2026-07-14
Population: stories the tracker first saw on this Coordinated Universal Time (UTC) calendar day; publisher date is used only if first-tracked time is unavailable and remains on each item.
- vulnerabilities
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
Microsoft released patches for 622 CVEs this week, including three zero-day vulnerabilities and over 60 critical issues.
Why it matters: Security teams must prioritize patching critical and zero-day CVEs immediately to prevent exploitation of unpatched systems in their environments.
- government policy
White House details ‘Gold Eagle’ clearinghouse for AI cyber threats
The Trump administration launched Gold Eagle, a federal clearinghouse managed by the Treasury Department to share artificial intelligence (AI) cyber threat information between government agencies and the private sector. The initiative, created through executive order in June 2026, aims to identify and patch software vulnerabilities using AI tools before malicious actors can exploit them, and is already collecting intelligence on discovered weaknesses. The clearinghouse involves contributions from the Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security, Department of Defense, open-source software providers, and critical infrastructure operators.
Why it matters: Organizations relying on open-source software and critical infrastructure operators should monitor Gold Eagle's vulnerability intelligence and patching priorities, as the initiative is designed to accelerate remediation of flaws discovered through AI scanning before public exploitation occurs.
- ransomware
Spanish Police take down €140 million cyber fraud ring, arrest four
Spanish police dismantled a cybercrime organization responsible for approximately 140 million euros in losses through investment fraud and business email compromise attacks. The operation resulted in four arrests and targeted money-laundering infrastructure used to conceal criminal proceeds.
Why it matters: Finance and business email users are targets of organized fraud rings that launder proceeds through complex networks; understanding takedown operations helps practitioners recognize and defend against BEC and investment fraud tactics.
- vulnerabilitiesCVE-2026-27690CVE-2026-44747
Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record
Microsoft disclosed 622 vulnerabilities during July 2026 Patch Tuesday, more than triple the previous month's record of 206 and reflecting an exponential surge driven by artificial intelligence tools discovering defects at scale. Two actively exploited zero-day vulnerabilities in Active Directory Federation Services and SharePoint Server were included among the batch, with 63 rated as critical. The pace suggests Microsoft will exceed 2,000 or more Common Vulnerabilities and Exposures (CVEs) for the calendar year, far surpassing historical annual records.
Why it matters: All organizations running Microsoft products must prioritize patch assessment and deployment given the record volume; the presence of two actively exploited zero-days in widely deployed authentication and collaboration systems demands immediate attention to those specific fixes.
- vulnerabilities
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
Automated Frequency Coordination (AFC) systems used in 6 GHz Wi-Fi implementations trust client-provided location data by default, creating an attack surface for location spoofing and potential disruption of wireless traffic. Security researchers have identified this design flaw as a vulnerability in the coordination mechanism that determines spectrum access permissions.
Why it matters: Network administrators and operators managing 6 GHz deployments face immediate risk of spectrum interference attacks that could degrade or block critical wireless communications; patching or reconfiguring AFC systems to validate location data server-side is now a priority.
- government policy
US unseals indictment against alleged operators of Russian bulletproof hosting service
The U.S. Department of Justice unsealed an indictment against alleged operators of a Russian hosting service that prosecutors claim provided infrastructure and technical support to cybercriminals. Media Land and its sister company ML Cloud, both based in St. Petersburg, are at the center of the allegations.
Why it matters: Practitioners managing incident response or threat hunting should monitor this case as it targets bulletproof hosting providers that enable ransomware, malware distribution, and other attacks; takedowns of such infrastructure disrupt attacker operations.
- threat intel
Nearly 300 GitHub repos pose as legit software to push malware
A threat actor created hundreds of fake GitHub repositories that impersonate legitimate software and security projects to distribute infostealer malware. These repositories are designed to deceive developers searching for authentic tools and libraries.
Why it matters: Developers using GitHub face risks of downloading malware-laden imposters instead of genuine dependencies, potentially compromising their systems and development environments. Organizations should implement artifact verification and dependency scanning to prevent supply chain compromise.
- vulnerabilities
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft released patches for 622 vulnerabilities in its monthly update, a record number. Two zero-day flaws in Active Directory and SharePoint Server have been exploited in the wild, and a BitLocker vulnerability was publicly disclosed before patching.
Why it matters: Organizations using Active Directory and SharePoint Server must prioritize patching the exploited zero-days immediately, while BitLocker users face public exploit code availability.
- vulnerabilitiesCVE-2026-48561CVE-2026-50661
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft released Windows 10 KB5099539, an extended security update containing July 2026 Patch Tuesday fixes for 570 vulnerabilities and additional security patches. This update addresses a substantial volume of identified flaws across the Windows 10 platform.
Why it matters: Organizations running Windows 10 should deploy this update to remediate 570 known vulnerabilities that could be exploited by attackers.
- ransomware
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
The D1R cybercrime group claimed to have stolen data from Synopsys and Bosch and threatened to leak it unless paid a ransom. Synopsys investigated the claim and found no evidence supporting a data breach at the company.
Why it matters: Security teams at Synopsys and Bosch need to assess whether ransom threats are credible or extortion attempts, and practitioners should monitor for any actual data releases that would indicate real compromise.
- vulnerabilitiesCVE-2026-48564CVE-2026-49796
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft released security patches on July Patch Tuesday addressing 570 vulnerabilities, including three zero-day flaws: two that were actively exploited in attacks and one previously disclosed to the public. This represents a significant volume of fixes across Microsoft's product portfolio.
Why it matters: All organizations running Microsoft products face potential exposure from these flaws, including two actively exploited zero-days; prioritize testing and deploying these patches immediately, starting with systems processing sensitive data.
- regulatory
Manage Vendor Risk in a Few Practical Steps
A brief piece outlines that managing vendor risk requires understanding risk tolerance, gaining visibility into exposures, and obtaining board-level oversight through disciplined governance approaches.
Why it matters: Security teams and risk officers need practical frameworks to govern third-party risk, which affects the security posture of organizations dependent on external vendors.
- vulnerabilities
Windows 11 KB5101650 & KB5099414 cumulative updates released
Microsoft released cumulative updates KB5101650 and KB5099414 for Windows 11 across versions 25H2, 24H2, and 23H2 to address security vulnerabilities, resolve bugs, and introduce new features. These updates maintain the regular patching cadence for the operating system.
Why it matters: Windows 11 administrators and users need to deploy these cumulative updates to remediate disclosed security vulnerabilities and maintain system stability and compatibility.
- vulnerabilitiesCVE-2026-15409CVE-2026-15410
SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
SonicWall has released patches for two actively exploited zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances. The company recommends affected organizations upgrade firmware, search for indicators of compromise, and if found, re-image or re-deploy appliances and reset credentials and multi-factor authentication tokens.
Why it matters: Organizations running SonicWall SMA 1000 Series appliances face active exploitation risk and must patch immediately, then audit for breach evidence and perform credential rotation.
- breaches incidents
Finland issues wanted notice for hacker behind massive psychotherapy data breach
Finnish authorities have issued a wanted notice for a hacker involved in a major psychotherapy data breach. The suspect's legal representative indicated the defendant's whereabouts are unknown but likely outside Finland.
Why it matters: Organizations handling psychotherapy records and practitioners subject to data protection laws should track this case as it demonstrates cross-border enforcement challenges and potential regulatory scrutiny of health data security.
- breaches incidents
Doxbin admin jailed for egging on swatters from behind a screen
A 26-year-old Welsh administrator of Doxbin, a dark web platform for sharing personally identifiable information, was sentenced to prison for facilitating swatting attacks across the UK, US, and Canada. Dare used his administrative position to encourage harassment and coordinate attacks on targets. His conviction addresses criminal activity that endangered victims through coordinated swatting incidents.
Why it matters: Security practitioners and law enforcement should track this outcome as it demonstrates prosecution of dark web infrastructure operators who facilitate harassment and swatting campaigns, helping establish legal precedent for attacking platform administrators rather than just individual attackers.
- vulnerabilities
Adobe Patches Critical ColdFusion Vulnerabilities
Adobe released patches for critical vulnerabilities in ColdFusion that could enable remote code execution and privilege escalation. The flaws pose significant risk to organizations running vulnerable versions of the application server.
Why it matters: ColdFusion administrators and organizations relying on the platform should apply patches immediately to prevent attackers from executing arbitrary code or gaining elevated access to systems.
- threat intel
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
Security researchers identified LabubaRAT, a previously undocumented remote access trojan written in Rust that impersonates NVIDIA software to avoid detection on Windows systems. The malware establishes persistence and can profile compromised hosts for follow-on attacks.
Why it matters: Windows administrators and security teams need to monitor for suspicious processes spoofing NVIDIA software, as this RAT enables attackers to maintain persistent access for reconnaissance and lateral movement.
Upcoming Speaking Engagements
- vulnerabilities
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
Progress Software confirmed that a high-severity zero-day vulnerability prompted the emergency shutdown of ShareFile Storage Zone Controllers. The company released security updates to address the flaw.
Why it matters: Organizations operating ShareFile Storage Zone Controllers face active exploitation risk and must deploy available patches immediately to prevent unauthorized access or data exposure.
- ai security
Frontier AI: The Genie's Out of the Bottle, But Where's the Rulebook?
Advanced artificial intelligence (AI) systems are being rolled out with greater autonomy and reduced human supervision. Several United States (U.S.) state governments are introducing legislation to require transparency about how these models are used. The developments highlight growing pressure to balance innovation with oversight.
Why it matters: Security teams in organizations deploying autonomous AI models must review upcoming state transparency requirements to avoid compliance gaps.
- threat intel
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
ClickFix malware is becoming available as a rental service, capable of bypassing traditional antivirus and endpoint detection and response tools, with YARA rule-based detection representing the most viable current mitigation approach.
Why it matters: Security teams defending against ClickFix need to shift detection strategies immediately, as conventional AV and EDR defenses are ineffective and YARA analysis must become a primary detection method.
- threat intel
LastPass, Bitwarden users targeted with fake security alerts
LastPass has issued a warning about a phishing campaign that tricks users with fake security notices and directs them to fraudulent websites. The campaign exploits users' trust in the password manager to capture credentials or sensitive information. This reflects an ongoing trend of attackers impersonating legitimate security vendors to harvest user data.
Why it matters: LastPass and Bitwarden users are at immediate risk of credential theft; practitioners should alert users to verify security notices directly through official channels and never click links in unsolicited messages.
- threat intel
Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says
Iran exploited known vulnerabilities in cellular networks to locate U.S. military personnel in the Middle East during the early phases of conflict. The technique leveraged existing weaknesses in mobile network infrastructure rather than targeting individual devices or accounts.
Why it matters: Military and defense personnel worldwide should understand that commercial mobile networks expose location data through known flaws; telecom operators and IT security teams need to prioritize patching network vulnerabilities and implementing geofencing controls.
- breaches incidents
Telegram’s shortlink domain is back online after day-long suspension
Telegram experienced a brief outage affecting its shortlink domain, which prevented users from accessing links to the messaging app. CEO Pavel Durov acknowledged the disruption on social media, confirming that shortlinks had stopped functioning.
Why it matters: Users relying on Telegram shortlinks for onboarding or sharing experienced access friction; practitioners managing Telegram infrastructure or integrations should monitor for similar service availability issues.
- vulnerabilities
You Don't Have to Run an Exploit to Know If You're Vulnerable
Organizations can validate vulnerability exploitability by testing the attack techniques and tactics (TTPs) that an exploit depends on, rather than running the exploit itself. This approach allows security teams to assess risk on critical systems where live exploit testing would be unsafe or impossible. Picus describes how TTP chaining enables this validation without direct exploitation.
Why it matters: Security practitioners managing critical infrastructure or systems without available exploits need safe methods to determine which vulnerabilities pose actual risk to their environment before allocating remediation resources.
- vulnerabilities
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
VMware patched seven severe vulnerabilities in Avi Load Balancer that could enable authentication bypass, remote code execution, privilege escalation, and directory traversal. The specific CVE numbers, affected versions, and remediation details were not provided in the available information.
Why it matters: Organizations running VMware Avi Load Balancer should prioritize patching these critical flaws to prevent unauthorized access, code execution, and privilege escalation in a security-critical network component.
- threat intel
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence has disclosed that Russian agencies are compromising internet-connected cameras across Europe to conduct surveillance on military logistics operations and Ukrainian troops. The campaign targets networked cameras to gather intelligence on NATO and Ukrainian military activities.
Why it matters: NATO members, Ukrainian forces, and any organization with internet-facing cameras in Europe face active surveillance targeting military and logistics operations; practitioners should audit camera access controls and network segmentation immediately.
- vulnerabilities
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Researchers disclosed two access control vulnerabilities in RabbitMQ that could leak OAuth client secrets and expose cross-tenant queue metadata. These flaws enable attackers to bypass tenant isolation boundaries and compromise enterprise messaging infrastructure. Miggo's security team discovered and reported the issues to the vendor.
Why it matters: Organizations using RabbitMQ in multi-tenant environments face risks of credential exposure and lateral movement across tenant boundaries if these vulnerabilities remain unpatched.
- research
Download: The ultimate guide to network operations management
A downloadable guide discusses challenges in modern network operations management, highlighting manual processes, growing complexity, and operational inefficiencies. The resource explores how intelligent workflows can reduce manual work, improve visibility, and accelerate response across network operations teams.
Why it matters: IT and security teams managing large networks need practical approaches to reduce operational friction and improve incident response speed.
- vulnerabilities
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
A vulnerability in Claude for Chrome remains unpatched across eight updates, allowing malicious extensions to access sensitive user data including Gmail and Calendar contents. The flaw appears related to ClaudeBleed, a class of vulnerabilities affecting how the extension isolates data from other browser extensions.
Why it matters: Users of Claude for Chrome face exposure of email and calendar data to any malicious extension installed in their browser; organizations should evaluate whether to restrict or disable the extension until a proper fix is released.
- vulnerabilities
Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
Security researchers disclosed a vulnerability in Cursor IDE that allows malicious code to execute automatically when opening compromised repositories. The flaw was reported in December, but the platform has not yet patched the issue, leaving users exposed to poisoned repository attacks.
Why it matters: Developers using Cursor are at risk of arbitrary code execution when cloning or opening repositories, potentially compromising their systems and credentials; practitioners should evaluate whether they or their teams use this IDE and consider restricting repository access or disabling auto-execution features.
- vulnerabilitiesCVE-2026-55040
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Rapid7 Labs disclosed CVE-2026-55040, a JWT token validation flaw in Microsoft SharePoint that allows unauthenticated attackers to bypass authentication and assume the identity of any known user. The vulnerability was discovered as part of a Pwn2Own Berlin competition entry and can be chained with a separate remote code execution flaw expected to patch in August 2026. Microsoft assigned the authentication bypass a CVSS v3.1 score of 5.3, though chaining it with RCE creates a critical attack path.
Why it matters: SharePoint administrators and Microsoft 365 operators must prioritize patching this active exploitation vulnerability immediately, as it grants unauthenticated remote access to sensitive collaboration platforms and can be weaponized for full system compromise when combined with secondary vulnerabilities.
- threat intel
New phishing kits target Microsoft 365 accounts, evade MFA
Two phishing kits named Jalisco and OmegaLord have been identified in attacks against Microsoft 365 accounts, employing methods designed to bypass multifactor authentication (MFA). The kits represent an evolution in credential theft tactics that circumvent common security controls.
Why it matters: Organizations using Microsoft 365 are at immediate risk; practitioners should review MFA implementation, user training on phishing indicators, and log monitoring for suspicious authentication attempts to detect compromise early.
- vulnerabilities
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Researchers discovered 11 Microsoft-signed UEFI applications that could allow attackers to bypass Secure Boot and execute arbitrary code during system boot. These vulnerable shims could be leveraged to deploy UEFI (Unified Extensible Firmware Interface) bootkits or other malware on affected systems.
Why it matters: Organizations running Linux on systems with Secure Boot enabled face firmware-level compromise risk; patching or removing these signed applications is critical to prevent bootkit deployment.
- ai security
“Context bombs” can frustrate AI-driven attacks, researchers found
Tracebit researchers demonstrated that context bombs, a defensive application of prompt injection, can effectively disrupt artificial intelligence (AI) agents attempting to compromise environments. The technique uses canaries, or decoy resources and credentials, to detect and block AI-driven attacks rather than hijack the AI agents themselves.
Why it matters: Security teams defending against AI-driven attacks can consider context bombs as an early warning and blocking mechanism, offering a practical defensive layer beyond traditional detection methods.
- vulnerabilitiesCVE-2025-14771CVE-2025-14772
ABB T-MAC Plus
ABB disclosed four critical vulnerabilities in T-MAC Plus version 4.0-24 affecting the web application, including file disclosure, authorization bypass, cross-site scripting, and incorrect authorization flaws with CVSS scores ranging from 8.8 to 9.9. The vendor released T-MAC Plus version 4.0-25 as a fix and recommends customers apply the update immediately. These vulnerabilities could allow authenticated users to exfiltrate sensitive files, perform unauthorized administrative operations, and inject malicious scripts.
Why it matters: Organizations operating ABB T-MAC Plus 4.0-24 in critical manufacturing environments worldwide face immediate risk of data theft and system compromise through authenticated attack vectors; patching to version 4.0-25 is urgent.
- vulnerabilitiesCVE-2026-10577
Rockwell Automation 1715-AENTR EtherNet/IP Adapter
Rockwell Automation issued a critical advisory for CVE-2026-10577 affecting the 1715-AENTR EtherNet/IP Adapter versions 3.003 and earlier. An unauthenticated debug port exposed to the network allows remote attackers to execute CLI commands without privilege checks, enabling file manipulation, task termination, memory modification, and I/O state changes. Rockwell recommends updating to version 3.011 or later.
Why it matters: Organizations deploying 1715-AENTR adapters in energy, water, or manufacturing environments face critical risk of unauthorized remote access and control system compromise; update immediately or isolate affected devices from network access.
- vulnerabilitiesCVE-2026-31431
ABB Ability Edgenius
ABB has released an advisory for CVE-2026-31431, a Linux kernel vulnerability affecting ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 installed on multiple gateway and server models. The flaw allows locally authenticated users or compromised container workloads to escalate privileges to root, potentially granting complete system control. A patch is available in version 3.2.4.1, and ABB recommends immediate application along with access restrictions to SSH and Cockpit.
Why it matters: Organizations deploying ABB Ability Edgenius in critical manufacturing environments must patch immediately, particularly in shared or containerized deployments where local privilege escalation poses elevated risk.
- vulnerabilitiesCVE-2025-13162
ABB Advant Master Online Builder
ABB disclosed a vulnerability in Advant Master Online Builder affecting Control Builder A and 800xA for Advant Master due to improper DLL search path handling that could allow unauthorized code execution. Updates are available with specific version recommendations for affected products across multiple release branches. The issue affects critical manufacturing infrastructure worldwide and carries a CVSS score of 4.4 (Medium severity).
Why it matters: Operators of ABB Advant Master systems in critical manufacturing environments must apply patches or upgrade to unaffected versions to prevent local code execution by authenticated attackers with system access.
- vulnerabilitiesCVE-2026-32201CVE-2026-45659
CISA Urges SharePoint Hardening After New Exploitations
CISA has confirmed active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affecting all supported on-premises versions, with attackers achieving remote code execution and stealing credentials for persistence. The agency identified two additional unpatched vulnerabilities posing risk and published detection signatures for AMSI and Microsoft Defender. CISA recommends immediate patching, enabling AMSI scanning in Full Mode, hardening network exposure, implementing enhanced logging, and hunting for existing compromise artifacts.
Why it matters: Organizations running on-premises SharePoint Server 2016, 2019, or Subscription Edition face active attacks targeting RCE and credential theft; apply patches immediately and verify AMSI configuration to detect ongoing exploitation before attackers establish durable persistence.
- research
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Researchers at KU Leuven analyzed 85 popular cryptocurrency wallet browser extensions and identified privacy vulnerabilities that allow address linking and cross-site tracking. The wallet communication patterns with websites and blockchain servers expose user activity in ways that enable deanonymization and user tracking across sites.
Why it matters: Cryptocurrency users relying on browser-based wallet extensions face privacy leakage that undermines the anonymity properties they expect, making them targets for tracking by advertisers, malicious sites, or adversaries attempting to correlate their on-chain activity.
- vulnerabilitiesCVE-2026-44747
SAP warns of critical flaws in NetWeaver and Commerce Cloud
The vendor released security updates addressing 16 vulnerabilities across multiple products in July 2026, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. The updates cover significant exposure in SAP's enterprise middleware and cloud commerce platforms.
Why it matters: SAP NetWeaver and Commerce Cloud administrators must assess whether critical vulnerabilities affect their deployments and apply patches immediately to prevent exploitation.
- ai security
How Pentera Turns AI Security Workflows into Validation Engines
Pentera uses artificial intelligence security agents to consolidate fragmented risk signals such as scanner outputs, severity scores, and threat intelligence. These agents help teams summarize findings, prioritize remediation, and recommend actions to accelerate decision-making. The approach addresses the challenge of attackers exploiting interconnected vulnerabilities rather than isolated issues.
Why it matters: Security teams using Pentera can reduce decision latency by automating validation of AI-driven risk signals and prioritizing remediation.
- cloud saas
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Security researchers identified threat actors using OAuth client ID spoofing to enumerate and validate stolen credentials against Microsoft Entra ID without triggering sign-in logs. The technique bypasses standard telemetry detection, allowing attackers to confirm compromised credentials while evading defender alerts.
Why it matters: Organizations using Microsoft Entra ID face silent credential validation attacks that circumvent logging and detection; practitioners should review access logs for anomalous OAuth authentication patterns and enforce conditional access policies to mitigate this evasion technique.
- vulnerabilities
Vulnerability in FIFA’s Network
FIFA's network contained a vulnerability that could be exploited by individuals with minimal access levels.
Why it matters: Organizations managing sports infrastructure should audit internal access controls; FIFA's exposure demonstrates how privilege boundaries can fail to prevent lateral movement or unauthorized actions.
- industry
Microsoft starts testing cleaner Windows Search without ads
Microsoft has begun testing a redesigned Windows Search interface that prioritizes search results over advertisements and promotional content, aiming for improved performance and relevance. The updated version is intended to deliver a cleaner user experience with faster query handling.
Why it matters: Windows administrators and users benefit from reduced distraction during system searches, streamlining workflow efficiency and reducing unwanted promotional exposure in a core OS component.
- threat intel
[Video] Where protection starts: Cisco Talos Intelligence Integrations
Cisco Talos Intelligence Integrations apply threat intelligence across Cisco's security and enterprise technologies to identify and block malicious activity. The integrations help security teams answer critical questions about newly registered domains, outbound connections, and unusual user behavior in their environments. A new video introduces the team and explains how these integrations work.
Why it matters: Security teams using Cisco products benefit from automated threat detection that applies the latest intelligence to block attacks more effectively across their infrastructure.
- identity access
Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Google has begun rolling out support for FIDO2 physical security keys and phone passkeys as a second authentication factor for Google Credential Provider for Windows (GCPW) across all Google Workspace customers. GCPW enables Windows login using Google Workspace credentials, and the new capability allows administrators to enforce two-step verification with hardware security keys. The update strengthens account security by providing organizations with stronger multi-factor authentication options for Windows device access.
Why it matters: Google Workspace administrators can now enforce hardware-based multi-factor authentication for Windows login, reducing reliance on passwords and phishing-vulnerable authentication methods for their organization's workforce.
- threat intel
M-Red-Team: AsyncAPI Supply Chain Compromise via GitHub Actions
A supply chain attack targeted AsyncAPI npm packages through compromised GitHub Actions workflows. Malicious packages were distributed via npm, affecting developers who installed the compromised versions.
Why it matters: Developers using AsyncAPI packages need to identify and update to safe versions immediately, as the compromise could enable code execution in build pipelines and downstream applications.
- threat intel
The serpent’s tongue: Luring the Python out of its den
Python packages are increasingly targeted by threat actors who exploit the trust in the packaging ecosystem to deliver malicious payloads at installation time without user interaction. GitHub's 2025 security data shows a 69% year-over-year increase in malware advisories, with 17% of reviewed advisories related to the Python Package Index (PyPI) ecosystem. The article examines the full lifecycle of Python package installation across hosting, distribution, and installation layers, and recommends defensive measures including dependency auditing, version pinning, and installation-time controls.
Why it matters: Python developers and DevOps teams face elevated supply chain risk when installing third-party packages; practitioners should implement dependency auditing tools and version pinning strategies today to reduce exposure to malicious package injection.
- industry
Valarian Raises $50 Million for Sovereign Infrastructure Control Layer
Valarian, a UK-based cybersecurity firm, has raised $50 million in funding for its ACRA (Sovereign Infrastructure Control Layer) technology, bringing total funding to $70 million. The company is developing infrastructure control solutions for sovereign and critical systems.
Why it matters: Organizations managing critical infrastructure and government entities evaluating control layer technologies should monitor Valarian's progress and product maturity as it scales operations with increased capital.
- industry
Introducing the Silent Push Partner Program
Silent Push has launched an official Channel Partner Program and dedicated partner portal to scale its threat intelligence platform across distributors, MSSPs, systems integrators, and resellers. The company offers partners branded assets, collateral, and enablement resources to market its Indicators of Future Attack (IOFA) technology, which provides visibility into adversary infrastructure before weaponization. The program formalizes existing partnerships across EMEA, APJ, and other regions, with new partner onboarding and training content planned for the coming weeks.
Why it matters: Practitioners evaluating threat intelligence vendors should assess whether Silent Push's partner ecosystem and go-to-market strategy align with their procurement process, and resellers need clarity on program benefits and competitive positioning for client engagements.
- threat intel
Multiple Jscrambler Packages Impacted by Supply Chain Attack
A threat actor compromised multiple Jscrambler packages on NPM and injected malicious code designed to steal credentials across platforms. The attack represents a supply chain compromise affecting developers who downloaded the poisoned package versions.
Why it matters: Developers using affected Jscrambler versions face credential theft and potential account compromise; verify your package versions and audit for unauthorized access to development systems and secrets.
- cloud saas
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI's Grok Build coding CLI tool was uploading complete Git repositories, including full commit history, to xAI's Google Cloud Storage infrastructure rather than only the specific files needed for a task. A researcher discovered this behavior while testing version 0.2.93 and was able to recover files from an intercepted upload that the agent had been instructed not to access.
Why it matters: Development teams using Grok Build may unknowingly expose proprietary code, secrets in commit history, and private repositories to xAI's infrastructure, creating data leakage and compliance risks that require immediate review of usage and uploaded content.
- threat intel
The Jalisco Toolkit and AI-Powered Phishing Surge
ReliaQuest researchers identified two phishing toolkits, Jalisco and OmegaLord, actively used in Microsoft 365 attacks. Jalisco generates fresh OAuth codes in real time to bypass time-based security controls, while OmegaLord harvests credentials and phone numbers to intercept multifactor authentication (MFA). These tools reflect a broader shift toward artificial intelligence (AI)-powered phishing-as-a-service kits that lower barriers for attackers of any skill level to conduct sophisticated campaigns.
Why it matters: Organizations using Microsoft 365 face immediate risk from device code phishing and credential theft that can bypass MFA and establish persistent access; practitioners should disable device code authentication in Entra ID via Conditional Access policies and monitor for device enrollment anomalies.
- vulnerabilities
Rapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle East
Rapid7 has announced a strategic distribution partnership with Mindware to expand its presence across the Middle East. The collaboration aims to help organizations in the region address complex security challenges through Rapid7's cybersecurity operations platform combined with Mindware's regional expertise and partner ecosystem. The partnership focuses on delivering unified security operations and reducing operational complexity for customers while enabling partners to grow their managed services offerings.
Why it matters: Organizations across the Middle East seeking to consolidate security tools and improve threat response capabilities now have access to Rapid7's platform through local partners, while solution providers can expand their service offerings and technical capabilities in a high-growth market.
- threat intel
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
Researchers identified 148 npm packages that posed as student web proxies and hijacked visitors browsers to launch a distributed denial of service attack. The campaign operated for about two weeks in May, using the registry as free hosting for the booby trapped site. No developers were targeted directly; instead the packages served as a trap for students seeking to bypass network restrictions.
Why it matters: Developers who install npm packages are affected, as these malicious proxies can turn end users browsers into DDoS bots, so practitioners should review and remove any suspicious packages from their projects.
- regulatory
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
The Pentagon has suspended the second phase of the Cybersecurity Maturity Model Certification (CMMC) program and established a task force to conduct a comprehensive review of contractor cybersecurity requirements. The decision indicates the defense department is reconsidering its approach to the certification framework.
Why it matters: Defense contractors and their suppliers must monitor this pause, as CMMC requirements affect their compliance obligations and ability to bid on government contracts; a reformed program may change current implementation timelines and assessment standards.
- threat intel
New tutorials on underground hacking forums have roughly doubled
Radware analyzed 8,870 tutorial posts across 24 deep- and dark-web forums from December 2022 through April 2026, identifying 3,034 unique hacking and fraud guides. Original tutorials have roughly doubled on these forums, with increasing focus on financial fraud techniques including carding and cash-out methods.
Why it matters: Fraud and financial crime teams should monitor escalating criminal knowledge-sharing on underground forums, as more accessible tutorials on payment card theft and money laundering lower the barrier to entry for would-be fraudsters.
- breaches incidents
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Microsoft researchers documented a year-long campaign in which attackers associated with ShinyHunters exploited trusted OAuth connections to Salesforce environments rather than targeting platform vulnerabilities. The attackers leveraged existing integrations between Salesforce and third-party applications to gain unauthorized access to corporate data across multiple attack paths.
Why it matters: Security teams managing Salesforce deployments need to audit OAuth permissions and third-party integrations immediately, as this technique bypasses traditional patch-based defenses and targets the trust relationships already in place.
- ai security
The best defense against AI attacks turns out to be a skeptical human
Seventy-eight percent of security practitioners now use generative artificial intelligence (AI) in daily work, according to the 2026 SANS AI Survey of 536 IT and security professionals. Adoption nearly doubled from the prior year, though reliability concerns persist, with 63 percent reporting significant shortcomings in AI detection and response capabilities. Human skepticism remains critical to managing AI limitations in security operations.
Why it matters: Security teams relying on AI for log analysis and incident response must validate AI outputs independently; widespread adoption without verification creates blind spots in threat detection and response workflows.
- research
Fake smart home residents could stand in for real ones in security research
Researchers are developing synthetic smart home usage data to supplement real-world recordings for security testing, potentially accelerating research by reducing the need for costly, invasive monitoring of actual homes. The approach creates artificial resident profiles and behaviors to generate larger and more diverse datasets that reflect varied household patterns.
Why it matters: Security practitioners evaluating smart home device risks benefit from accelerated research into device behavior under diverse conditions, enabling better understanding of attack surfaces and normal baseline activity for anomaly detection.
- threat intel
Your vendor’s vendor might be the real breach risk
A Field CTO from Zero Networks explains how breaches at vendors' subcontractors can compromise your organization through credentials and access tokens you never directly vetted. Attackers now target third-party vendors' vendors as an entry point into downstream customers' systems, leveraging trust relationships and access permissions that extend beyond direct vendor relationships.
Why it matters: Security practitioners need to assess and monitor the full supply chain of vendors and subcontractors, as compromised credentials at unknown third parties can grant attackers direct access to your environment.
- cloud saas
Chatto: Open-source team messenger with privacy at its core
Chatto is an open-source team messaging application that enables organizations to host their own chat infrastructure rather than using commercial platforms. The software aims to provide privacy and control by keeping message data on operator-controlled infrastructure, with installation simplified through a single executable binary.
Why it matters: Security practitioners managing teams with data residency or privacy requirements can evaluate Chatto as a self-hosted alternative to evaluate against their organizational policies and infrastructure capabilities.
Cybersecurity jobs available right now: July 14, 2026
A job listing aggregation post highlights open cybersecurity positions, including a Cyber Network Engineer role at Fiserv focused on enterprise network security architecture across on-premises and cloud environments. The position involves designing network governance, assessing security risks, and collaborating with infrastructure teams to integrate security controls.
Why it matters: Job seekers and talent managers need awareness of current hiring demand and role requirements in the cybersecurity market; HR and staffing teams benefit from visibility into competitor compensation and role focus areas.
- ai security
AI Security Report 2026
Check Point Research's 2026 annual report documents a shift in artificial intelligence (AI) use in cyberattacks, moving from development aid to active operator in live intrusions across nation-state and criminal campaigns. AI now generates deployment-ready malware and attack frameworks, with attackers favoring jailbroken commercial models that load persistent bypass configurations across sessions. The report identifies AI-enabled phishing-as-a-service, voice-based vishing attacks, synthetic identity fraud, and indirect prompt injection as operational threats, alongside persistent data leakage risks through generative AI applications in enterprises.
Why it matters: Security teams must assume AI now executes attacks autonomously and builds malware at scale, forcing a shift from detection of AI-assisted tactics to defense against AI-driven operations; Business Services sectors face the highest exposure risk with 5.91% of AI interactions carrying data breach potential, requiring controls on shadow AI usage and prompt input validation.
- threat intel
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
The FBI warned in March 2026 about a fast-growing scam where criminals impersonate city and county planning departments to collect fraudulent permit fees from property owners via wire transfer. Because victims authorize these payments themselves, behavioral fraud detection systems fail to flag them as suspicious, making the beneficiary accounts used by scammers the key signal for detection. Research into one active ring, called Diligent Planner, identified 53 verified mule accounts across 23 campaigns, with direct engagement of scam operations proving more effective than automated risk scoring.
Why it matters: Payment processors, banks, and financial institutions need to shift focus from sender behavior to beneficiary account intelligence to block these scams, since authorized customer payments bypass standard fraud controls; government impersonation losses nearly doubled year over year to roughly $798 million.
- cloud saas
Defending SaaS-based applications against ShinyHunters OAuth abuse
Microsoft identified threat actor activity associated with ShinyHunters targeting Salesforce and other SaaS applications between mid-2025 and mid-2026 through three primary attack vectors: voice phishing to trick users into authorizing malicious OAuth applications, supply chain compromise of trusted integrations like Salesloft and Gainsight, and exploitation of misconfigured guest access. The actors abused legitimate OAuth relationships to enumerate customer relationship management records, exfiltrate data at scale, and maintain persistent access across multiple industries including retail, education, and manufacturing.
Why it matters: Salesforce administrators and SaaS security teams need to immediately review OAuth-connected applications, validate third-party integrations, audit guest access configurations, and enable event monitoring to detect unauthorized application consent and data exfiltration attempts targeting sensitive CRM data.
- breaches incidents
KlueセキュリティインシデントとRecorded Futureへの影響
Recorded Future disclosed that Klue, a third-party marketing vendor, suffered unauthorized access to an integration layer connecting Klue with other SaaS platforms including Salesforce. Recorded Future's Salesforce account was affected through a compromised OAuth token, exposing business data fields such as customer contact names, email addresses, and potentially certain business contract information, though the company's core platform and internal databases were not accessed. Recorded Future has revoked related OAuth tokens, engaged with Salesforce for investigation support, and is monitoring for further anomalous activity.
Why it matters: Recorded Future customers should review potential exposure through the Klue ecosystem and implement standard phishing and spam defenses; organizations using Klue or similar third-party integrations with Salesforce should audit their own OAuth token management and SaaS application access controls.