Bharat Threat FeedGlobal threats, decoded for Indian defenders
Weekly Brief · 26 July 2026

Weekly Brief — 26 July 2026

A Check Point SmartConsole authentication bypass and a fourth actively exploited SharePoint flaw give defenders two urgent management-plane patches this week, while a chainable WordPress Core exploit puts unauthenticated remote code execution within reach of anyone running a default install. A ransomware crew has claimed a Hyderabad pharma contractor, extending a pattern of contractor and supply-chain breaches reported in India in recent months, and a China-linked espionage operation shows commercial coding agents now running live intrusions rather than assisting them from the sidelines.
1CriticalCVSS 9.1

Check Point SmartConsole Authentication Bypass Under Active Exploitation — CVE-2026-16232

CVSS 9.1 (CISA); Check Point's own advisory rates it 9.3 | CISA KEV, 22 July — remediation due 25 July* Check Point disclosed CVE-2026-16232 on 22 July 2026, a critical authentication-bypass flaw in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management (MDS), versions R77.30 through R80-R82.10. An unauthenticated attacker can obtain an application login token and use it to log in to SmartConsole with full administrative privileges, provided the management server is internet-reachable and Trusted Clients restrictions are not configured. Check Point confirmed a limited number of customers were targeted in the wild and published six attacker IP addresses as indicators of compromise. CISA added the flaw to its Known Exploited Vulnerabilities catalogue the same day, with a federal remediation deadline of 25 July.

India exposureCheck Point holds GeM-registered, government-approved vendor status and is deployed across central and state government bodies, PSUs, defence, railways, police departments and banks. A compromised management console gives an attacker the ability to rewrite security policy across every firewall it controls.
ActionInstall the 22 July Jumbo hotfix immediately. Restrict SmartConsole Trusted Clients to approved administrative IP ranges, remove any direct internet exposure of the management server, and check logs against Check Point's published attacker IP list.
SourceCheck Point advisory sk185169, 22 July 2026; CISA KEV, 22 July 2026; Security Affairs, 23 July 2026; The Hacker News, 23 July 2026.
2CriticalCVSS 9.8

Fourth SharePoint Flaw in a Month Moves to Active Exploitation — CVE-2026-50522

CVSS 9.8 | CISA KEV, 22 July — remediation due 25 July | Update to last week's SharePoint coverage* A second, distinct on-premises SharePoint vulnerability from the same 14-15 July Patch Tuesday batch has now moved to active exploitation. CVE-2026-50522 is a deserialization-of-untrusted-data flaw in SharePoint 2016, 2019 and Subscription Edition; a public proof-of-concept released around 21 July led to compromise within hours, according to watchTowr's honeypot network. Attackers are using the access to extract SharePoint machine keys for persistence, meaning patching alone does not remove an attacker who already got in. SecurityWeek's 22 July count names it as the fourth SharePoint CVE exploited in this wave, alongside CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644.

India exposureThe same on-premises SharePoint installed base flagged in last week's brief — government ministries, public-sector banks and large enterprises — is exposed here too. Organisations that patched only last week's SharePoint/AD FS zero-days remain vulnerable to this separate flaw, and any farm compromised via the earlier CVEs needs machine-key rotation, not just a patch.
ActionApply the July cumulative update if not already done, rotate SharePoint machine keys and any credentials that traversed the server, hunt for web shells and abnormal Site Owner activity, and treat internet-facing farms as potentially already compromised rather than merely at risk.
SourceSecurityWeek, 22 July 2026; Security Affairs, 21 July 2026; CISA KEV, 22 July 2026; The Hacker News, 22-23 July 2026.
3

WordPress Core "wp2shell" Chain Enables Unauthenticated RCE on Default Installs — CVE-2026-63030 / CVE-2026-60137

No vulnerable plugin required | CISA KEV, 21 July — remediation due 4 August* Two WordPress Core flaws disclosed 17 July 2026 chain into fully unauthenticated remote code execution against a default installation. CVE-2026-63030 is a REST API batch-route confusion bug that bypasses authentication; CVE-2026-60137 is a SQL injection through the unsanitised author__not_in parameter in WP_Query. Affected versions are WordPress Core 6.8.x, 6.9.x and 7.0.x before 6.8.6, 6.9.5 and 7.0.2 respectively. WordPress.org pushed forced automatic updates, but public proof-of-concept code triggered mass scanning within days: honeypots logged tens of thousands of exploitation attempts, more than 100 rogue administrator accounts created, and confirmed database and credential exfiltration. Full weaponisation is easiest where object caching is off and plugin/theme paths remain writable, though the underlying flaw sits in core, not a plugin.

India exposureWordPress runs a large share of Indian government micro-sites, PSU informational portals, educational institution websites and SMB storefronts. Because the entry point is a core authentication bypass, sites do not need a misconfigured plugin to be at risk.
ActionConfirm forced auto-updates actually completed rather than assuming they did; manually upgrade any site still on an affected version; audit administrator accounts for unrecognised entries; rotate database credentials; and check uploads and themes for web shells.
SourceWordPress.org security release notes, 17 July 2026; CISA KEV, 21 July 2026; The Hacker News, 21 and 24 July 2026.
4

Krybit Ransomware Group Claims Hyderabad Pharma CRDMO LAXAI Life Sciences

No CVE | Threat-actor claim, not independently confirmed* Krybit, a double-extortion ransomware-as-a-service operation active since roughly April 2026, posted a claim on 23 July 2026 that it had compromised LAXAI Life Sciences Pvt Ltd, a Hyderabad-headquartered contract research, development and manufacturing organisation serving pharmaceutical and biotech clients. The group's Tor leak site threatens to publish exfiltrated data unless LAXAI opens negotiations. Neither LAXAI nor CERT-In has issued a statement confirming the breach at time of writing; this item rests on the group's own claim as tracked by ransomware-monitoring services, not on independent confirmation.

India exposureThis is a direct claim against an India-headquartered company. CRDMOs hold drug-discovery, formulation and client research data on behalf of global pharma partners, a contractor-adjacent target class that keeps appearing in India incident reporting this year.
ActionLife-sciences contract manufacturers and research organisations should review third-party and vendor access to research systems, verify backup isolation from production networks, confirm EDR coverage extends to manufacturing and lab environments, and have a breach-notification decision process ready under CERT-In's reporting timelines regardless of whether this specific claim is substantiated.
SourceDeXpose breach-tracking report, 24 July 2026; Ransomware.live victim listing, 23 July 2026.
5

China-Linked Actor Runs Claude Code and DeepSeek as Live Intrusion Tooling

No CVE | Nation-state espionage — AI-agent tradecraft* Hunt.io researchers, in a report published 14 July 2026, found a suspected China-linked operator running Anthropic's Claude Code (version 2.1.165) and DeepSeek-v4-pro as working components inside active intrusions rather than as background assistance. Claude Code executed bash commands, managed persistent and parallel agent sessions, and built phishing infrastructure; DeepSeek-v4-pro handled attack-technique selection, reworked exploits after failed attempts, and generated scripts. Confirmed activity, dated 8-12 June 2026, hit a citizen-complaint government portal in Afghanistan, a Thai government administrative system via SQL injection, and Taiwanese semiconductor, telecom and chemical supply-chain targets, alongside reconnaissance against US government portals and parallel probing of financial-services and payment platforms across Europe, Australia and Asia. Thirteen Hong Kong-hosted servers supported the operation; one was left with an open directory of over 2,400 files including phishing kits, exploit scripts and operator notes in Simplified Chinese.

India exposureNo named source lists an Indian victim in this campaign, and none is implied here. What it documents is relevant to Indian government and BFSI defenders regardless: coding agents integrated directly into intrusion execution shorten the time an operator needs to adapt exploits and stand up phishing infrastructure, and that tooling pattern is now demonstrated in the field by a state-linked actor rather than theorised.
ActionGovernment and BFSI security teams should treat AI-agent-accelerated adaptation as a planning assumption, shorten patch and credential-rotation windows accordingly, tighten monitoring on citizen-facing portals and payment platforms, and extend phishing-infrastructure takedown processes to cover AI-generated cloned login pages, which are harder to distinguish visually from the originals.
SourceHunt.io research report, 14 July 2026; Security Affairs, 14-16 July 2026; GBHackers, 15-16 July 2026.

Takeaway

This week's vendor sweep checked Fortinet, Cisco, Palo Alto Networks, Check Point, Juniper, SonicWall, Sophos, Barracuda, WatchGuard, Zscaler, Citrix NetScaler, Ivanti, F5 BIG-IP, Versa, VMware VeloCloud, Aruba/HPE EdgeConnect and Seqrite/Quick Heal by name; only Check Point produced a fresh critical item this week. The throughline across this edition is management-plane and platform exposure rather than novel exploitation technique: a firewall console, a collaboration server and a content-management system all became full-compromise paths once an attacker could reach an authentication or deserialization weakness from the internet. The LAXAI claim keeps the contractor-breach pattern from recent editions active in a new sector, and the Hunt.io findings are a reminder that the gap between a well-resourced state actor's tooling and a routine criminal crew's is narrowing faster than most defensive playbooks assume.

Nirad Threat Research