The 48-hour period from July 15-16, 2026 witnessed a dramatic escalation in cyber threats across multiple vectors. Microsoft released a record-breaking 622 CVE patches in its July Patch Tuesday—triple the previous month's count and the second consecutive record-setting release—including three actively exploited zero-days. Critical supply chain attacks dominated the threat landscape, highlighted by the AsyncAPI npm compromise delivering credential-stealing malware through weaponized CI/CD workflows, and multiple AI tool vulnerabilities enabling arbitrary code execution. The breach ecosystem expanded significantly with major incidents affecting Fluke (821K records), Goose Creek Candle (6.6M customer records), and critical infrastructure including India's Kudankulam nuclear plant. Ransomware operations maintained aggressive tempo with 19 new victim disclosures spanning healthcare, legal, manufacturing, and infrastructure sectors, while Dutch law enforcement dismantled a €100M+ cryptocurrency investment fraud network operating call centers across multiple countries.
Record-breaking patch release includes actively exploited flaws across SharePoint, Zoom, and bootloader components
Microsoft's July Patch Tuesday sets yet another record with 622 CVEs—three times the previous month's count and the second consecutive record-breaking release. Three zero-days are being actively exploited in the wild.
CISA added three SharePoint Server vulnerabilities to the Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting these flaws to compromise Internet-exposed on-premises SharePoint instances. Federal agencies must patch by deadline.
Zoom warns of a critical vulnerability in its Windows desktop client and SDK that could allow unauthenticated attackers to hijack user accounts remotely.
Ten critical severity CVEs (CVSS 9.0+) disclosed affecting Wekan, NocoBase, AdonisJS, and other platforms. Vulnerabilities enable unauthenticated remote code execution, command injection, and authentication bypass across widely-deployed applications.
Nearly a dozen vulnerable and revoked UEFI shim bootloaders remained trusted for years, providing attackers with a path to bypass Secure Boot protections and establish persistent boot-level access.
Sophisticated supply chain attacks target developer ecosystems and AI tooling infrastructure
Threat actors compromised five AsyncAPI npm packages and weaponized trusted CI/CD workflows to distribute remote access trojans with info-stealing capabilities. The attack leveraged import-time payload delivery to execute malicious code during package installation.
Elastic Security Labs reverse-engineered TELEPUZ, a modular malware-as-a-service platform that emerged in April through CLICKFIX-VIDAR attack chains. Analysis reveals sophisticated infrastructure and evasion techniques designed for persistence and data exfiltration.
Palo Alto Unit 42 analyzed TuxBot v3, an IoT botnet framework built with assistance from large language models. The malware features cross-compiled binaries targeting multiple architectures, sophisticated C2 infrastructure, and contains bugs indicative of AI-assisted development.
URLhaus identified 50+ malicious URLs distributing ClearFake, ClickFix, GuLoader, and PureLogsStealer malware families. Distribution infrastructure spans compromised legitimate sites and attacker-controlled domains targeting Windows and macOS platforms.
Malwarebytes discovered CrashStealer, malware disguised as Apple's legitimate CrashReporter application. The trojan steals passwords from macOS Keychain, browser data, cryptocurrency wallets, and other sensitive information from infected Macs.
Multiple critical vulnerabilities discovered in AI assistants and development environments enabling code execution and credential theft
Russian-speaking threat actor 'bandcampro' weaponized Google's open-source Gemini CLI AI tool, using it as an autonomous hacking agent and to operate a small-scale botnet. Demonstrates emerging abuse of AI tooling for offensive operations.
Researchers disclosed the 'PromptFiction' vulnerability in Claude AI agents that automatically sends malicious prompts when combined with another exploit. The now-patched flaw could have enabled end-to-end attacks on targeted systems through AI agent manipulation.
The ClaudeBleed vulnerability allows malicious Chrome extensions to abuse Claude for Chrome's excessive permissions, enabling unauthorized access to users' Gmail accounts and other sensitive browser data.
Security researchers discovered simple age-old bugs in the Cursor development environment that give attackers access to developers' secrets and source code-rich environments through a basic two-click social engineering attack.
Intruder built an AI-powered system combining code slicing with LLMs to automatically discover complex software vulnerabilities. The 'vulnerability vending machine' successfully found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under embargo.
Major law enforcement disruption of cryptocurrency fraud network; bulletproof hosting operators charged
Dutch authorities arrested multiple individuals operating an international cryptocurrency investment scam estimated to have defrauded tens of thousands of victims of over €100 million. The group operated like a legitimate business since 2021, running approximately two dozen call centers across several countries with over 700 employees posing as professional financial advisers.
US federal prosecutors unsealed charges against three Russian nationals for providing bulletproof hosting services to ransomware gangs that caused over $62 million in damages to victims worldwide. The infrastructure enabled persistent criminal operations by shielding threat actors from law enforcement.
Major credential exposures affect millions across retail, manufacturing, healthcare, and critical infrastructure sectors
Ransomware group World Leaks posted a massive cache of files related to India's largest nuclear power plant on the dark web, including purported blueprints of facility components, supplier details, and operational information labeled as originating from Reliance Group. The breach represents a critical infrastructure security incident with national security implications.
Goose Creek Candle Company suffered a data breach affecting 6.6 million customers. Exposed data includes email addresses, names, phone numbers, physical addresses, and purchase histories. The breach was disclosed after threat actors sent emails to customers claiming the company had a security vulnerability.
A coalition of 42 state attorneys general reached an $18 million settlement with genetic testing company 23andMe for cybersecurity failings that led to a major data breach exposing sensitive genetic and personal information of customers.
Prestigious law firm Wilmer Cutler Pickering Hale & Dorr faces putative class action lawsuit in US District Court for the District of Columbia over May data breach that exposed clients' personal information. Plaintiffs seek millions in damages for negligence.
Partnered Health, which operates family medical clinics across Australia with six locations per state, suffered a cyber breach exposing patient data including potentially sensitive treatment information affecting patients nationwide.
Multiple ransomware groups claimed 19 new victims spanning healthcare (Carient Heart & Vascular, South Plains Rural Health), legal services (Shillen Mackall & Seldon, Hughes Atwood & Mullaly), manufacturing (Stephens Precision, Pioneer Construction, Heritage Mechanical), transportation (Nihon Kotsu - Japan's largest taxi operator, Ferrovial global infrastructure), technology (Solid Advance), and retail (Levin Furniture, Jani-King facilities services). Notable victims include Panasonic Aero (aviation systems) and Abbott-owned Exact Sciences Corporation under final extortion deadline.
Electronic test and measurement equipment manufacturer Fluke was targeted in a ShinyHunters 'pay or leak' extortion campaign. Over 100GB of data published includes 821K records containing corporate contact information with email addresses, employers, job titles, names, physical addresses, and support tickets.
New government initiatives focus on AI safety, vulnerability management, and international cybersecurity cooperation
US government restrictions on Anthropic and OpenAI frontier AI models have intensified calls in the UK and allied countries to reduce reliance on US tech companies, with significant implications for cybersecurity architecture and supply chain dependencies.
The Gold Eagle program launches to enable industry, critical infrastructure operators, and government agencies to use artificial intelligence for rapid detection, prioritization, and patching of cybersecurity vulnerabilities across sectors.
Nigeria advanced regulations forcing organizations to disclose cyberattacks, joining other nations in shifting toward mandated transparency as cybercriminals in the West African country see increasing profits.
OpenAI outlined a policy framework where state-level AI laws help build a cohesive national framework for safe, democratic AI development and deployment, advocating for coordinated governance across federal and state levels.
Industry shifts in attack vectors and defensive capabilities highlight identity-based threats
Email-based credential attacks surpassed exploit-based initial access as the leading ransomware infection vector in 2025. Despite 97% of credential-based attacks encountering multifactor authentication, MFA failed to prevent compromise, highlighting weaknesses in identity security controls.
Microsoft details how Defender Experts helps security teams convert overwhelming threat intelligence signal from endpoints, identities, cloud workloads, and third-party tools into decisive defensive action amid unprecedented visibility yet persistent uncertainty.
OpenAI published research on GPT-Red, an automated red teaming system using self-play to improve AI safety, alignment, and robustness against prompt injection attacks through continuous adversarial testing.
Evidence from the Forensic Focus International Well-Being Study formally submitted to UK Parliament and national policing/forensic bodies, highlighting mental health challenges facing digital forensics practitioners examining disturbing evidence.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.