This reporting period witnessed an exceptional surge in vulnerability disclosures, with Microsoft releasing patches for a record-breaking 570 security flaws—nearly triple their previous record. Three zero-day vulnerabilities are actively exploited in the wild, including critical SonicWall SMA1000 flaws (CVE-2026-15409, CVE-2026-15410) and a Progress ShareFile Storage Zone Controller vulnerability. The threat landscape shows sophisticated adversary tradecraft with the ShinyHunters threat actor conducting OAuth abuse campaigns targeting SaaS applications, while law enforcement disrupted a €140 million Spanish cyber fraud ring and unsealed indictments against Russian bulletproof hosting operators. The ransomware ecosystem remains highly active with 18 new victim organizations across multiple sectors including automotive, hospitality, healthcare data, and critical infrastructure. Nearly 300 malicious GitHub repositories were discovered distributing infostealer malware disguised as legitimate software, demonstrating supply chain attack evolution.
The period also revealed significant software supply chain risks with critical vulnerabilities in widely-deployed components including Ruby JWT (CVE-2026-45363, CVSS 9.1) enabling authentication bypass, and decompress package for Node.js (CVE-2026-53486, CVSS 9.1) allowing arbitrary file operations. Multiple AI/ML development tools showed concerning security gaps, including the Cursor IDE auto-executing malicious code from poisoned repositories and xAI's Grok Build CLI tool leaking users' confidential code to unauthorized servers. Threat actors continue exploiting trusted platforms for credential theft, with new Jalisco and OmegaLord phishing kits defeating MFA protections on Microsoft 365 accounts, and ClearFake campaigns leveraging social engineering through FaceTime to drain bank accounts.
Microsoft released a record 570 patches including 3 zero-days; critical flaws in SonicWall, Progress ShareFile, and SAP products actively exploited or requiring immediate attention
Microsoft released security updates for 570 vulnerabilities, nearly triple the previous record. Three zero-day vulnerabilities are included: two exploited in attacks and one publicly disclosed. This represents an unprecedented volume requiring immediate security team triage and prioritization.
SonicWall warns that CVE-2026-15409 and CVE-2026-15410 are being actively exploited in zero-day attacks against SMA1000 appliances. Security updates have been released and immediate patching is urged for all customers with exposed appliances.
SAP addressed 16 vulnerabilities in July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter requiring immediate attention from SAP enterprise customers.
Critical vulnerability in ruby-jwt allows JWT.decode to accept attacker-forged tokens when using an empty key with HMAC algorithms. OpenSSL returns valid digest under empty key, enabling complete authentication bypass. CVSS 9.1.
Critical path traversal in decompress package allows arbitrary file read/write outside target directory via crafted hardlink and symlink entries in archives. Affects Node.js applications using this widely-deployed extraction library. CVSS 9.1.
Multiple out-of-bounds write and input validation flaws in Illustrator (CVE-2026-48334 CVSS 9.3, CVE-2026-48335/36/37) enable arbitrary code execution via malicious files with scope change, affecting Adobe Creative Cloud users.
Progress Software confirmed a high-severity zero-day vulnerability caused the emergency shutdown of ShareFile Storage Zone Controllers. Security updates are now available to patch the actively exploited flaw affecting enterprise file sharing infrastructure.
Automated Frequency Coordination systems for 6 GHz Wi-Fi trust client-side data by default, enabling location spoofing and attacks that could disrupt critical infrastructure wireless communications and traffic management systems.
Nearly 300 fake GitHub repositories distribute infostealers; Mirai and Mozi botnet activity persists; ClearFake and ClickFix campaigns evolve with new social engineering tactics
Threat actors published hundreds of fake GitHub repositories posing as legitimate software and security projects to distribute infostealer malware. This supply chain attack vector targets developers and security professionals seeking trusted tools.
Multiple Mirai botnet payloads detected across various architectures (ARM, MIPS, x86_64, aarch64) hosted on gravy.rapidbranchzi.com, organza.rapidbranchzi.com, wreath.rapidbranchzi.com, and zipper.rapidbranchzi.com domains, indicating active IoT device compromise campaigns.
ClearFake campaigns delivering platform-specific payloads (Windows and macOS) through compromised domains using social engineering to trick users into downloading malware disguised as browser updates or security alerts.
ClickFix attack vector now available as a service, evading AV and EDR detection. YARA analysis identified as the best detection method. The technique's rental availability significantly lowers barrier to entry for threat actors.
Kratos Phishing-as-a-Service operation uses trusted platforms, anti-bot checks, and convincing login pages to steal Microsoft 365 credentials while delaying detection. Mature operation affecting enterprise users across multiple regions.
Persistent Mozi botnet activity observed with malware downloads from multiple compromised IoT devices across Chinese and international IP ranges, targeting MIPS and ARM architectures for botnet expansion.
ShinyHunters OAuth abuse campaigns; Spanish police dismantle €140M fraud ring; US indicts Russian bulletproof hosting operators; sanctions against ransomware enablers
Microsoft identified ShinyHunters threat actor campaigns from mid-2025 to mid-2026 using voice phishing (vishing) and supply chain attacks to abuse OAuth mechanisms in SaaS-based applications, enabling persistent access to victim environments.
Law enforcement dismantled a cybercrime and money-laundering organization that generated €140 million ($160 million) through investment fraud and business email compromise attacks, arresting four individuals. Significant disruption to organized cybercrime infrastructure.
DOJ unsealed indictments against alleged operators of Media Land and ML.Cloud, Russian bulletproof hosting services providing cybercriminals with infrastructure and technical support. Rewards for Justice offering $10M for information on Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yuliya Vladimirovna Pankova.
Treasury Department's OFAC sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations by providing VPN services and malware infrastructure to ransomware gangs.
Dutch intelligence reports Russian agencies compromising internet-connected cameras across Europe to spy on NATO logistics operations and Ukrainian military personnel, demonstrating sophisticated HUMINT collection against critical infrastructure.
Trusted ransomware negotiator secretly collaborated with BlackCat ransomware gang to extort victims instead of helping them, costing organizations millions in inflated ransom payments. Represents insider threat within incident response ecosystem.
Finnish police issued wanted notice for convicted hacker responsible for massive psychotherapy data breach affecting thousands. Defendant left Finland while on appeal, raising concerns about extradition and justice in high-profile data breach cases.
Callum Dare, 26-year-old Doxbin administrator, sentenced to prison for his role in numerous swatting incidents across UK, US, and Canada. Doxbin platform facilitated exposure of PII used in dangerous swatting campaigns targeting individuals.
18 new ransomware victim organizations disclosed including automotive, hospitality, pharma, and infrastructure sectors; notable incidents include xAI data leak and Synopsys/Bosch breach claims
DragonForce ransomware group claims compromise of Momenta, a Chinese AI and autonomous-driving company. Attackers stole all source code, financial documents, configuration files, and employee database. Servers and workstations encrypted. Group alleges company attempting to hide breach from Chinese regulators, HKEX commission, and investors.
BlackNevas ransomware group reports massive data breach affecting Arkın Hotel Group including premium properties The Arkın Colony and Cratos Premium hotels. Over 1 TB of guest and casino data compromised, representing significant hospitality sector breach.
Elon Musk's xAI announced emergency measures after Grok Build CLI tool uploaded users' private code and confidential information to a server without authorization. Company promises to delete all affected data following serious privacy breach.
Chaos ransomware group compromised pharmaceutical company infrastructure and stole 142 GB of critical corporate data including financial statements (CAPEX, fixed assets, accounts receivable/payable), operational data, and sensitive business information.
BlackNevas ransomware group listed L'azurde Company for Jewelry, a prominent Middle Eastern jewelry manufacturer and retailer headquartered in Riyadh, Saudi Arabia, operating across Kingdom, Egypt, UAE, Kuwait, Oman, and Qatar.
DragonForce listed Midal Cables, founded 1977 manufacturer of aluminum rods/wires, overhead line conductors, and extruded products with offices in Bahrain, London, Toronto, Kuala Lumpur and Nairobi. Critical infrastructure supply chain target.
DragonForce compromised SITAV SpA, Italian company specializing in construction, maintenance, revision, and restoration of trains and railway vehicles including high-speed trains, regional transport, trams, and subways. Transportation sector impact.
DragonForce listed Edison Global Networks Limited, Hong Kong-based IT system integrator and MSP with offices in Shenzhen, Shanghai, and Beijing. Specializes in cloud solutions, network infrastructure, disaster recovery, and global data center services.
DragonForce compromised Intron Technology Holdings Limited, Chinese automotive electronics solutions provider focusing on New Energy, Body Control, Safety and Powertrain systems. Supply chain impact to automotive industry.
CMD Organization ransomware group listed Target Energy Solutions, rapidly growing digital oilfield services company providing web-based visualization, collaboration and workflow tools via MEERA platform to petrotechnical community.
DragonForce group also compromised: Graphic International Centre (UAE printing/office automation), Road Ahead Technologies (Chinese 3D scanning), Atcom (VoIP manufacturer), Omax Autos (Indian auto components), Ifage (Geneva education foundation), and Asimar (Thai shipyard).
New ransomware group D1R listed Synopsys and Bosch on leak site, claiming exploitation of Synopsys website vulnerability to access corporate client database containing 40,000 entries. Synopsys reports no evidence of data breach found in investigation.
New phishing kits defeat MFA; Cursor IDE vulnerability enables malicious code auto-execution; FaceTime-based scams targeting banking; password manager users targeted with fake alerts
Critical vulnerability in Anyquery allows arbitrary file write leading to remote code execution via unrestricted ATTACH DATABASE in server mode. CVSS 9.1. Affects SQL query tool deployments in server configurations.
Two sophisticated phishing kits discovered targeting Microsoft 365 accounts with techniques that successfully bypass multi-factor authentication protections. Represents evolution in credential harvesting capabilities.
Critical vulnerability in popular Cursor AI coding platform automatically executes malicious code when opening poisoned repositories. Reported to Cursor in December but remains unpatched, exposing developers to supply chain attacks through compromised code repositories.
Cybercriminals combining social engineering through FaceTime and other apps with exploitation of unpatched devices to steal credentials and drain bank accounts. Multi-stage attack leveraging both technical vulnerabilities and human manipulation.
Woodpecker CI/CD platform vulnerable to cross-tenant agent impersonation via spoofed agent_id metadata in gRPC communications, enabling unauthorized access to build pipelines and secrets. CVSS 7.1.
LastPass warns of ongoing phishing campaign using fraudulent security notices to direct password manager users to fake websites for credential harvesting. Targets high-value users protecting multiple account credentials.
Microsoft introduces passkeys as default authentication; frontier AI deployment raises regulatory questions; vendor risk management guidance
Cutting-edge AI models deploying with increased independence and reduced human oversight while regulatory frameworks lag. Multiple state governments attempting to legislate transparency requirements for frontier AI use in critical applications.
Microsoft announces passkeys will become default authentication method for Entra ID enterprise identity service starting September 2026, representing major shift away from password-based authentication for enterprise environments.
Guidance on managing third-party vendor risk through risk tolerance definition, exposure visibility, and board oversight. Addresses complexity of handling third-party risk with disciplined, precise governance approach.
OpenAI publishes enterprise guidance on managing AI investments by measuring useful work per dollar, improving efficiency, and scaling high-value workflows as autonomous AI agents become more prevalent in enterprise environments.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.