2026-07-14
- vulnerabilities
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
Microsoft released patches for 622 CVEs this week, including three zero-day vulnerabilities and over 60 critical issues.
Why it matters: Security teams must prioritize patching critical and zero-day CVEs immediately to prevent exploitation of unpatched systems in their environments.
- breaches incidents
Elon Musk promises to delete all data following a leak of users’ confidential information
xAI announced it will permanently delete all previously uploaded user data following an unauthorized disclosure of private code and confidential information through the Grok Build CLI tool. The company stated the deletion decision was made for security reasons in response to the incident.
Why it matters: Developers using xAI's Grok Build tool should verify what data was exposed and confirm deletion status, as confidential code and proprietary information may have been compromised.
- government policy
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats
The Trump administration launched Gold Eagle, a federal clearinghouse managed by Treasury to share AI-related cyber threat intelligence between government and private sector organizations. The initiative, established through a White House executive order, includes participation from DHS, DoD, CISA, open-source software providers, and critical infrastructure operators, and has already begun collecting vulnerability intelligence. Gold Eagle aims to identify, prioritize, and patch vulnerabilities using AI tools before adversaries exploit them, particularly addressing the widespread risk of insecure code and misconfigurations in open-source software.
Why it matters: Security practitioners across critical infrastructure and software development organizations should engage with Gold Eagle to access early threat intelligence on vulnerabilities and coordinate patching efforts before adversaries discover them using AI-powered scanning tools.
- breaches incidents
Rewards For Justice offers reward for info on Media Land, ML.Cloud, and three individuals associated with it
The US Rewards for Justice program announced a $10 million reward for information leading to the identification or location of Media Land, a Russian bulletproof hosting (BPH) provider, its subsidiary ML.Cloud, and three associated individuals. Media Land allegedly facilitates illegal activities by hosting illicit content and providing anonymous domain registration services for customers.
Why it matters: Organizations managing abuse, law enforcement, and threat intelligence teams should be aware that US authorities are actively seeking information on a significant BPH provider; practitioners may encounter Media Land or ML.Cloud infrastructure when investigating phishing, malware, or other criminal infrastructure.
- ransomware
Spanish Police take down €140 million cyber fraud ring, arrest four
Spanish police dismantled a cybercrime organization responsible for approximately 140 million euros in losses through investment fraud and business email compromise attacks. The operation resulted in four arrests and targeted money-laundering infrastructure used to conceal criminal proceeds.
Why it matters: Finance and business email users are targets of organized fraud rings that launder proceeds through complex networks; understanding takedown operations helps practitioners recognize and defend against BEC and investment fraud tactics.
- vulnerabilitiesCVE-2026-27690CVE-2026-44747
Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record
Microsoft disclosed 622 vulnerabilities during July 2026 Patch Tuesday, more than triple the previous month's record of 206 and reflecting an exponential surge driven by artificial intelligence tools discovering defects at scale. Two actively exploited zero-day vulnerabilities in Active Directory Federation Services and SharePoint Server were included among the batch, with 63 rated as critical. The pace suggests Microsoft will exceed 2,000 or more Common Vulnerabilities and Exposures (CVEs) for the calendar year, far surpassing historical annual records.
Why it matters: All organizations running Microsoft products must prioritize patch assessment and deployment given the record volume; the presence of two actively exploited zero-days in widely deployed authentication and collaboration systems demands immediate attention to those specific fixes.
- vulnerabilities
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
Automated Frequency Coordination (AFC) systems used in 6 GHz Wi-Fi implementations trust client-provided location data by default, creating an attack surface for location spoofing and potential disruption of wireless traffic. Security researchers have identified this design flaw as a vulnerability in the coordination mechanism that determines spectrum access permissions.
Why it matters: Network administrators and operators managing 6 GHz deployments face immediate risk of spectrum interference attacks that could degrade or block critical wireless communications; patching or reconfiguring AFC systems to validate location data server-side is now a priority.
- government policy
US unseals indictment against alleged operators of Russian bulletproof hosting service
The U.S. Department of Justice unsealed an indictment against alleged operators of a Russian hosting service that prosecutors claim provided infrastructure and technical support to cybercriminals. Media Land and its sister company ML Cloud, both based in St. Petersburg, are at the center of the allegations.
Why it matters: Practitioners managing incident response or threat hunting should monitor this case as it targets bulletproof hosting providers that enable ransomware, malware distribution, and other attacks; takedowns of such infrastructure disrupt attacker operations.
- threat intel
Nearly 300 GitHub repos pose as legit software to push malware
A threat actor created hundreds of fake GitHub repositories that impersonate legitimate software and security projects to distribute infostealer malware. These repositories are designed to deceive developers searching for authentic tools and libraries.
Why it matters: Developers using GitHub face risks of downloading malware-laden imposters instead of genuine dependencies, potentially compromising their systems and development environments. Organizations should implement artifact verification and dependency scanning to prevent supply chain compromise.
- vulnerabilities
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft released patches for 622 vulnerabilities in its monthly update, a record number. Two zero-day flaws in Active Directory and SharePoint Server have been exploited in the wild, and a BitLocker vulnerability was publicly disclosed before patching.
Why it matters: Organizations using Active Directory and SharePoint Server must prioritize patching the exploited zero-days immediately, while BitLocker users face public exploit code availability.
- vulnerabilitiesCVE-2026-48561CVE-2026-50661
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft released Windows 10 KB5099539, an extended security update containing July 2026 Patch Tuesday fixes for 570 vulnerabilities and additional security patches. This update addresses a substantial volume of identified flaws across the Windows 10 platform.
Why it matters: Organizations running Windows 10 should deploy this update to remediate 570 known vulnerabilities that could be exploited by attackers.
- ransomware
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
The D1R cybercrime group claimed to have stolen data from Synopsys and Bosch and threatened to leak it unless paid a ransom. Synopsys investigated the claim and found no evidence supporting a data breach at the company.
Why it matters: Security teams at Synopsys and Bosch need to assess whether ransom threats are credible or extortion attempts, and practitioners should monitor for any actual data releases that would indicate real compromise.
- vulnerabilitiesCVE-2026-48564CVE-2026-49796
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft released security patches on July Patch Tuesday addressing 570 vulnerabilities, including three zero-day flaws: two that were actively exploited in attacks and one previously disclosed to the public. This represents a significant volume of fixes across Microsoft's product portfolio.
Why it matters: All organizations running Microsoft products face potential exposure from these flaws, including two actively exploited zero-days; prioritize testing and deploying these patches immediately, starting with systems processing sensitive data.
- regulatory
Manage Vendor Risk in a Few Practical Steps
A brief piece outlines that managing vendor risk requires understanding risk tolerance, gaining visibility into exposures, and obtaining board-level oversight through disciplined governance approaches.
Why it matters: Security teams and risk officers need practical frameworks to govern third-party risk, which affects the security posture of organizations dependent on external vendors.
- vulnerabilities
Windows 11 KB5101650 & KB5099414 cumulative updates released
Microsoft released cumulative updates KB5101650 and KB5099414 for Windows 11 across versions 25H2, 24H2, and 23H2 to address security vulnerabilities, resolve bugs, and introduce new features. These updates maintain the regular patching cadence for the operating system.
Why it matters: Windows 11 administrators and users need to deploy these cumulative updates to remediate disclosed security vulnerabilities and maintain system stability and compatibility.
- vulnerabilitiesCVE-2026-15409CVE-2026-15410
SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
SonicWall has released patches for two actively exploited zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances. The company recommends affected organizations upgrade firmware, search for indicators of compromise, and if found, re-image or re-deploy appliances and reset credentials and multi-factor authentication tokens.
Why it matters: Organizations running SonicWall SMA 1000 Series appliances face active exploitation risk and must patch immediately, then audit for breach evidence and perform credential rotation.
- breaches incidents
Finland issues wanted notice for hacker behind massive psychotherapy data breach
Finnish authorities have issued a wanted notice for a hacker involved in a major psychotherapy data breach. The suspect's legal representative indicated the defendant's whereabouts are unknown but likely outside Finland.
Why it matters: Organizations handling psychotherapy records and practitioners subject to data protection laws should track this case as it demonstrates cross-border enforcement challenges and potential regulatory scrutiny of health data security.
- breaches incidents
Doxbin admin jailed for egging on swatters from behind a screen
A 26-year-old Welsh administrator of Doxbin, a dark web platform for sharing personally identifiable information, was sentenced to prison for facilitating swatting attacks across the UK, US, and Canada. Dare used his administrative position to encourage harassment and coordinate attacks on targets. His conviction addresses criminal activity that endangered victims through coordinated swatting incidents.
Why it matters: Security practitioners and law enforcement should track this outcome as it demonstrates prosecution of dark web infrastructure operators who facilitate harassment and swatting campaigns, helping establish legal precedent for attacking platform administrators rather than just individual attackers.
- vulnerabilities
Adobe Patches Critical ColdFusion Vulnerabilities
Adobe released patches for critical vulnerabilities in ColdFusion that could enable remote code execution and privilege escalation. The flaws pose significant risk to organizations running vulnerable versions of the application server.
Why it matters: ColdFusion administrators and organizations relying on the platform should apply patches immediately to prevent attackers from executing arbitrary code or gaining elevated access to systems.
- threat intel
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Security researchers identified LabubaRAT, a previously undocumented remote access trojan written in Rust that impersonates NVIDIA software to avoid detection on Windows systems. The malware establishes persistence and can profile compromised hosts for follow-on attacks.
Why it matters: Windows administrators and security teams need to monitor for suspicious processes spoofing NVIDIA software, as this RAT enables attackers to maintain persistent access for reconnaissance and lateral movement.
- vulnerabilities
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
Progress Software confirmed that a high-severity zero-day vulnerability prompted the emergency shutdown of ShareFile Storage Zone Controllers. The company released security updates to address the flaw.
Why it matters: Organizations operating ShareFile Storage Zone Controllers face active exploitation risk and must deploy available patches immediately to prevent unauthorized access or data exposure.
Upcoming Speaking Engagements
An individual has scheduled speaking engagements at six conferences and events across North America between July and October 2026, including appearances at policy, leadership, security, and convention venues. The list includes confirmed dates for most events, with speaking times to be announced for several of them.
Why it matters: This content has no direct security impact for practitioners; it is a speaker's personal calendar with no vulnerability, threat, incident, or policy information relevant to cybersecurity decision-making.
- ai security
Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?
Advanced AI models are being deployed with reduced human oversight and greater autonomy, prompting some state governments to propose transparency requirements around their implementation. These legislative efforts represent early attempts to establish governance frameworks for frontier AI systems.
Why it matters: Security and compliance practitioners need to monitor emerging state-level AI transparency rules that may affect how your organization deploys and validates AI systems, and understand the governance gap as models operate with less direct human control.
- threat intel
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
ClickFix malware is becoming available as a rental service, capable of bypassing traditional antivirus and endpoint detection and response tools, with YARA rule-based detection representing the most viable current mitigation approach.
Why it matters: Security teams defending against ClickFix need to shift detection strategies immediately, as conventional AV and EDR defenses are ineffective and YARA analysis must become a primary detection method.
- threat intel
LastPass, Bitwarden users targeted with fake security alerts
LastPass has issued a warning about a phishing campaign that tricks users with fake security notices and directs them to fraudulent websites. The campaign exploits users' trust in the password manager to capture credentials or sensitive information. This reflects an ongoing trend of attackers impersonating legitimate security vendors to harvest user data.
Why it matters: LastPass and Bitwarden users are at immediate risk of credential theft; practitioners should alert users to verify security notices directly through official channels and never click links in unsolicited messages.
- threat intel
Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says
Iran exploited known vulnerabilities in cellular networks to locate U.S. military personnel in the Middle East during the early phases of conflict. The technique leveraged existing weaknesses in mobile network infrastructure rather than targeting individual devices or accounts.
Why it matters: Military and defense personnel worldwide should understand that commercial mobile networks expose location data through known flaws; telecom operators and IT security teams need to prioritize patching network vulnerabilities and implementing geofencing controls.
- breaches incidents
Telegram’s shortlink domain is back online after day-long suspension
Telegram experienced a brief outage affecting its shortlink domain, which prevented users from accessing links to the messaging app. CEO Pavel Durov acknowledged the disruption on social media, confirming that shortlinks had stopped functioning.
Why it matters: Users relying on Telegram shortlinks for onboarding or sharing experienced access friction; practitioners managing Telegram infrastructure or integrations should monitor for similar service availability issues.
- vulnerabilities
You Don't Have to Run an Exploit to Know If You're Vulnerable
Organizations can validate vulnerability exploitability by testing the attack techniques and tactics (TTPs) that an exploit depends on, rather than running the exploit itself. This approach allows security teams to assess risk on critical systems where live exploit testing would be unsafe or impossible. Picus describes how TTP chaining enables this validation without direct exploitation.
Why it matters: Security practitioners managing critical infrastructure or systems without available exploits need safe methods to determine which vulnerabilities pose actual risk to their environment before allocating remediation resources.
- vulnerabilities
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
VMware patched seven severe vulnerabilities in Avi Load Balancer that could enable authentication bypass, remote code execution, privilege escalation, and directory traversal. The specific CVE numbers, affected versions, and remediation details were not provided in the available information.
Why it matters: Organizations running VMware Avi Load Balancer should prioritize patching these critical flaws to prevent unauthorized access, code execution, and privilege escalation in a security-critical network component.
- threat intel
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence has disclosed that Russian agencies are compromising internet-connected cameras across Europe to conduct surveillance on military logistics operations and Ukrainian troops. The campaign targets networked cameras to gather intelligence on NATO and Ukrainian military activities.
Why it matters: NATO members, Ukrainian forces, and any organization with internet-facing cameras in Europe face active surveillance targeting military and logistics operations; practitioners should audit camera access controls and network segmentation immediately.
- vulnerabilities
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Researchers disclosed two access control vulnerabilities in RabbitMQ that could leak OAuth client secrets and expose cross-tenant queue metadata. These flaws enable attackers to bypass tenant isolation boundaries and compromise enterprise messaging infrastructure. Miggo's security team discovered and reported the issues to the vendor.
Why it matters: Organizations using RabbitMQ in multi-tenant environments face risks of credential exposure and lateral movement across tenant boundaries if these vulnerabilities remain unpatched.
- research
Download: The ultimate guide to network operations management
A downloadable guide discusses challenges in modern network operations management, highlighting manual processes, growing complexity, and operational inefficiencies. The resource explores how intelligent workflows can reduce manual work, improve visibility, and accelerate response across network operations teams.
Why it matters: IT and security teams managing large networks need practical approaches to reduce operational friction and improve incident response speed.
- vulnerabilitiesCVE-2026-55040
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Rapid7 Labs discovered CVE-2026-55040, an authentication bypass vulnerability in Microsoft SharePoint that allows unauthenticated attackers to assume the identity of any known user by manipulating JWT token validation. The vulnerability has a CVSS score of 5.3 and can be chained with a second RCE vulnerability for complete system compromise; Microsoft will patch the RCE component in August 2026 while the authentication bypass fix is already available.
Why it matters: SharePoint administrators and security teams must prioritize patching this authentication bypass immediately, as it enables unauthorized access to sensitive business data and can be weaponized in combination with other vulnerabilities to achieve remote code execution across the enterprise.
- vulnerabilities
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
Security researchers disclosed a vulnerability in Cursor IDE that allows malicious code to execute automatically when opening compromised repositories. The flaw was reported in December, but the platform has not yet patched the issue, leaving users exposed to poisoned repository attacks.
Why it matters: Developers using Cursor are at risk of arbitrary code execution when cloning or opening repositories, potentially compromising their systems and credentials; practitioners should evaluate whether they or their teams use this IDE and consider restricting repository access or disabling auto-execution features.
- vulnerabilities
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
A vulnerability in Claude for Chrome remains unpatched across eight updates, allowing malicious extensions to access sensitive user data including Gmail and Calendar contents. The flaw appears related to ClaudeBleed, a class of vulnerabilities affecting how the extension isolates data from other browser extensions.
Why it matters: Users of Claude for Chrome face exposure of email and calendar data to any malicious extension installed in their browser; organizations should evaluate whether to restrict or disable the extension until a proper fix is released.
- threat intel
New phishing kits target Microsoft 365 accounts, evade MFA
Two phishing kits, Jalisco and OmegaLord, have emerged in active attacks targeting Microsoft 365 accounts with techniques designed to bypass multi-factor authentication (MFA). These tools represent an escalation in phishing sophistication as threat actors work to compromise accounts even when additional authentication layers are in place.
Why it matters: Organizations relying on Microsoft 365 with standard MFA face credential theft risk from these kits; practitioners should investigate whether reverse-proxy phishing or session-hijacking methods are being used and consider additional controls like conditional access policies.
- vulnerabilities
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Researchers discovered 11 Microsoft-signed UEFI applications that could allow attackers to bypass Secure Boot and execute arbitrary code during system boot. These vulnerable shims could be leveraged to deploy UEFI (Unified Extensible Firmware Interface) bootkits or other malware on affected systems.
Why it matters: Organizations running Linux on systems with Secure Boot enabled face firmware-level compromise risk; patching or removing these signed applications is critical to prevent bootkit deployment.
- ai security
“Context bombs” can frustrate AI-driven attacks, researchers found
Tracebit researchers have developed a defensive technique using prompt injection to stop AI agents from compromising targeted environments. The approach deploys canary resources that trigger early warnings when attackers or AI agents interact with them, leveraging what the researchers call context bombs to disrupt AI-driven attack chains.
Why it matters: Security teams defending against AI-assisted attacks now have a practical detection mechanism; understanding context bombs and canary deployment can improve incident response speed when AI agents probe systems.
- vulnerabilitiesCVE-2026-32201CVE-2026-45659
CISA Urges SharePoint Hardening After New Exploitations
CISA has confirmed active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affecting all supported on-premises versions, with attackers achieving remote code execution and stealing credentials for persistence. The agency identified two additional unpatched vulnerabilities posing risk and published detection signatures for AMSI and Microsoft Defender. CISA recommends immediate patching, enabling AMSI scanning in Full Mode, hardening network exposure, implementing enhanced logging, and hunting for existing compromise artifacts.
Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face active attacks targeting RCE and credential theft; apply patches immediately and verify AMSI configuration to detect ongoing exploitation before attackers establish durable persistence.
- vulnerabilitiesCVE-2025-13162
ABB Advant Master Online Builder
ABB disclosed a vulnerability in Advant Master Online Builder affecting Control Builder A and 800xA for Advant Master due to improper DLL search path handling that could allow unauthorized code execution. Updates are available with specific version recommendations for affected products across multiple release branches. The issue affects critical manufacturing infrastructure worldwide and carries a CVSS score of 4.4 (Medium severity).
Why it matters: Operators of ABB Advant Master systems in critical manufacturing environments must apply patches or upgrade to unaffected versions to prevent local code execution by authenticated attackers with system access.
- vulnerabilitiesCVE-2026-31431
ABB Ability Edgenius
ABB has released an advisory for CVE-2026-31431, a Linux kernel vulnerability affecting ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 installed on multiple gateway and server models. The flaw allows locally authenticated users or compromised container workloads to escalate privileges to root, potentially granting complete system control. A patch is available in version 3.2.4.1, and ABB recommends immediate application along with access restrictions to SSH and Cockpit.
Why it matters: Organizations deploying ABB Ability Edgenius in critical manufacturing environments must patch immediately, particularly in shared or containerized deployments where local privilege escalation poses elevated risk.
- vulnerabilitiesCVE-2026-10577
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
A critical vulnerability (CVE-2026-10577) in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions 3.003 and earlier exposes an unauthenticated debug port that allows remote attackers to execute command-line commands without authentication. Successful exploitation could enable an attacker to read or delete files, stop tasks, modify memory, and alter I/O states, affecting confidentiality, integrity, and availability. Rockwell Automation recommends updating to version 3.011 or later and has published mitigation guidance for organizations unable to patch immediately.
Why it matters: Energy, water and wastewater, and critical manufacturing organizations worldwide using the 1715-AENTR adapter face immediate remote code execution risk; patching to version 3.011 or implementing network segmentation and VPN controls is essential to prevent operational disruption and loss of control over industrial systems.
- vulnerabilitiesCVE-2025-14771CVE-2025-14772
ABB T-MAC Plus
ABB disclosed four critical vulnerabilities in T-MAC Plus version 4.0-24 affecting the web application, including file disclosure, authorization bypass, cross-site scripting, and incorrect authorization flaws with CVSS scores ranging from 8.8 to 9.9. The vendor released T-MAC Plus version 4.0-25 as a fix and recommends customers apply the update immediately. These vulnerabilities could allow authenticated users to exfiltrate sensitive files, perform unauthorized administrative operations, and inject malicious scripts.
Why it matters: Organizations operating ABB T-MAC Plus 4.0-24 in critical manufacturing environments worldwide face immediate risk of data theft and system compromise through authenticated attack vectors; patching to version 4.0-25 is urgent.
- research
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven analyzed 85 popular cryptocurrency wallet browser extensions and identified privacy vulnerabilities that allow address linking and cross-site tracking. The wallet communication patterns with websites and blockchain servers expose user activity in ways that enable deanonymization and user tracking across sites.
Why it matters: Cryptocurrency users relying on browser-based wallet extensions face privacy leakage that undermines the anonymity properties they expect, making them targets for tracking by advertisers, malicious sites, or adversaries attempting to correlate their on-chain activity.
- vulnerabilitiesCVE-2026-44747
SAP warns of critical flaws in NetWeaver and Commerce Cloud
The vendor released security updates addressing 16 vulnerabilities across multiple products in July 2026, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The updates cover significant exposure in SAP's enterprise middleware and cloud commerce platforms.
Why it matters: SAP NetWeaver and Commerce Cloud administrators must assess whether critical vulnerabilities affect their deployments and apply patches immediately to prevent exploitation.
- ai security
How Pentera Turns AI Security Workflows into Validation Engines
Pentera uses AI security agents to consolidate fragmented risk signals from multiple sources, including scanner output, severity scores, threat intelligence, and configuration findings into unified validation workflows. The approach aims to help security teams prioritize remediation and accelerate decision-making by modeling how attackers actually move through environments rather than relying on isolated data points.
Why it matters: Security teams need to understand which vulnerabilities and exposures pose the most immediate risk; consolidated AI-driven prioritization can reduce investigation time and guide remediation sequencing.
- cloud saas
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Security researchers identified threat actors using OAuth client ID spoofing to enumerate and validate stolen credentials against Microsoft Entra ID without triggering sign-in logs. The technique bypasses standard telemetry detection, allowing attackers to confirm compromised credentials while evading defender alerts.
Why it matters: Organizations using Microsoft Entra ID face silent credential validation attacks that circumvent logging and detection; practitioners should review access logs for anomalous OAuth authentication patterns and enforce conditional access policies to mitigate this evasion technique.
- vulnerabilities
Vulnerability in FIFA’s Network
FIFA's network contained a vulnerability that could be exploited by individuals with minimal access levels.
Why it matters: Organizations managing sports infrastructure should audit internal access controls; FIFA's exposure demonstrates how privilege boundaries can fail to prevent lateral movement or unauthorized actions.
- industry
Microsoft starts testing cleaner Windows Search without ads
Microsoft has begun testing a redesigned Windows Search interface that prioritizes search results over advertisements and promotional content, aiming for improved performance and relevance. The updated version is intended to deliver a cleaner user experience with faster query handling.
Why it matters: Windows administrators and users benefit from reduced distraction during system searches, streamlining workflow efficiency and reducing unwanted promotional exposure in a core OS component.
- threat intel
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Cisco Talos Intelligence Integrations apply threat intelligence across Cisco's security and enterprise technologies to identify and block malicious activity. The integrations help security teams answer critical questions about newly registered domains, outbound connections, and unusual user behavior in their environments. A new video introduces the team and explains how these integrations work.
Why it matters: Security teams using Cisco products benefit from automated threat detection that applies the latest intelligence to block attacks more effectively across their infrastructure.
- identity access
Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Google has begun rolling out support for FIDO2 physical security keys and phone passkeys as a second authentication factor for Google Credential Provider for Windows (GCPW) across all Google Workspace customers. GCPW enables Windows login using Google Workspace credentials, and the new capability allows administrators to enforce two-step verification with hardware security keys. The update strengthens account security by providing organizations with stronger multi-factor authentication options for Windows device access.
Why it matters: Google Workspace administrators can now enforce hardware-based multi-factor authentication for Windows login, reducing reliance on passwords and phishing-vulnerable authentication methods for their organization's workforce.
- threat intel
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
A supply chain attack targeted AsyncAPI npm packages through compromised GitHub Actions workflows. Malicious packages were distributed via npm, affecting developers who installed the compromised versions.
Why it matters: Developers using AsyncAPI packages need to identify and update to safe versions immediately, as the compromise could enable code execution in build pipelines and downstream applications.
- threat intel
The serpent’s tongue: Luring the Python out of its den
Python packages are increasingly targeted by threat actors who exploit the trust in the packaging ecosystem to deliver malicious payloads at installation time without user interaction. GitHub's 2025 security data shows a 69% year-over-year increase in malware advisories, with 17% of reviewed advisories related to the Python Package Index (PyPI) ecosystem. The article examines the full lifecycle of Python package installation across hosting, distribution, and installation layers, and recommends defensive measures including dependency auditing, version pinning, and installation-time controls.
Why it matters: Python developers and DevOps teams face elevated supply chain risk when installing third-party packages; practitioners should implement dependency auditing tools and version pinning strategies today to reduce exposure to malicious package injection.
- industry
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer
Valarian, a UK-based cybersecurity firm, has raised $50 million in funding for its ACRA (Sovereign Infrastructure Control Layer) technology, bringing total funding to $70 million. The company is developing infrastructure control solutions for sovereign and critical systems.
Why it matters: Organizations managing critical infrastructure and government entities evaluating control layer technologies should monitor Valarian's progress and product maturity as it scales operations with increased capital.
- industry
Introducing the Silent Push Partner Program
Silent Push has launched an official Channel Partner Program and dedicated partner portal to scale its threat intelligence platform across distributors, MSSPs, systems integrators, and resellers. The company offers partners branded assets, collateral, and enablement resources to market its Indicators of Future Attack (IOFA) technology, which provides visibility into adversary infrastructure before weaponization. The program formalizes existing partnerships across EMEA, APJ, and other regions, with new partner onboarding and training content planned for the coming weeks.
Why it matters: Practitioners evaluating threat intelligence vendors should assess whether Silent Push's partner ecosystem and go-to-market strategy align with their procurement process, and resellers need clarity on program benefits and competitive positioning for client engagements.
- threat intel
Multiple Jscrambler Packages Impacted by Supply Chain Attack
A threat actor compromised multiple Jscrambler packages on NPM and injected malicious code designed to steal credentials across platforms. The attack represents a supply chain compromise affecting developers who downloaded the poisoned package versions.
Why it matters: Developers using affected Jscrambler versions face credential theft and potential account compromise; verify your package versions and audit for unauthorized access to development systems and secrets.
- cloud saas
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI's Grok Build coding CLI tool was uploading complete Git repositories, including full commit history, to xAI's Google Cloud Storage infrastructure rather than only the specific files needed for a task. A researcher discovered this behavior while testing version 0.2.93 and was able to recover files from an intercepted upload that the agent had been instructed not to access.
Why it matters: Development teams using Grok Build may unknowingly expose proprietary code, secrets in commit history, and private repositories to xAI's infrastructure, creating data leakage and compliance risks that require immediate review of usage and uploaded content.
- threat intel
The Jalisco Toolkit and AI-Powered Phishing Surge
ReliaQuest identified two phishing toolkits, Jalisco and OmegaLord, actively exploited in campaigns targeting Microsoft 365 environments. Jalisco provisions fresh OAuth codes in real time to defeat time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multi-factor authentication (MFA). The discovery reflects a broader trend of AI-powered phishing-as-a-service (PhaaS) kits lowering the barrier for attackers to conduct sophisticated campaigns that bypass MFA and establish persistence in cloud environments.
Why it matters: Microsoft 365 defenders must immediately review device code authentication settings and disable the feature via Conditional Access policies, since these toolkits enable attackers to compromise accounts and exfiltrate SaaS data for extortion without exposing user credentials or triggering MFA.
- vulnerabilities
Rapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle East
Rapid7 announced a strategic distribution partnership with Mindware to expand its cybersecurity platform presence across the Middle East. The partnership aims to help regional organizations address complex security challenges by combining Rapid7's AI-powered security operations platform with Mindware's local expertise and partner ecosystem. The collaboration focuses on simplifying security operations and enabling partners to deliver managed services tailored to regional customer needs.
Why it matters: Security teams and managed service providers in the Middle East gain access to a unified platform and local support infrastructure to modernize their cybersecurity operations and reduce operational complexity.
- threat intel
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
Researchers at JFrog discovered 148 malicious npm packages disguised as student web proxies that redirected visitors' browsers into a DDoS botnet during May. The campaign targeted end users visiting the proxy sites rather than the developers who installed the packages, leveraging npm's registry as free hosting for the malicious infrastructure.
Why it matters: Developers relying on npm packages must validate package legitimacy and watch for supply chain attacks that abuse trusted registries; organizations should monitor outbound traffic from developer machines for unexpected botnet activity.
- regulatory
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
The Pentagon has suspended the second phase of the Cybersecurity Maturity Model Certification (CMMC) program and established a task force to conduct a comprehensive review of contractor cybersecurity requirements. The decision indicates the defense department is reconsidering its approach to the certification framework.
Why it matters: Defense contractors and their suppliers must monitor this pause, as CMMC requirements affect their compliance obligations and ability to bid on government contracts; a reformed program may change current implementation timelines and assessment standards.
- threat intel
New tutorials on underground hacking forums have roughly doubled
Radware analyzed 8,870 tutorial posts across 24 deep- and dark-web forums from December 2022 through April 2026, identifying 3,034 unique hacking and fraud guides. Original tutorials have roughly doubled on these forums, with increasing focus on financial fraud techniques including carding and cash-out methods.
Why it matters: Fraud and financial crime teams should monitor escalating criminal knowledge-sharing on underground forums, as more accessible tutorials on payment card theft and money laundering lower the barrier to entry for would-be fraudsters.
- breaches incidents
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Microsoft researchers documented a year-long campaign in which attackers associated with ShinyHunters exploited trusted OAuth connections to Salesforce environments rather than targeting platform vulnerabilities. The attackers leveraged existing integrations between Salesforce and third-party applications to gain unauthorized access to corporate data across multiple attack paths.
Why it matters: Security teams managing Salesforce deployments need to audit OAuth permissions and third-party integrations immediately, as this technique bypasses traditional patch-based defenses and targets the trust relationships already in place.
- ai security
The best defense against AI attacks turns out to be a skeptical human
A SANS survey of 536 IT and security professionals found that 78% of practitioners now use generative AI in daily security work, up from 50% the previous year. However, reliability has not kept pace with adoption, with 63% reporting significant shortcomings in AI detection and response capabilities.
Why it matters: Security teams relying on AI for log analysis and incident response need to maintain skeptical oversight and validation, as AI tools show substantial gaps in accuracy and reliability that could miss genuine threats or produce poor guidance.
- research
Fake smart home residents could stand in for real ones in security research
Researchers are developing synthetic smart home usage data to supplement real-world recordings for security testing, potentially accelerating research by reducing the need for costly, invasive monitoring of actual homes. The approach creates artificial resident profiles and behaviors to generate larger and more diverse datasets that reflect varied household patterns.
Why it matters: Security practitioners evaluating smart home device risks benefit from accelerated research into device behavior under diverse conditions, enabling better understanding of attack surfaces and normal baseline activity for anomaly detection.
- threat intel
Your vendor’s vendor might be the real breach risk
A Field CTO from Zero Networks explains how breaches at vendors' subcontractors can compromise your organization through credentials and access tokens you never directly vetted. Attackers now target third-party vendors' vendors as an entry point into downstream customers' systems, leveraging trust relationships and access permissions that extend beyond direct vendor relationships.
Why it matters: Security practitioners need to assess and monitor the full supply chain of vendors and subcontractors, as compromised credentials at unknown third parties can grant attackers direct access to your environment.
- cloud saas
Chatto: Open-source team messenger with privacy at its core
Chatto is an open-source team messaging application that enables organizations to host their own chat infrastructure rather than using commercial platforms. The software aims to provide privacy and control by keeping message data on operator-controlled infrastructure, with installation simplified through a single executable binary.
Why it matters: Security practitioners managing teams with data residency or privacy requirements can evaluate Chatto as a self-hosted alternative to evaluate against their organizational policies and infrastructure capabilities.
Cybersecurity jobs available right now: July 14, 2026
A job listing aggregation post highlights open cybersecurity positions, including a Cyber Network Engineer role at Fiserv focused on enterprise network security architecture across on-premises and cloud environments. The position involves designing network governance, assessing security risks, and collaborating with infrastructure teams to integrate security controls.
Why it matters: Job seekers and talent managers need awareness of current hiring demand and role requirements in the cybersecurity market; HR and staffing teams benefit from visibility into competitor compensation and role focus areas.
- threat intel
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
The FBI warned in March 2026 about a fast-growing scam where criminals impersonate city and county planning departments to collect fraudulent permit fees from property owners via wire transfer. Because victims authorize these payments themselves, behavioral fraud detection systems fail to flag them as suspicious, making the beneficiary accounts used by scammers the key signal for detection. Research into one active ring, called Diligent Planner, identified 53 verified mule accounts across 23 campaigns, with direct engagement of scam operations proving more effective than automated risk scoring.
Why it matters: Payment processors, banks, and financial institutions need to shift focus from sender behavior to beneficiary account intelligence to block these scams, since authorized customer payments bypass standard fraud controls; government impersonation losses nearly doubled year over year to roughly $798 million.
- breaches incidents
KlueセキュリティインシデントとRecorded Futureへの影響
Recorded Future experienced an incident on June 12-13, 2026, affecting its Salesforce account through a compromised OAuth token in an integration layer between Salesforce and Klue, a third-party marketing vendor. The breach did not target Recorded Future directly; rather, the company was incidentally exposed when attackers exploited the Klue-Salesforce integration. The exposed data was limited to business contact information and customer names stored in the Salesforce database, while Recorded Future's core platform, Intelligence Graph, and internal systems remained unaffected.
Why it matters: Recorded Future customers and partners should review their own exposure to the Klue ecosystem and monitor for phishing or spam; organizations integrating SaaS platforms should evaluate third-party integration security as part of overall SaaS security posture management.