← Carolina Clear Tech

Cyber Threat Brief

2026-07-16

Listen to this brief (34:13)

Download MP3
Show Notes

Show Notes - 2026-07-16

Stories Covered

CVEs Referenced

CVE-2023-4346, CVE-2026-15409, CVE-2026-15410, CVE-2026-15718, CVE-2026-15719, CVE-2026-15764, CVE-2026-15765, CVE-2026-26268, CVE-2026-32201, CVE-2026-45659, CVE-2026-46817, CVE-2026-47865, CVE-2026-48259, CVE-2026-48284, CVE-2026-48318, CVE-2026-48319, CVE-2026-48321, CVE-2026-48322, CVE-2026-48324, CVE-2026-48325, CVE-2026-48327, CVE-2026-48356, CVE-2026-48358, CVE-2026-48359, CVE-2026-55040, CVE-2026-56155, CVE-2026-56164, CVE-2026-58644

Indicators of Compromise

Domains: 53[.]71

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - July 16, 2026

Today: Microsoft ships a record 622 patches including four CISA-KEV vulnerabilities with same-day exploitation deadlines, while a disgruntled researcher drops another Windows zero-day hours after Patch Tuesday. SonicWall confirms active exploitation of two chained SMA1000 zero-days since June 22, with Rapid7 linking attacks to likely ransomware activity. Identity compromise now tops vulnerability exploitation as the primary ransomware attack vector, with multifactor authentication failing to prevent 97% of credential-based compromises.

Critical Alerts

Microsoft SharePoint Server Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-32201, CVE-2026-45659)

CISA issued urgent guidance on three actively exploited SharePoint Server vulnerabilities affecting all supported on-premises versions (Subscription Edition, 2019, 2016). CVE-2026-56164 is a privilege escalation flaw (CVSS 5.3) exploitable remotely without authentication, patched in July 2026 Patch Tuesday with a CISA deadline of July 17. CVE-2026-32201 is a spoofing vulnerability (EPSS 0.228, 97th percentile) patched in April with exploitation as a zero-day, now past its April 28 deadline. CVE-2026-45659 is a code execution flaw (EPSS 0.032, 87th percentile) patched via May out-of-band update, deadline July 4. Attackers establish remote code execution, steal IIS machine keys, perform deserialization attacks, gain persistence, and deploy malware. Microsoft's July updates also resolved CVE-2026-55040 and CVE-2026-58644, critical-severity bugs allowing security feature bypass and arbitrary code execution, not yet flagged as exploited but high-risk.

SonicWall SMA1000 Zero-Day Chain Exploited Since June 22 (CVE-2026-15409, CVE-2026-15410)

SonicWall disclosed two zero-day vulnerabilities in SMA1000 appliances under active exploitation since June 22. CVE-2026-15409 and CVE-2026-15410 have been chained together in attacks. CVE-2026-15410 is a max-severity defect (EPSS 0.016, 74th percentile) allowing authenticated requests. CVE-2026-15409 is rated 7.2, enabling authenticated command injection (EPSS 0.014, 69th percentile). When chained, attackers go from zero access to complete system compromise. Rapid7 researchers observed attacks targeting ransomware deployment, though encryption was prevented. Overlapping TTPs indicate the same threat group discovered and exploited both zero-days. SonicWall credited an internal employee with discovery but has not disclosed when discovery occurred or earliest exploitation instance. CISA added both to KEV catalog with July 17 deadline. Fewer than 5,000 SMA1000 appliances are deployed globally (less than 0.5% of SonicWall's monitored sensor footprint).

Active Directory Federation Services Privilege Escalation (CVE-2026-56155)

Microsoft patched CVE-2026-56155 (CVSS 7.8), a privilege escalation flaw in Active Directory Federation Services (AD FS) under active exploitation. CISA added it to KEV catalog with July 28 deadline. EPSS score 0.004 (30th percentile) suggests exploitation is targeted rather than widespread. No additional context on exploit activity disclosed.

Oracle E-Business Suite Privilege Management Flaw (CVE-2026-46817)

CISA added CVE-2026-46817 to KEV catalog based on evidence of active exploitation. This is an improper privilege management vulnerability in Oracle E-Business Suite. EPSS 0.007 (48th percentile). CISA BOD 26-04 requires federal agencies to patch by July 18.

KNX Protocol Authentication Lockout Bypass (CVE-2023-4346)

CISA added CVE-2023-4346, a 2023 vulnerability in KNX Association KNX Protocol Connection Authorization Option 1, to KEV catalog. This is an overly restrictive account lockout mechanism vulnerability under active exploitation. EPSS 0.005 (38th percentile). Federal agency deadline is July 29.

Ransomware & Extortion

Identity Attacks Overtake Exploits as Top Ransomware Cause

Sophos' State of Ransomware 2026 report surveyed 2,158 IT and cybersecurity leaders across 17 countries whose organizations suffered ransomware in the past year. Malicious email (26%) and phishing (24%) dethroned vulnerabilities (18%, down from 32%) as the top ransomware root cause after three years of vulnerability dominance. Identity compromise accounts for half of all ransomware attacks. Compromised credentials were the root cause in 23% of cases. 56% of ransomware attacks successfully encrypted victim networks. Ransom demands and payments are down year-over-year. Two-thirds of victims (67%) said their ransomware attack was the most significant identity attack over the past year. The most startling finding: multifactor authentication was deployed in 97% of instances where compromised credentials were the root cause. One-time passwords, push-based applications, and passkeys were most common. FIDO2 tokens ranked fourth. MFA failures stem from incomplete deployment across systems (creating gaps) and evolving bypass techniques. Organizations practicing aggressive defense-in-depth with segmentation, ZTNA to replace legacy VPNs, and 24/7 threat detection show best results.

Ransomware Groups Use AI to Amplify Extortion Pressure

FulcrumSec, a data extortion group active since September 2025, uses AI to analyze stolen data and establish firm negotiating positions rather than hacking. The group breaches organizations using hardcoded credentials, exposed credentials, unpatched applications, or misconfigured storage. It claims 25 breaches with several terabytes stolen. FulcrumSec uses AI teams to analyze private models and intellectual property, then frames extortion demands with detailed reports for threat researchers and journalists. In one case, FulcrumSec claimed it stole 1.3TB (700,717 files) from pharmaceutical company Novo Nordisk, including five undisclosed drug programs, in-development drug and RNA delivery programs, and private AI models. The group claimed AI analysis showed the data could save competitors three to five years of development time, setting an initial $25 million ransom. FulcrumSec also generates detailed breach reports with logos and formatting, providing "every bit of research and write up" to journalists. In one incident, the group used a stolen OpenAI key from the victim to pay ChatGPT to summarize the victim's own data. DragonForce ransomware group uses LLMs to manufacture psychological pressure, claiming to have legal counsel on staff to imply knowledge of victims' reporting requirements.

World Leaks Posts Files from India's Kudankulam Nuclear Plant

Ransomware group World Leaks posted a cache of files related to India's largest nuclear plant (Kudankulam Nuclear Power Plant) on the dark web. Files include purported blueprints of facility parts and supplier details. Data is labeled as coming from Reliance Group. This represents a significant critical infrastructure targeting.

Business & Infrastructure Threats

Nightmare Eclipse Drops LegacyHive Windows Zero-Day Hours After Patch Tuesday

Security researcher Chaotic Eclipse (Nightmare Eclipse) released exploit code for LegacyHive, a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability, hours after Microsoft's July 2026 Patch Tuesday. The PoC requires another standard user credential and a third username (which can be an administrator account). Successful exploitation mounts the target user hive in current user classes root. The researcher said the exploit was stripped down to prevent public exploitation. The original exploit did not require additional user credentials and was not limited to usrclass.dat hive - any hive could be loaded. The vulnerability works on all supported desktop and server versions of Windows, including those running July 2026 Patch Tuesday updates. This is a privilege escalation exploit targeting the Windows User Profile Service, allowing users with limited system rights to compromise admin accounts by modifying classes registry hives. Microsoft is investigating but has not yet acknowledged the vulnerability. Chaotic Eclipse and Microsoft have been in a heated dispute since April 2026, with the researcher releasing details of multiple exploits before patches were available, citing communication breakdown. Three Microsoft Defender vulnerabilities came under active exploitation shortly after public disclosure.

AsyncAPI npm Supply Chain Compromise - Import-Time Payload Delivery

Microsoft Threat Intelligence identified a coordinated supply chain compromise of the @asyncapi npm organization on July 14. Five package versions across four package names were republished within 90 minutes, each carrying the same malicious loader: @asyncapi/specs 6.11.2-alpha.1 and 6.11.2, @asyncapi/[email protected], @asyncapi/[email protected], and @asyncapi/[email protected]. Because @asyncapi/specs is a transitive dependency of numerous AsyncAPI tooling packages, this affected developer workstations, CI/CD pipelines, container builds, and production services that resolved these versions during the exposure window. Unlike postinstall-hook patterns, this executes at module-load (import/require) time, so npm install --ignore-scripts does not neutralize it. The second stage decrypts and evaluates a Miasma modular runtime with active C2, persistence, and decentralized fallback channels. Credential harvesting, propagation, and high-risk modules were disabled in this instance but could be enabled. The compromise originated from a pwn request against asyncapi/generator. A misconfigured GitHub Actions workflow (pull_request_target) executed attacker-controlled PR code, exposed the asyncapi-bot PAT, and enabled unauthorized pushes. Legitimate GitHub Actions OIDC release workflows published poisoned packages under automated identity [email protected], producing valid provenance signatures from unauthorized commits. Miasma runtime provided encrypted bootstrap, persistence, C2, data return paths, and resilient discovery via Nostr, Ethereum, BitTorrent DHT, libp2p, and IPFS.

TuxBot v3 Evolution: LLM-Assisted IoT Botnet Framework

Palo Alto Networks Unit 42 identified TuxBot v3 Evolution, a modular IoT botnet framework showing signs of LLM-assisted development. While the AI generated botnet code, it included a safety disclaimer the developer failed to remove before shipping. Several functions failed to work correctly, though corrected iterations likely exist. The framework consists of a C-based bot agent cross-compiling for 17 architectures (ARM, MIPS, x86_64, PowerPC, RISC-V, etc.), a Go-based C2 server with DDoS-for-hire panel, a custom exploit virtual machine, Docker-based test infrastructure, and automated build system. The bot brute-forces Telnet with 1,496 credential pairs, contains exploits for 30+ IoT device families, and communicates over encrypted TCP. Fallback C2 mechanisms include SHA512 DGA, P2P gossip with Ed25519-signed commands, IRC, DNS TXT queries, and HTTP polling. Unit 42 recovered complete source code (61 C++ files, 58 headers, compiler, VM, Docker configs, QEMU setups, 254 automated DDoS benchmark reports) and a compiled binary submitted to VirusTotal January 20, 2026. The framework is derived from AISURU and Wuhan botnet lineages plus MHDDoS Python toolkit. Infected devices display "Infected By Akiru" console banner.

Cursor IDE Arbitrary Code Execution via Malicious Repositories (CVE-2026-26268)

AI security firm Mindgard disclosed an unpatched vulnerability in Cursor IDE that triggers arbitrary code execution when opening malicious repositories on Windows. When a file named git.exe exists in a project root, Cursor executes it without user approval, warning, or click. The binary runs with user privileges and access to source code, SSH keys, and cloud tokens. Cursor keeps re-running it while the project stays open. Mindgard reported the flaw December 15, 2025. Seven months later, no patch exists and Cursor has published no advisory. Cursor checks several locations for Git binary when a project loads, including the workspace itself. Process Monitor shows Cursor.exe spawning the repo-root binary with command "git rev-parse --show-toplevel". Mindgard's PoC was Windows Calculator renamed git.exe, committed to root. Clone, open, done. The most recent dated confirmation is April 30, 2026 against Cursor 3.2.16. Current release is 3.11 (July 10). Cloning a repository is how binaries land on disk in the first place, so attackers need no foothold.

Spanish Cybercrime Network Takedown: €140M Stolen, 70 Individuals

Spanish national police disrupted an Iberian cybercrime network employing 70+ individuals across 19 registered companies and 1,000 financial accounts. Hackers operated from two nerve centers, perpetrating MitM attacks, CEO impersonation scams, social engineering with fake invoices, and fake investment platform scams. Total theft: €140 million ($161 million), with €61 million from CEO impersonation in 2024 alone. Authorities froze and recovered €3 million in soon-to-be-stolen funds. Four core members arrested, including the main suspect (moved to Porto, Portugal), his partner, and a fraud agency operator managing financial infrastructure (arrested in Panama). The remaining 67+ individuals worked as money mules. Revenue moved through 19 corporations, 120 merchant accounts, and 800 bank accounts. Many mules were international citizens recruited to travel to Spain, register companies, and open accounts. Illicit funds went through multiple financial routing layers and countries before withdrawal. Authorities seized 15 computers and 170 smartphones.

Patch Priority

Vulnerability Disclosures

Mozilla Firefox - Two Critical Flaws with Public Exploit Code

Mozilla released Firefox 152.0.6 addressing two critical flaws with public exploit code: CVE-2026-15718 (invalid pointer in JavaScript WebAssembly) and CVE-2026-15719 (site isolation in DOM Navigation). Mozilla is not aware of attacks in the wild abusing these flaws despite public exploit code.

Google Chrome - 15 Flaws Including Two Critical Use-After-Free Bugs

Google patched 15 security flaws including two critical use-after-free bugs in Ozone (CVE-2026-15764 and CVE-2026-15765), a cross-platform abstraction layer for Linux, ChromeOS, and Fuchsia. CVE-2026-15764 (EPSS 0.003, 22nd percentile) allows remote attackers who convince users to engage in specific UI gestures to potentially exploit heap corruption via crafted HTML. Patched in Chrome 150.0.7871.124/.125 for Windows/Mac and 150.0.7871.124 for Linux.

Adobe ColdFusion - Eight Critical Flaws

Adobe patched 88 vulnerabilities including eight critical flaws in ColdFusion: CVE-2026-48318 (CVSS 9.9, path traversal RCE, EPSS 0.067 93rd percentile), CVE-2026-48322 (CVSS 9.6, code injection RCE), CVE-2026-48284 (CVSS 9.6, improper input validation RCE), CVE-2026-48321 (CVSS 9.3, incorrect authorization privilege escalation), CVE-2026-48325 (CVSS 9.3, missing authentication RCE), CVE-2026-48319 (CVSS 9.1, path traversal RCE), CVE-2026-48324 (CVSS 9.1, SQL injection RCE), CVE-2026-48327 (CVSS 9.0, incorrect authorization RCE). Fixed in ColdFusion 2025 Update 11 and 2023 Update 22.

Adobe Commerce and Magento - Two Critical Flaws

Adobe patched CVE-2026-48356 (CVSS 9.6, file upload privilege escalation, EPSS 0.283 98th percentile) and CVE-2026-48358 (CVSS 9.1, improper encoding RCE) in Adobe Commerce and Magento Open Source.

Adobe Experience Manager - Two Critical Flaws

Adobe fixed CVE-2026-48259 (CVSS 9.6, SSRF RCE) and CVE-2026-48359 (CVSS 9.6, XXE RCE) in Adobe Experience Manager.

VMware Avi Load Balancer - Critical Authentication Bypass (CVE-2026-47865)

Broadcom fixed CVE-2026-47865 (CVSS 9.8), a critical authentication bypass vulnerability in VMware Avi Load Balancer. A malicious user with network access can exploit this to access the Avi Control plane. Discovered and reported by Filip Waeytens of NATO Cyber Security Centre.

Forgotten UEFI Shim Bootloaders Expose Secure Boot Blind Spot

ESET discovered 11 vulnerable but still-trusted UEFI shim bootloaders (version 0.9 or earlier) that attackers could use to bypass Secure Boot on systems trusting Microsoft's third-party UEFI signing certificate. Microsoft revoked the vulnerable bootloaders in June through Secure Boot revocation updates, but unpatched systems may continue to trust these components. The shims were configured to launch vulnerable second-stage bootloaders (older GRUB2 versions), lacked security protections in newer versions, or contained vulnerabilities allowing Secure Boot bypass. An attacker needs only a copy of one old bootloader and understanding of Secure Boot to bypass secure startup. This enables malicious code execution at boot time and persistent access below the OS level.

Microsoft Cancels Patch Tuesday for Some Dell Users Over Shutdowns and Overheating

Microsoft blocked July 2026 Patch Tuesday updates for some Dell systems experiencing surprise shutdowns and overheating. No CVE details or affected Dell model list provided in source article. This is a patch deployment issue rather than vulnerability disclosure.

General Security News

OpenAI GPT-Red Automates Prompt Injection Testing

OpenAI disclosed details of GPT-Red, an internal automated red-teaming model scaling prompt injection vulnerability discovery. GPT-Red functions like a human red-teamer: it sends prompts, monitors GPT model responses, and iterates toward malicious goals (uploading sensitive data to external servers, exfiltration, fraudulent instructions, disabling 2FA, external script injection, API key forwarding, malicious scraper scripts). GPT-Red is trained using self-play reinforcement learning with diverse defender LLMs on broad red-teaming scenarios. It's rewarded for eliciting valid failures (successful prompt injections) while defenders are rewarded for resisting attacks and completing original tasks. GPT-5.6 Sol is OpenAI's most robust model to prompt injections, achieving 6x fewer failures against direct prompt injection benchmarks compared to GPT-5.5 (four months prior). GPT-Red is kept separate from other models to prevent malicious capabilities from reaching attackers. Real-world tests: GPT-Red attacked an AI vending machine (Andon Labs), lowering expensive item prices to $0.50 minimum, ordering $100 items for $0.50, and canceling other customers' orders. A second test targeted a Codex CLI agent (GPT-5.4 mini) across 10 data exfiltration tasks, successfully causing sensitive data leaks.

Cisco Talos: The Hunter's Paradox - Is It Time to Embrace Automated Threat Hunting?

Cisco Talos researcher discusses the Hunter's Paradox: humans can no longer keep up with security data volume and velocity, requiring automation, but the most capable automation (AI) can't be fully trusted. Volume problem: more data than anyone can read, compounding yearly. Velocity problem: automated attacks move at machine speed, human-driven intrusions outpace defenders, AI on offense widens the gap. Capacity problem: even perfectly staffed and funded teams can't beat the math. Opting out of AI isn't an option for hunting at scale. The deeper trust issue: attackers lie and cheat constantly (deception is the medium they operate in). AI takes training data and telemetry at face value, with no concept that it might be deceived. This skews judgment even when explicitly told to detect anomalies. The article argues for a middle path: AI-assisted hunting with humans in oversight roles rather than fully automated or fully manual approaches.

CISA and NSA Publish Coordinated Vulnerability Disclosure Program Guidance

CISA, NSA, and international partners published joint guidance for software manufacturers and online service providers to design and implement coordinated vulnerability disclosure (CVD) programs. The guidance includes best practices for working with external security researchers: clear vulnerability disclosure policy (VDP), process for triaging and remediating reported vulnerabilities, assigning CVE identifiers, and leveraging third-party intermediaries (CISA, national CSIRTs) to substitute or supplement CVD programs. Organizations implementing robust CVD programs work transparently with researchers, remediate vulnerabilities, build constructive relationships, enhance product security, improve vulnerability management, and demonstrate dedication to protecting customers.

UK Steps Up Tech Sovereignty Push Following US AI Export Restrictions

The Trump administration's export control order banning foreign nationals from accessing Anthropic's Fable 5 and Mythos 5 models (later lifted) sparked UK concerns about dependence on US technology. The UK's House of Commons Science, Innovation and Technology Committee warned "the whim of a foreign government" could cut off access to key technologies like AI. The UK National Cyber Security Centre and DSIT detailed "Cyber Shield" strategy to build sovereign defense using frontier AI to identify, reduce, and resolve national cyber risk. However, more than two-thirds of UK, Spain, and France businesses run primarily on US tech companies. Europe absorbs 48.4% of global DDoS attacks (5x higher than North America's 9.4%), driven by Russian-aligned hacktivists. BEC involved 81% of reported incidents in Germany and Benelux (27% in US). Southern and Eastern Europe show strongest cybersecurity market growth: Spain 20% increase, Italy 15%, Poland 59% year-over-year (North America ~10%).

Data Breach Incidents

Three breach incidents noted but with minimal details: WilmerHale law firm sued over client data breach in May, Nayax fintech states it won't pay extortion demand from The Syndicate group, and Partnered Health (Australia) exposed patient records at family clinics affecting 16 clinics. Calgary 911 employee charged with breach of trust for unauthorized disclosure of confidential information.

Trends & Context

July 2026 marks a turning point in the Patch Tuesday process. Microsoft shipped 622 patches (a record), yet a researcher dropped another Windows zero-day the same day, functional on fully patched systems. The SharePoint exploitation chain demonstrates attackers moved faster than Microsoft's patch cadence in 2026 (three separate incidents from April through July). Identity compromise dethrones vulnerability exploitation as the primary ransomware vector, yet MFA deployed in 97% of credential-based attacks failed to prevent compromise, suggesting incomplete deployment or sophisticated bypass techniques. Supply chain attacks continue to evolve with the AsyncAPI compromise demonstrating import-time payload delivery that bypasses traditional install script protections. AI lowers barriers to entry for both attackers (TuxBot botnet development) and defenders (OpenAI's GPT-Red), but also enhances ransomware extortion tactics (FulcrumSec's data analysis for negotiation leverage).