daily cyber × ai intelligence

index

July 15, 2026

Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days

60 of 60 sources 437 gathered 400 triaged 42 clustered 42 written

Microsoft’s July load-in broke every prior record — 622 CVEs, two already under active attack in Active Directory and SharePoint. Elsewhere a fresh Windows privilege-escalation PoC dropped, ESET revived the Secure Boot bootkit threat with 11 forgotten signed shims, and a jailbroken Gemini reportedly stood up a working C2 in six minutes.

Vulnerabilities & Exploits

  • Microsoft shipped a record 622 CVEs, roughly triple June’s previous high, and two are being actively exploited — an Active Directory flaw and a SharePoint Server flaw, both credited to incident responders, plus a publicly-disclosed BitLocker bypass. Microsoft attributes the ballooning counts to AI-assisted vulnerability discovery. 62 are rated critical; Chromium/Edge added another 427. Patch and reboot the two exploited bugs first. Krebs on Security, The Hacker News, SANS ISC, SecurityWeek (discussion)
  • A new Windows privilege-escalation zero-day PoC, “LegacyHive,” was released by researcher Nightmare-Eclipse, targeting the Windows User Profile Service. It uses a timed path-switching trick to make Windows mount another user’s registry hive — potentially an administrator’s — under a standard helper account, and reportedly works across desktop and server builds patched through July 2026. GitHub, project mirror
  • ESET found 11 old, Microsoft-signed UEFI shim bootloaders that bypass Secure Boot on most UEFI systems. The forgotten Linux-distro shims still carry valid signatures and contain bugs that let an attacker run untrusted code at boot — enabling persistent UEFI bootkits that survive OS reinstalls and evade AV. Reported to CERT/CC. WeLiveSecurity, SC World
  • Progress confirmed the ShareFile Storage Zone Controller shutdown was driven by an actively exploited high-severity zero-day and has now shipped patches — closing out the emergency takedown reported last week (earlier coverage). BleepingComputer
  • Rapid7 disclosed CVE-2026-55040, a SharePoint JWT authentication bypass allowing user impersonation, now fixed. A researcher notes it chains with the Flow2Shell bug (CVE-2026-47298) for a full pre-auth path. Rapid7, MSRC
  • SAP patched three critical flaws in NetWeaver (CVSS 9.9 ABAP data-tampering bug), Commerce Cloud, and AppRouter, among 16 fixes this month; impacts range from data modification to request-response desync. BleepingComputer, The Hacker News

New Tools & Releases

  • BingusLdr — a DLL loader built with Crystal Palace that implements a CET-compatible stack-spoofing technique for EDR evasion, with an accompanying write-up on the approach. GitHub, write-up
  • SindriKit 1.4.0 adds an in-memory COFF loader and BOF execution engine with dynamic symbol resolution, automatic x64 trampoline generation, and remote injection without loader modification — a step up from the 1.3.0 release covered earlier (earlier coverage). write-up
  • Thumper — an open-source tripwire against the Shai-Hulud npm worm (and its evolved cousin “IronWorm”): plant realistic decoy credentials where the worm scans, and get alerted the instant one is read. GitHub

Cloud & Identity

  • Microsoft mapped a year of ShinyHunters activity against Salesforce, finding attackers walked into corporate tenants without exploiting a single platform flaw — abusing existing OAuth trust between Salesforce and connected apps/third-party vendors, plus vishing and misconfigurations. Defender monitoring was updated in response. The Hacker News, Microsoft
  • At least two threat actors are using “OAuth client ID spoofing” to validate stolen Entra ID credentials and enumerate accounts without generating a successful sign-in event — slipping past the telemetry defenders rely on to catch credential testing. The Hacker News
  • A researcher registered on FIFA’s public Agent Platform and was auto-added to FIFA’s internal Microsoft Entra tenant — the same tenant powering its internal systems. The Angular app only checked roles client-side while backend APIs served everything, including RTMP ingest URLs and stream keys for World Cup 2026 camera feeds. The researcher reported “the Angular app only checked roles client-side; the backend APIs served everything,” including write access to match stats and the live score system. bobdahacker.com, Schneier (discussion)
  • Passkeys become the default authentication method in Entra ID starting September 1, 2026, with native SMS/voice support retiring February 1, 2027 — plan migrations now. BleepingComputer, Microsoft

AI & Model Security

  • A jailbroken Google Gemini was used by a Russian-speaking fraudster to spin up a fresh C2 server for a credential- and crypto-stealing botnet in about six minutes, per The Register — a concrete demonstration of AI collapsing the time from intent to working attack infrastructure. The Register
  • Cursor IDE auto-executes malicious code from poisoned repositories, per Mindgard’s full disclosure of an unpatched arbitrary-code-execution flaw. Researchers reported it to Cursor in December; it remains exploitable in the popular AI coding platform. Mindgard, Dark Reading
  • xAI’s Grok Build CLI uploaded entire Git repositories — full commit histories and files it was explicitly told not to read — to an xAI Google Cloud bucket; uploads reportedly stopped after a server change and Musk promised a “purge,” though independent verification of deletion is lacking (earlier coverage). The Register, The Hacker News

Threat Activity

  • Finland issued a wanted notice for Aleksanteri Kivimäki, the convicted hacker behind the massive Vastaamo psychotherapy data breach; his lawyer believes he is now outside Finland. The Record
  • LabubaRAT, a previously undocumented Rust-based RAT, masquerades as NVIDIA software to blend into Windows environments, profiling hosts and establishing a reusable foothold for hands-on activity, per Blackpoint Cyber. The Hacker News
  • Kratos, a Phishing-as-a-Service platform, targets Microsoft 365 users across the US and EU with trusted lure chains, anti-bot checks, and evolving fake login pages; detection hinges on specific page assets and exfil endpoints. ANY.RUN
  • Russian cluster APT-C-60/APT-Q-12 is abusing GitLab, jsDelivr, and Codeberg — not just GitHub — as attack infrastructure, per JPCERT/CC. JPCERT/CC
  • The ClickFix ecosystem is expanding and now evades AV and EDR, available for rent at scale; Hudson Rock traces one sophisticated campaign back to an initial infostealer infection, and Dark Reading points to YARA as the best remaining detection option. Hudson Rock, Dark Reading

Supply Chain

  • A coordinated attack abused a GitHub Actions misconfiguration to steal a privileged token and push malicious npm packages into AsyncAPI repos, delivering multi-stage malware for persistence and exfiltration; separately, three packages (solana-key-utils, crypto-validate-lib, eth-wallet-helpers) impersonate blockchain libraries to steal MetaMask, Phantom, Ledger and Trezor credentials. Wiz, Nextron IOCs, CERT-SE
  • 148 npm packages disguised as student web proxies quietly turned visitors’ browsers into a DDoS botnet for about two weeks in May, using the registry as free hosting for a booby-trapped proxy site, per JFrog. The Hacker News

Policy & Industry

  • The EU and UK issued a coordinated cyber sanctions package — the EU hitting 9 individuals and 4 entities, the UK 24 — tied to Russian intelligence, and jointly attributed the failed December 2025 wiper attack on Poland’s power grid to Russia’s FSB (earlier coverage). The Register, CERT.dk
  • 23andMe agreed to an $18 million settlement with the New York AG over its data breach exposing millions of customers’ genetic data, plus mandated new security measures. NY AG
  • A Welsh Doxbin administrator (“KT”/“Chans”), Callum Dare, was sentenced to two years and three months for encouraging and assisting swatting attacks across the UK, US and Canada; investigators tied him to Doxbin via a PayPal account and email, and recovered phishing software mimicking dark-web marketplaces. The Register
Models