Show Notes - 2026-07-16
Stories Covered
Today:Microsoft SharePoint Server Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-32201, CVE-2026-45659) [Critical Alerts]SonicWall SMA1000 Zero-Day Chain Exploited Since June 22 (CVE-2026-15409, CVE-2026-15410) [Critical Alerts]Active Directory Federation Services Privilege Escalation (CVE-2026-56155) [Critical Alerts]Oracle E-Business Suite Privilege Management Flaw (CVE-2026-46817) [Critical Alerts]KNX Protocol Authentication Lockout Bypass (CVE-2023-4346) [Critical Alerts]Identity Attacks Overtake Exploits as Top Ransomware Cause [Ransomware & Extortion]Ransomware Groups Use AI to Amplify Extortion Pressure [Ransomware & Extortion]World Leaks Posts Files from India's Kudankulam Nuclear Plant [Ransomware & Extortion]Nightmare Eclipse Drops LegacyHive Windows Zero-Day Hours After Patch Tuesday [Business & Infrastructure Threats]AsyncAPI npm Supply Chain Compromise - Import-Time Payload Delivery [Business & Infrastructure Threats]TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework [Business & Infrastructure Threats]Cursor IDE Arbitrary Code Execution via Malicious Repositories (CVE-2026-26268) [Business & Infrastructure Threats]Spanish Cybercrime Network Takedown: €140M Stolen, 70 Individuals [Business & Infrastructure Threats]Mozilla Firefox - Two Critical Flaws with Public Exploit Code [Vulnerability Disclosures]Google Chrome - 15 Flaws Including Two Critical Use-After-Free Bugs [Vulnerability Disclosures]Adobe ColdFusion - Eight Critical Flaws [Vulnerability Disclosures]Adobe Commerce and Magento - Two Critical Flaws [Vulnerability Disclosures]Adobe Experience Manager - Two Critical Flaws [Vulnerability Disclosures]VMware Avi Load Balancer - Critical Authentication Bypass (CVE-2026-47865) [Vulnerability Disclosures]Forgotten UEFI Shim Bootloaders Expose Secure Boot Blind Spot [Vulnerability Disclosures]Microsoft Cancels Patch Tuesday for Some Dell Users Over Shutdowns and Overheating [Vulnerability Disclosures]OpenAI GPT-Red Automates Prompt Injection Testing [General Security News]Cisco Talos: The Hunter's Paradox - Is It Time to Embrace Automated Threat Hunting? [General Security News]CISA and NSA Publish Coordinated Vulnerability Disclosure Program Guidance [General Security News]UK Steps Up Tech Sovereignty Push Following US AI Export Restrictions [General Security News]Data Breach Incidents [General Security News]CVEs Referenced
CVE-2023-4346, CVE-2026-15409, CVE-2026-15410, CVE-2026-15718, CVE-2026-15719, CVE-2026-15764, CVE-2026-15765, CVE-2026-26268, CVE-2026-32201, CVE-2026-45659, CVE-2026-46817, CVE-2026-47865, CVE-2026-48259, CVE-2026-48284, CVE-2026-48318, CVE-2026-48319, CVE-2026-48321, CVE-2026-48322, CVE-2026-48324, CVE-2026-48325, CVE-2026-48327, CVE-2026-48356, CVE-2026-48358, CVE-2026-48359, CVE-2026-55040, CVE-2026-56155, CVE-2026-56164, CVE-2026-58644
Indicators of Compromise
53[.]71