vulnerability Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft released its July 2026 security update, containing 622 vulnerabilities, with 57 classified as critical. Several of these, including those affecting Active Directory Federation Services, SharePoint Server, and v… Cisco Talos · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50370vulnerabilityrceeop
threat-intel Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Microsoft released its largest Patch Tuesday update to date, encompassing 622 security updates, with two of these fixes already being actively exploited by attackers. These vulnerabilities, affecting SharePoint Server an… The Hacker News · Jul 14, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-50661zero-dayprivilege escalationremote code execution
vulnerability Microsoft Patches a Record 570 Security Flaws Microsoft released a record 570 security updates for its Windows operating systems and other software, nearly triple the number from last month's Patch Tuesday. The surge in updates is largely due to the increasing use o… Krebs on Security · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayzero-dayvulnerability
vulnerability Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th) Microsoft's July Patch Tuesday release includes a massive 622 vulnerabilities, with a significant number already exploited. Many of these vulnerabilities affect products like Edge and SharePoint, and a notable one – a B… SANS Internet Storm Center · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayvulnerabilitymicrosoft
vulnerability Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Microsoft released a record-breaking 622 security patches this Patch Tuesday, including two actively exploited zero-day vulnerabilities in Active Directory and SharePoint Server. These flaws allow attackers to escalate p… SecurityWeek · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661zero-daypatch tuesdayvulnerability
threat-intel ClickFix's Mushrooming Ecosystem Demands New Defense Tactics ClickFix, initially a social engineering attack vector, has evolved into a sophisticated malware-as-a-service (MaaS) ecosystem, outpacing traditional security defenses. Attackers are now utilizing a range of malware, inc… Dark Reading · Jul 14, 2026 High social engineeringmalware-as-a-serviceyara
threat-intel 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers have discovered 11 outdated, Microsoft-signed UEFI shim bootloaders that could be exploited to bypass Secure Boot on systems relying on these shims. These bootloaders, primarily from versions 0.7 and earlier,… The Hacker News · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797FIuefisecure bootvulnerability
vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
threat-intel OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Threat actors are exploiting a blind spot in Microsoft Entra ID’s sign-in telemetry by using ‘OAuth client ID spoofing’ to enumerate user accounts and validate stolen credentials without triggering traditional login aler… The Hacker News · Jul 14, 2026 High N/oathspoofingentria id
vulnerability Forgotten UEFI shims undermining Secure Boot Researchers at ESET discovered 11 old, Microsoft-signed UEFI shim bootloaders from 2026-02-16 that could bypass UEFI Secure Boot on most systems. These shims, used by various software packages, allowed attackers to deplo… WeLiveSecurity · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797CVE-2020-10713uefisecure bootrevocation
threat-intel Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths For a year, attackers leveraging the ShinyHunters group gained access to Salesforce environments not through exploiting vulnerabilities, but by exploiting trust placed in connected apps and vendors. They achieved this th… The Hacker News · Jul 14, 2026 High USoathconnected appsvendor compromise
threat-intel 'Yellow Teams' Are Defining the Future of AI Security A growing trend of ‘yellow teams’ – engineering groups building both attack and defense tools – is emerging as a crucial response to the increasing threat of AI-powered cyberattacks. These teams are using advanced AI mod… Dark Reading · Jul 13, 2026 High aicybersecurityvulnerability
threat-intel Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found A popular Chrome and Edge header-editing extension, ModHeader, was found to contain a hidden browsing history collector, despite claims it didn't collect data. Researchers at Stripe OLT discovered the collector was dorma… The Hacker News · Jul 13, 2026 High CNextensiondata-collectionheader-editing
threat-intel GigaWiper Lets Threat Actors Choose Their Own Destructive Attack GigaWiper is a novel, modular malware that combines backdoor and wiper capabilities, allowing attackers to choose how to destroy a targeted system while minimizing their operational footprint. Initially identified as a G… Dark Reading · Jul 13, 2026 High IRRUVEwiperbackdoormodular
threat-intel New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Researchers have developed MemGhost, an automated tool that can plant false memories in AI assistants by sending a single, carefully crafted email. The tool bypasses existing security measures by exploiting the agents' a… The Hacker News · Jul 13, 2026 High CVE-2025-32711aimemory poisoningemail
threat-intel Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft Forg365, a new PhaaS operation, is targeting Microsoft 365 accounts using a sophisticated combination of device code phishing, AitM tactics, and AI-assisted lure creation. The platform allows even inexperienced operators… The Hacker News · Jul 13, 2026 High UNRUphishingaitmdevice code
threat-intel Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 A security firm, Lexfo, uncovered three separate phishing operations targeting Microsoft 365, all leveraging modified versions of the Evilginx proxy. These campaigns utilized a combination of traditional proxying and a n… The Hacker News · Jul 13, 2026 High EGFRNOphishingevilginxdevice-code
threat-intel Europe revives law allowing big tech to scan for CSAM The European Parliament has revived a law allowing big tech companies like Google, Microsoft, and Meta to scan users' messages to detect child sexual abuse material (CSAM). This move, driven by a procedural vote and conc… The Record · Jul 10, 2026 Medium privacyencryptionchild_protection
threat-intel Cybercriminals Flock to Healthcare Businesses as Attacks Surge Cyberattacks on healthcare businesses, including service providers supporting hospitals, have surged dramatically, nearly doubling in the past year and significantly outpacing attacks on hospitals themselves. This trend… Dark Reading · Jul 10, 2026 High USGEransomwarecyberattackhealthcare
threat-intel Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access A threat actor, linked to the O-UNC-066 group (affiliated with The Com/Scattered Spider), is using a sophisticated, operator-controlled phishing kit to trick users into enrolling fake Microsoft Entra passkeys, gaining un… The Hacker News · Jul 10, 2026 High passkeyphishingvishing