Info
2026-07-15 06:06Z · last 24h · 60 findings
· glm-5.2:cloud
Threat Brief — 2026-07-15 | Record Patch Wave, Active Zero-Days
Executive Summary
July 2026 Patch Tuesday is the largest on record, with Microsoft fixing 570–622 vulnerabilities including three zero-days—two under active exploitation and one publicly disclosed. Separately, SonicWall SMA1000 and Progress ShareFile zero-days are being exploited in the wild and require immediate patching. The supply-chain front remains hot: ~300 malicious GitHub repos impersonating legitimate projects, 148 npm packages forming a DDoS botnet, and Cursor IDE auto-executing code from poisoned repositories.
Top Items
- Microsoft July 2026 Patch Tuesday (record 570–622 CVEs, 3 zero-days) — Two zero-days are under active attack and one is publicly disclosed; 60+ critical vulnerabilities span Windows DNS RCE (CVE-2026-49169), Active Directory RCE (CVE-2026-49164), Bluetooth Port Driver RCE (CVE-2026-42975), SQL Server ODBC RCE (CVE-2026-42990), and Microsoft Copilot command injection (CVE-2026-48561). Triage the zero-days and network-reachable criticals first. (BleepingComputer) (Krebs) (The Hacker News)
- SonicWall SMA1000 zero-days actively exploited (CVE-2026-15409KEV·R, CVE-2026-15410KEV·R) — Threat actors are exploiting two SMA1000 vulnerabilities in the wild; SonicWall has released patches. If you run SMA1000 appliances, treat this as emergency patching. (BleepingComputer)
- Progress ShareFile zero-day forces Storage Zone shutdown — A high-severity zero-day in ShareFile Storage Zone Controllers triggered an emergency shutdown last week; Progress has now shipped patches. Validate your Storage Zone posture before re-enabling. (BleepingComputer)
- SAP NetWeaver ABAP CVSS 9.9 (CVE-2026-44747) — SAP's July 2026 cycle fixes 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter; the NetWeaver ABAP flaw could expose or modify data. Prioritise ERP-facing systems. (The Hacker News) (BleepingComputer)
- ~300 malicious GitHub repos distributing infostealers — A threat actor published hundreds of repositories impersonating legitimate software and security projects to push infostealer malware. Review allow-lists for developer tools sourced from GitHub. (BleepingComputer)
- OAuth client ID spoofing validates stolen Microsoft Entra credentials — At least two threat actors are using a novel evasion technique to enumerate accounts and validate stolen Entra ID credentials while evading telemetry. Relevant to any org using Entra ID / OAuth flows. (The Hacker News)
- New M365 phishing kits (Jalisco, OmegaLord) evade MFA — Two kits targeting Microsoft 365 accounts use techniques that defeat multi-factor authentication. Reinforce conditional access and phishing-resistant factors (passkeys, FIDO2). (BleepingComputer)
- Cursor IDE auto-executes malicious code from poisoned repos — A vulnerability reported to Cursor in December remains unpatched; opening a poisoned repository can trigger automatic code execution. Caution anyone using Cursor in CI or dev environments. (Dark Reading)
- 148 npm packages disguised as student proxies formed DDoS botnet — Malicious npm packages turned visitors' browsers into a DDoS botnet for ~two weeks in May. Audit npm dependency manifests for suspicious proxy-themed packages. (The Hacker News)
- LabubaRAT masquerades as NVIDIA software — A new Rust-based RAT impersonates NVIDIA software to establish persistent footholds on Windows hosts. Update EDR signatures and monitor for bogus NVIDIA binaries. (The Hacker News)
- 11 old Microsoft-signed Linux UEFI shims bypass Secure Boot — Vulnerable signed EFI applications can be abused to bypass Secure Boot on most modern systems. Relevant for endpoint hardening and secure-boot enforcement policies. (The Hacker News)
- Claude for Chrome flaw allows rogue extensions to trigger Gmail/Calendar reads — Any browser extension running scripts on claude.ai can invoke Claude for Chrome tasks against Gmail, Google Docs, and Calendar. Review extension allow-lists. (The Hacker News)
- Grok Build CLI uploads entire Git repositories to xAI storage — xAI's coding CLI was found uploading full repo histories to a Google Cloud Storage bucket, not just needed files. Risky for any repositories containing secrets or proprietary code. (The Hacker News)
Themes
- Patch deluge & triage strain: Microsoft's record-breaking release arrives alongside urgently patched zero-days from SonicWall, SAP, and Progress—making prioritisation harder than usual. Network-reachable RCEs (DNS, AD, Bluetooth, SQL Server ODBC) and the Copilot command injection deserve top triage slots.
- Supply-chain & developer-tool attacks: Fake GitHub repos, npm botnet packages, Cursor IDE auto-execution, and Grok Build's full-repo exfiltration all target developer trust. A unified developer-security review—dependency auditing, IDE hardening, and AI-coding-tool data-handling policies—is overdue.
- Identity & cloud compromise: OAuth client ID spoofing for Entra ID, MFA-evading M365 phishing kits, ShinyHunters' Salesforce data theft via trusted access, and Microsoft's September passkey default rollout all point to identity as the primary battleground. Phishing-resistant authentication is the consistent defensive recommendation.
