Info
2026-07-15 16:32Z · last 24h · 60 findings
· glm-5.2:cloud
Threat Brief — 2026-07-15 — Patch Tsunami Meets Supply-Chain Storm
Executive Summary
Microsoft shipped a record-breaking Patch Tuesday covering 570–622 CVEs, including two zero-days under active attack and one publicly disclosed. Meanwhile, the AsyncAPI npm namespace was compromised to deliver credential-stealing botnet malware, and nearly 300 fake GitHub repos are pushing infostealers—developer supply chains are under coordinated assault. Two actively exploited SonicWall SMA1000 zero-days and CISA-flagged SharePoint flaws round out a high-triage week for edge and collaboration infrastructure.
Top Items
- Microsoft Patch Tuesday (July 2026) — record 570+ CVEs, 3 zero-days. Two zero-days are under active attack; a third is publicly disclosed. Includes critical RCE in DNS Server (CVE-2026-49169, use-after-free over network), Active Directory (CVE-2026-49164, heap overflow RCE), and Copilot command injection (CVE-2026-48561). Microsoft is also blocking updates on some Dell PCs due to shutdown issues. Source: BleepingComputer, The Hacker News
- SonicWall SMA1000 — two zero-days actively exploited. CVE-2026-15409KEV·R and CVE-2026-15410KEV·R; one enables arbitrary command execution. Patches available; SonicWall urges immediate installation. Source: BleepingComputer, The Hacker News
- CISA: SharePoint flaws under active exploitation. Three vulnerabilities targeting internet-exposed on-prem SharePoint Server instances; CISA urging immediate patching. Source: BleepingComputer
- AsyncAPI npm packages infected with credential-stealing malware. Five malicious versions in the
@asyncapinamespace deliver a multi-stage botnet loader / remote access trojan. Reported by OX Security, SafeDep, Socket, StepSecurity. Source: BleepingComputer, The Hacker News
- ~300 fake GitHub repos distributing infostealers. Repos impersonate legitimate software and security projects to push infostealer malware. Source: BleepingComputer
- SAP NetWeaver ABAP — CVSS 9.9 flaw patched. CVE-2026-44747 could expose or modify data; part of SAP's July 2026 security updates. Source: The Hacker News
- Cursor IDE flaws enable dev environment takeover. Opening a repo containing a
git.exein the project root triggers silent execution on Windows with no prompt. A separate "2-click" exploit chain also targets developer secrets and source code. Source: The Hacker News, Dark Reading
- Firefox/Chrome/Adobe/VMware critical patches released. Mozilla warned that exploit code is public for two critical Firefox flaws (CVE-2026-15718 and another in WebAssembly). Source: The Hacker News
- New Windows zero-day PoC dropped post-Patch Tuesday. "LegacyHive" exploits User Profile Service arbitrary hive load for elevation of privileges. Released by researcher "Chaotic Eclipse." Source: The Hacker News
- RabbitMQ — batch of CVEs across multiple protocols. Includes unauthenticated OAuth credential disclosure (CVE-2026-57219), unauthenticated DoS via frame-size bypass (CVE-2026-57220), cross-tenant routing-key bypass (CVE-2026-57217), stored XSS (CVE-2026-57213, CVE-2026-44839), remote guest sessions (CVE-2026-57216), SSRF on Windows (CVE-2026-57211), and reply-channel injection (CVE-2026-57215). Source: MSRC RSS feeds.
- LabubaRAT — Rust-based RAT masquerading as NVIDIA software. Previously undocumented; creates reusable foothold on Windows hosts. Source: The Hacker News
- Claude for Chrome — rogue extensions can trigger Gmail/Calendar reads. Any extension running scripts on claude.ai can invoke Claude for Chrome tasks targeting Gmail, Google Docs, and Calendar. Requires a malicious extension already installed. Source: The Hacker News
- ClickFix ecosystem expanding — evades AV/EDR. Attack vector available for rent at scale; YARA analysis recommended as best detection option. Source: Dark Reading
Themes
- Developer tooling and supply chain under coordinated attack. AsyncAPI npm compromise, 300+ malicious GitHub repos, Cursor IDE auto-execution flaws, and LabubaRAT masquerading as NVIDIA software all target developers and CI/CD pipelines within the same 24-hour window. Treat package registries, cloned repos, and IDE project folders as untrusted by default.
- Patch-backlog pressure. Microsoft's record 570–622-CVE Patch Tuesday, SAP's CVSS 9.9, a RabbitMQ batch (10+ CVEs), Firefox/Chrome/Adobe/VMware updates, and the Windows "LegacyHive" PoC dropped hours after patches—triage queues will be overloaded this week. Prioritize edge-facing systems (SonicWall, SharePoint) where exploitation is confirmed.
- AI tooling surfaces new attack vectors. Copilot command injection (CVE-2026-48561), Claude for Chrome cross-extension abuse, an AI "vulnerability vending machine" generating zero-days, and TuxBot v3 built with LLM assistance all suggest AI-integrated products are rapidly becoming both targets and threat-actor tooling.
