around on-device age verification might seem tangential to critical vulnerabilities and malware, but it represents a regulatory and privacy shift that's creating new attack surfaces. Governments worldwide are mandating age verification systems. The technical implementation of those systems matters enormously. An on-device approach keeps biometric data local and private. A centralized approach creates massive honeypots of facial data that criminals and hostile actors would love to compromise. As these systems roll out globally, we should expect them to become targets. The cryptography securing local biometric data needs to be unbreakable, because the consequences of a breach—your face, your identity, tied to your age and location—are more severe than most other data breaches.

What security professionals should take from this week: vulnerability response timelines are shrinking, and they're shrinking because the tools for mass exploitation are commoditizing. The companies that will survive the next year intact are those treating patch management not as a compliance checkbox but as a security control equivalent to network segmentation. Second, credential theft and initial access vulnerabilities are increasingly complementary attacks. If your organization hasn't modeled attack chains where one feeds into the other, you're operating with a blind spot. Third, emerging regulatory requirements around privacy and data handling are creating new compliance burdens, but they're also creating new attack vectors. The security requirements and the privacy requirements need to be aligned, not siloed.

Looking ahead, we should watch for two things: whether WordPress sites actually patch en masse or whether we see ACR Stealer campaigns systematically targeting unpatched WordPress installations, and whether attackers begin creating malware variants specifically designed to exploit the new vulnerabilities in 7-Zip and WordPress. Exploit kits for critical vulnerabilities typically appear within weeks, not months. We're already in the window where organizations are racing to patch while attackers are racing to weaponize.

The Wire isn't here to spread alarm, but to be precise about risk. This week represents a moment where three separate threat vectors—exploitable vulnerabilities, credential-stealing malware, and expanding regulatory surface area—are aligning in ways that favor attackers. The organizations that will remain secure are those that recognize this moment not as a collection of isolated problems but as a strategic challenge requiring immediate, coordinated response.

Key Takeaways

  • Patch 7-Zip and WordPress immediately. These are not optional. Both carry public exploits and trivial user interaction requirements. Organizations should treat these equivalent to ransomware preparation—as true emergency-level vulnerabilities.
  • Credential theft is now the follow-on attack. ACR Stealer demonstrates that the goal is no longer just machine access but credential harvesting at scale. Assume any machine compromised through RCE will be used as a staging ground for credential theft.
  • Automated patch deployment is now table stakes. Manual patching cannot keep pace with exploit development cycles. Organizations without automated deployment pipelines are operating at unacceptable risk.
  • Regulatory requirements create attack surface. Age verification mandates, privacy regulations, and identity systems are becoming security targets. Technical implementation of compliance requirements should be reviewed as security decisions, not compliance afterthoughts.

The Wire is HackWire's daily editorial briefing, published every morning.