threat-intel Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes Microsoft's July 2026 Patch Tuesday update is the largest in the program's history, containing 622 unique CVEs, including three zero-day vulnerabilities. The sheer volume of updates presents a significant prioritization… Dark Reading · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch-tuesdayzero-dayvulnerability
vulnerability Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft released its July 2026 security update, containing 622 vulnerabilities, with 57 classified as critical. Several of these, including those affecting Active Directory Federation Services, SharePoint Server, and v… Cisco Talos · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50370vulnerabilityrceeop
threat-intel Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Microsoft released its largest Patch Tuesday update to date, encompassing 622 security updates, with two of these fixes already being actively exploited by attackers. These vulnerabilities, affecting SharePoint Server an… The Hacker News · Jul 14, 2026 High CVE-2026-56164CVE-2026-56155CVE-2026-50661zero-dayprivilege escalationremote code execution
vulnerability Microsoft Patches a Record 570 Security Flaws Microsoft released a record 570 security updates for its Windows operating systems and other software, nearly triple the number from last month's Patch Tuesday. The surge in updates is largely due to the increasing use o… Krebs on Security · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayzero-dayvulnerability
vulnerability Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here , (Tue, Jul 14th) Microsoft's July Patch Tuesday release includes a massive 622 vulnerabilities, with a significant number already exploited. Many of these vulnerabilities affect products like Edge and SharePoint, and a notable one – a B… SANS Internet Storm Center · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661patch tuesdayvulnerabilitymicrosoft
vulnerability Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days Microsoft released a record-breaking 622 security patches this Patch Tuesday, including two actively exploited zero-day vulnerabilities in Active Directory and SharePoint Server. These flaws allow attackers to escalate p… SecurityWeek · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50661zero-daypatch tuesdayvulnerability
vulnerability CISA Urges SharePoint Hardening After New Exploitations The Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations with on-premises SharePoint Server instances (versions 2016, 2019, and Subscription Edition) about active exploitation of vulnerabiliti… CISA Advisories · Jul 14, 2026 High CVE-2026-32201CVE-2026-45659CVE-2026-56164sharepointvulnerabilityiis
threat-intel Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft Forg365, a new PhaaS operation, is targeting Microsoft 365 accounts using a sophisticated combination of device code phishing, AitM tactics, and AI-assisted lure creation. The platform allows even inexperienced operators… The Hacker News · Jul 13, 2026 High UNRUphishingaitmdevice code
threat-intel In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops Multiple cybersecurity incidents and threats are unfolding, including a ransomware affiliate pleading guilty in the US, a subscription-based remote access trojan (QuimaRAT) being actively sold on the dark web, and a Cana… SecurityWeek · Jul 10, 2026 High ARCAUSransomwaredata breachremote access trojan
threat-intel "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th) This phishing email campaign uses a clever technique to evade AI-based email security filters. The attacker employs a large, padded HTML attachment containing a credential-stealing page. The padding itself – a massive bl… SANS Internet Storm Center · Jul 10, 2026 High phishingai evasioncontent classification
vulnerability New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure A newly discovered CitrixBleed-like vulnerability (CVE-2026-8451) in NetScaler ADC and Gateways was exploited within 24 hours of its public disclosure. The flaw, stemming from an out-of-bounds read issue in the XML parse… SecurityWeek · Jul 2, 2026 Critical CVE-2026-8451DEHKcitrixbleedsamlmemory disclosure
ransomware SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation A high-severity remote code execution (RCE) vulnerability (CVE-2026-45659) in Microsoft SharePoint Server has been added to the CISA KEV catalog due to active exploitation. This vulnerability, stemming from deserializing… The Hacker News · Jul 2, 2026 High CVE-2026-45659CVE-2025-11371USremote code executionsharepointvulnerability
threat-intel ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos has identified a new phishing-as-a-service (PhaaS) platform called ARToken, which shares significant similarities with the existing EvilTokens platform operated by Sekoia and tracked by Microsoft. ARToken uti… Cisco Talos · Jul 1, 2026 High USphishingeviltokensreact
threat-intel AI-Generated Workflows Are a Silent Security Disaster This article highlights a growing security risk stemming from the use of AI-generated workflows within Microsoft 365 environments. Developers and users are leveraging AI assistants to automate tasks like document approva… Dark Reading · Jun 30, 2026 Medium aiautomationpermissions
malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader
threat-intel Salesforce Data Thefts Continue via Klue App Compromise A series of data thefts targeting Salesforce instances have been linked to a new threat actor group, Icarus, following a compromise of Klue's Battlecards app. The attacks leveraged compromised OAuth tokens and Python scr… Dark Reading · Jun 18, 2026 High USoauthsaasdata exfiltration
threat-intel 5 reasons Microsoft 365 backup isn’t enough for business data protection This article highlights the limitations of relying solely on Microsoft 365’s built-in backup and retention policies for business data protection. It argues that organizations need a third-party solution to adequately add… BleepingComputer · Jun 18, 2026 High ransomwarebackupdata protection
threat-intel EvilTokens: A phishing attack that doesn’t steal your password EvilTokens is a sophisticated phishing-as-a-service (PaaS) kit that bypasses traditional phishing defenses by leveraging the OAuth 2.0 device authorization grant flow. Attackers use convincing lures – often mimicking leg… WeLiveSecurity · Jun 15, 2026 High phishingoath2device-code
vulnerability Microsoft Issues Out-of-Band SharePoint Patch Microsoft has released an out-of-band security patch to address a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. The flaw allows authenticated attackers to execute code without elevat… Dark Reading · May 26, 2026 Critical CVE-2026-45659CHremote code executionsharepointzero-day