As cited
Copy frozen at (site build).
vulnerabilities
20th July - Threat Intelligence Report
Ernst and Young disclosed a breach involving a compromised third-party IT support platform exposing client documents and tax information. Supply chain compromises affected the Jscrambler JavaScript package and multiple artificial intelligence tools including Claude Code, DeepSeek, and Grok Build. Microsoft released 622 patches in July including fixes for two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services, while WordPress issued emergency updates for critical remote code execution flaws.
Why it matters: Organizations using EY's support services should investigate whether their data was exposed in the breach. Development teams need to audit projects using Jscrambler versions distributed between the compromise and removal. Security teams must prioritize the two Microsoft vulnerabilities under active exploitation and the WordPress flaws affecting versions 6.9.0 through 7.0.1, which enable unauthenticated remote code execution. Cloud platform users should review AI tool configurations to prevent credential exposure through compromised code assistants.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
20th July - Threat Intelligence Report
Ernst and Young disclosed a breach involving a compromised third-party IT support platform exposing client documents and tax information. Supply chain compromises affected the Jscrambler JavaScript package and multiple artificial intelligence tools including Claude Code, DeepSeek, and Grok Build. Microsoft released 622 patches in July including fixes for two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services, while WordPress issued emergency updates for critical remote code execution flaws.
Why it matters: Organizations using EY's support services should investigate whether their data was exposed in the breach. Development teams need to audit projects using Jscrambler versions distributed between the compromise and removal. Security teams must prioritize the two Microsoft vulnerabilities under active exploitation and the WordPress flaws affecting versions 6.9.0 through 7.0.1, which enable unauthenticated remote code execution. Cloud platform users should review AI tool configurations to prevent credential exposure through compromised code assistants.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
20th July - Threat Intelligence Report
Ernst and Young disclosed a breach involving a compromised third-party IT support platform exposing client documents and tax information. Supply chain compromises affected the Jscrambler JavaScript package and multiple artificial intelligence tools including Claude Code, DeepSeek, and Grok Build. Microsoft released 622 patches in July including fixes for two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services, while WordPress issued emergency updates for critical remote code execution flaws.
Why it matters: Organizations using EY's support services should investigate whether their data was exposed in the breach. Development teams need to audit projects using Jscrambler versions distributed between the compromise and removal. Security teams must prioritize the two Microsoft vulnerabilities under active exploitation and the WordPress flaws affecting versions 6.9.0 through 7.0.1, which enable unauthenticated remote code execution. Cloud platform users should review AI tool configurations to prevent credential exposure through compromised code assistants.
- Source published
- First seen by Cybersecurity Tracker