STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 22 July 2026 · 24h windowRISKCRITICAL
StratQuad CTI Daily Brief, 22 July 2026
Compiled from 52 monitored sources · 1686 articles reviewed

Today’s Briefing

CVE-2026-63030 and CVE-2026-60137 form an exploited chain in WordPress Core that permits unauthenticated remote code execution on default installations, now tracked as wp2shell and added to CISA KEV today alongside CVE-2026-0770 in Langflow. CISA also published advisories for an authentication bypass in Siemens Opcenter X before V2604 and an impersonation vulnerability in Rockwell Automation FactoryTalk Services Platform 6.6, both affecting operational technology environments.

Top Stories

  1. CC-4815 - Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell)
  2. Siemens Opcenter X
  3. Rockwell Automation FactoryTalk Services Platform

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

Get the brief at 07:00, every weekday.

The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.

← All briefs