← The Desk 2026-07-21 The Wire
The Perimeter Site

Seoul Bike-Sharing Breach Impacts 4 Million Users While Qilin Exploits Palo Alto VPNs

Dana Kessler
2026-07-21
# Seoul Bike-Sharing Breach Impacts 4 Million Users While Qilin Exploits Palo Alto VPNs The 3am page is a Seoul bike-sharing service. 4 million users have their data exposed. The city is now talking about compensation. It is a reminder that municipal services are the softest targets on the wire. They have the data of every citizen but the security budget of a library. The tech sector is still the primary target. It ranks first of 15 sectors this week with 373 stories. Today alone, 107 data breaches hit the wire. That is the volume we are dealing with. The real noise is the WordPress `wp2shell` situation. We've seen the RCE warnings, but now the mass scanning has hit critical mass. A public exploit is fueling the fire. Vendor ratings usually inflate the urgency, but I've read the advisory. This one is legitimate. If you're running a standard installation without a hardened config, you aren't just vulnerable. You're likely already being scanned. The problem isn't the vulnerability. It's the dwell time. Attackers are using `wp2shell` to gain a foothold and then staying quiet. They aren't always defacing sites. They're turning these millions of installations into a proxy network for the next phase of the attack. Then we have the professionals. The Qilin ransomware gang is now exploiting a critical flaw in Palo Alto Networks VPN software. This isn't a script kiddie with a scanner. This is a targeted play. They find the VPN, they break the perimeter, and they encrypt the core before the SOC even sees a spike in traffic. This rhymes with the Ivanti and Fortinet campaigns from last year. The pattern is identical: find the one piece of hardware the admin trusts implicitly, exploit the edge, and move laterally. Where it differs is the speed. Qilin is moving from entry to impact in a fraction of the time it took the old APTs. They aren't interested in long-term espionage. They want the ransom. The AI hype is finally producing something useful for attackers. CVE-2026-6875 in the ServiceNow AI Platform is a sandbox escape. It allows unauthenticated remote code execution. The industry is obsessed with "AI attackers" and LLMs writing malware. That is a distraction. The real risk is the AI platform itself becoming the gateway. If an attacker escapes the sandbox in a tool like ServiceNow, they aren't just in the AI tool. They are in the orchestration layer of the entire enterprise. The second-order effect here is massive. Most companies have given their AI agents high-privilege access to automate tickets, provision users, and read databases. An attacker who hits the AI platform doesn't need to steal credentials. They just tell the AI agent to do the work for them. The AI becomes the ultimate inside man. I'm sceptical of the "AI security" labels being slapped on these flaws. It's not an AI problem. It's a memory management and sandbox isolation problem. It's the same old bugs in a new, expensive wrapper. The wire is also showing a lot of fallout from the Paidwork breach. 23 million users exposed. It's another case of a company scaling its user base faster than its security controls. We're seeing a trend where the "bridge" is the target. VPNs, AI platforms, and municipal portals. These are the points where trust is highest and verification is lowest. If you're managing a fleet of WordPress sites, stop looking at the dashboard and start looking at the logs for unauthorized shells. If you're running Palo Alto VPNs, assume the perimeter is porous until you've verified the patch level. The most uncomfortable question right now is how many "autonomous agents" are currently running with root access to your production environment. We've spent two years giving AI the keys to the kingdom. Now the locks are breaking. The Windows LegacyHive zero-day is another curiosity. We have unofficial patches circulating because the official channel is too slow. When the community is patching Windows before Microsoft does, the trust model is officially broken. The volume of today's incidents is high. 107 breaches is a lot of noise. But the signal is clear. The edge is failing. Whether it's a VPN in a corporate data center or a bike-share app in Seoul, the entry points are wide open. Watch the ServiceNow exploitation. If we see a wave of "automated" lateral movement across different tenants, it means the sandbox escape is being weaponized at scale. That would change the priority from "patch the AI tool" to "isolate the entire orchestration layer."
◼
← More from the Desk Live Wire →

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.