Threat Brief — 2026-07-23 — KEV catalog fills, GitHub runners weaponised
Executive summary: CISA's KEV catalog gained two actively exploited vulnerabilities today — a SharePoint deserialization RCE (CVE-2026-50522KEV) and a Check Point SmartConsole authentication bypass (CVE-2026-16232KEV) — both demanding immediate patch prioritisation. Separately, attackers are repurposing compromised GitHub repositories as distributed attack infrastructure against cPanel/WHM servers, a campaign that abuses CI/CD trust for broad scanning. On the identity front, researchers warn synthetic identity fraud is expanding from human targets to machine identities, a shift that traditional identity-theft controls won't catch.
Top items
- SharePoint deserialization RCE (CVE-2026-50522KEV) formally added to CISA KEV. This is the third SharePoint zero-day in a month; the KEV listing confirms active exploitation. Microsoft SharePoint servers with exposed management interfaces are at risk of unauthenticated remote code execution via deserialization of untrusted data. Patch immediately or isolate from external access. (src: CISA:KEV)
- Check Point SmartConsole improper authentication (CVE-2026-16232KEV) confirmed in KEV catalog. Unauthenticated remote attackers can obtain and abuse application login tokens. This KEV entry formalises the alert CISA first flagged on 2026-07-22; Check Point appliances should already be patched, but verify. (src: CISA:KEV)
- GitHub Actions runners weaponised for large-scale cPanel/WHM attacks. Compromised repositories are being turned into distributed scanning and exploitation infrastructure targeting cPanel and WebHost Manager instances. If your organisation uses GitHub Actions, audit runner configurations and repository access for signs of compromise; if you run cPanel/WHM, ensure admin interfaces are not internet-exposed. (src: The Hacker News)
- Synthetic identity fraud expanding to machine identities. Attackers are manufacturing fictitious identities — rather than stealing real ones — to compromise service accounts, API keys, and other non-human credentials. Conventional identity-theft detection (watching for misuse of known PII) will miss these fabricated identities. Review machine-identity lifecycle controls and anomaly baselines. (src: The Hacker News)
- Google introduces selfie-video account recovery. Users locked out of their accounts can now record a short selfie video to regain access, adding a new recovery vector on top of existing methods. Security implications of biometric-based account recovery remain under debate; monitor for abuse patterns. (src: The Hacker News)
Themes
KEV momentum: Two KEV additions in a single day continues a pattern of rapid catalog growth this week, consistent with the Linux kernel team's 432-CVE dump and multiple zero-day disclosures. Prioritise patching anything that lands in KEV — attackers are moving fast from disclosure to exploitation.
Infrastructure trust abuse: The GitHub Actions campaign mirrors broader trends this week (AI sandbox escapes, Azure DevOps MCP hijacking) where legitimate developer tooling is being subverted as attack infrastructure. Treat CI/CD runners and agent integrations as untrusted attack surface.
===
