July 20, 2026 by sig9

Hacker Wars - July 20, 2026

bulletin-feature-image

Your daily dose of infosec chaos


AI systems are now hacking each other, critical infrastructure software is getting hammered with zero-days, and WordPress sites are about to have a very bad week. If you thought the robots were coming for your job, turns out they’re coming for your servers first.

Hugging Face Gets Breached By An Autonomous AI Agent

In what might be the most ironic hack of the year, Hugging Face - the world’s largest AI model repository - was breached by an autonomous AI agent system targeting its production infrastructure. The attackers used AI to hack the AI platform, which is either a sign of the apocalypse or just really good marketing for their security consulting services.

What to do: Audit your Hugging Face integrations and rotate any API keys or tokens that had access to their platform.


Critical NGINX Heap Overflow Lets Remote Attackers Crash or RCE Workers

F5 patched a critical heap buffer overflow in NGINX (CVE-2026-42533) that lets unauthenticated remote attackers crash worker processes or potentially achieve code execution with crafted HTTP requests. The flaw affects NGINX 1.30.4 and 1.31.3, and if you’re running an older version, you’re basically leaving your front door wide open with a neon “hack me” sign.

What to do: Update to NGINX 1.30.4 (stable) or 1.31.3 (mainline) immediately, or NGINX Plus 37.0.3.1 if you’re paying for it.


SonicWall SMA Zero-Days Exploited In The Wild Before Disclosure

A previously unknown threat actor has been exploiting zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances since late June, gaining root access before the flaws were even publicly disclosed. Volexity is tracking the activity, which is a reminder that your VPN might be the weakest link in your security chain.

What to do: Check your SonicWall SMA appliances for indicators of compromise and apply patches as soon as they’re available.


WordPress Core WP2Shell RCE Flaws Now Have Public Exploits

The critical “wp2shell” remote code execution vulnerabilities in WordPress Core now have public exploits available, which means every script kiddie and their grandmother will be scanning for vulnerable sites. If you’re running WordPress and haven’t patched yet, congratulations - you’re about to become a case study in why patching matters.

What to do: Update WordPress immediately if you haven’t already, and scan your sites for signs of compromise.


SleeperGem Supply Chain Attack Hits Ruby Ecosystem With Malicious Gems

A new supply chain attack codenamed SleeperGem has been discovered targeting the Ruby ecosystem through three malicious gems published to RubyGems. The rogue packages were designed to serve additional payloads to developer machines, because apparently we haven’t learned our lesson about trusting random code from strangers on the internet.

What to do: Audit your Gemfile.lock for the compromised gems (git_credential_manager and related packages) and remove them immediately.


Catch you tomorrow. In the meantime, go check your attack surface.


Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown

This bulletin is provided for informational purposes. Contact us for tailored security analysis.