Skip to content
Marcus Reed | CISO Intel

Daily Threat Intelligence  ·  CVE & Zero-Day Tracking  ·  APT & Ransomware Analysis

Go back

CISO Intel Brief — Thursday, 16-07-2026

🛡️ CISO Intel — Thursday, 16-07-2026

Blog generation failed — API error. Presenting Discord briefing as fallback.

🔴 Critical Threats & Active Exploitation

Microsoft SharePoint ServerCVE-2026-56164 (CVSS 9.8) — An unauthenticated, network-based privilege escalation vulnerability. This is actively being exploited in the wild and requires no user interaction. Mandiant/Google FLARE discovered it during real-world attacks. 📌 Source: Orca Security · Tenable — https://www.orca.security/blog/microsoft-july-2026-patch-tuesday-actively-exploited-sharepoint-zero-day/

Russian State-Sponsored APT Groups — Russian APT groups, including those linked to FSB Center 16 (Berserk Bear, Energetic Bear, Ghost Blizzard, Crouching Yeti, Dragonfly, Static Tundra), are actively targeting poorly secured network devices, especially routers, to compromise critical infrastructure worldwide. They are using spoofed requests to steal device configurations and exploiting known Cisco vulnerabilities like CVE-2018-0171 and CVE-2008-4128. 📌 Source: CISA (US and allied governments) — direct link unavailable

🛡️ CVEs Worth Your Attention

CVE-2026-48318 | Adobe ColdFusion | CVSS 9.9 | Path traversal leading to arbitrary code execution | PoC: No (exploit code published for Firefox, not Adobe) 📌 Source: The Hacker News — https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware.html

CVE-2026-50518 | Windows DHCP Server | CVSS 9.8 | Buffer overflow exploitable via malicious DHCP packets | PoC: No 📌 Source: Orca Security — https://www.orca.security/blog/microsoft-july-2026-patch-tuesday-actively-exploited-sharepoint-zero-day/

CVE-2026-56159 | Windows DHCP Server | CVSS 9.8 | Buffer overflow exploitable via malicious DHCP packets | PoC: No 📌 Source: Orca Security — https://www.orca.security/blog/microsoft-july-2026-patch-tuesday-actively-exploited-sharepoint-zero-day/

CVE-2026-56188 | Windows Server Network Driver | CVSS 9.8 | Unauthenticated RCE via network traffic | PoC: No 📌 Source: Orca Security — https://www.orca.security/blog/microsoft-july-2026-patch-tuesday-actively-exploited-sharepoint-zero-day/

CVE-2026-55944 | Dynamics NAV/365 Business Central | CVSS 9.8 | Deserialization flaw enabling unauthenticated RCE | PoC: No 📌 Source: Orca Security — https://www.orca.security/blog/microsoft-july-2026-patch-tuesday-actively-exploited-sharepoint-zero-day/

CVE-2026-56190 | Remote Desktop Protocol (RDP) | CVSS (Not specified, RCE) | RCE in the RDP stack, a common internet-exposed service | PoC: No 📌 Source: Orca Security — https://www.orca.security/blog/microsoft-july-2026-patch-tuesday-actively-exploited-sharepoint-zero-day/

CVE-2026-40953 | Secure Access clients < 14.55 | CVSS (Not specified, heap overflow) | Heap overflow in certificate parsing function, local access with admin required | PoC: No 📌 Source: CVE Record — https://www.cve.org/CVERecord?id=CVE-2026-40953

CVE-2026-24229 | NVIDIA TensorRT-LLM for Linux | CVSS (Not specified) | Attacker could read, write, or delete internal cluster state via FastAPI server, leading to info disclosure, data tampering, DoS | PoC: No 📌 Source: NVD — https://nvd.nist.gov/vuln/detail/CVE-2026-24229

CVE-2026-24234 | NVIDIA TensorRT-LLM for Linux | CVSS (Not specified) | Network-accessible attacker could cause server-side request forgery in multimodal media fetching functions, leading to DoS and info disclosure | PoC: No 📌 Source: CVE Record — https://www.cve.org/CVERecord?id=CVE-2026-24234

CVE-2026-61828 | Nixpkgs MySQL Services | CVSS (Not specified) | Local users can log in as root without a password when used with mysql or percona-server due to improper database initialization. 📌 Source: NVD · GitHub, Inc. — https://nvd.nist.gov/vuln/detail/CVE-2026-61828

⚡ New TTPs & Attack Research

Ransomware Initial Access Shift to Identity Compromise — Sophos’ 2026 State of Ransomware report indicates a significant shift: 79% of ransomware attacks now start with compromised identities. Malicious email (26%) and phishing (24%) are now the top root causes, overtaking exploited vulnerabilities (18%). This highlights a focus on credential theft and social engineering.

AI-Driven Ransomware Campaigns — The first half of 2026 saw a 20% increase in ransomware attacks, with AI-enabled attacks confirmed or suspected by 78% of organizations. There are reports of ransomware campaigns operated entirely by large language models, indicating AI is moving from a support role to direct execution in cyber intrusions.

Agentic AI Prompt Injection (Fake Chain of Thought) — OpenAI’s internal red-teaming model, GPT-Red, discovered a novel prompt injection technique called “fake chain of thought.” This method plants false reasoning steps that an AI model treats as already verified, allowing for manipulation. GPT-Red successfully manipulated an AI-run vending machine to change prices and cancel orders.

🏗️ DevSecOps & Cloud Security

Malicious npm Package Compromises (Jscrambler) — The Jscrambler npm package was compromised via leaked npm credentials, leading to the publication of trojanized versions. The malicious packages (jscrambler@8.14.0, 8.18.0, 8.20.0) initially used preinstall hooks, then pivoted to injecting code directly into dist/index.js and dist/bin/jscrambler.js to evade detection. The payload is a cross-platform infostealer targeting developer workstations and CI/CD environments, collecting browser/cloud credentials, crypto wallet data, and AI development tool configurations. 📌 Source: CSO Online · Cloud Threat Landscape — https://www.csoonline.com/article/2143438/npm-ecosystem-hit-with-two-new-supply-chain-compromises.html

AI Agent Supply Chain Attacks — Adversaries targeted ClawHub, the community skill registry for OpenClaw, in early 2026, deploying silent data exfiltration payloads to affected agents. This highlights a new vector for supply chain attacks specifically targeting AI agent ecosystems and their integrated tools. 📌 Source: CrowdStrike — https://www.crowdstrike.com/blog/crowdstrike-aidr-defining-the-next-era-of-cybersecurity/

🔧 Patches & Vendor Releases

Microsoft July 2026 Patch Tuesday — Microsoft released its largest Patch Tuesday ever, addressing 622 CVEs, including 56 critical vulnerabilities and the actively exploited SharePoint zero-day (CVE-2026-56164). This includes critical RCEs in DHCP Server, Windows Server Network Driver, Dynamics NAV/365 Business Central, and RDP, as well as 164 fixes for Microsoft Office. Rate: 🟢 solid fix 📌 Source: Orca Security · Tenable — https://www.orca.security/blog/microsoft-july-2026-patch-tuesday-actively-exploited-sharepoint-zero-day/

Mozilla Firefox 152.0.6 — Addresses two critical flaws (CVE-2026-15718, CVE-2026-15719) for which exploit code is public, though no active exploitation in the wild is confirmed. Rate: 🟢 solid fix 📌 Source: The Hacker News — https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware.html

Google Chrome 150.0.7871.124/.125 — Ships fixes for 15 security flaws, including two critical use-after-free bugs in Ozone (CVE-2026-15764, CVE-2026-15765). Rate: 🟢 solid fix 📌 Source: The Hacker News — https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware.html

Adobe Security Updates — Patches 88 vulnerabilities, including multiple critical-severity bugs in ColdFusion, Commerce, Experience Manager, and Illustrator. Rate: 🟢 solid fix 📌 Source: The Hacker News — https://thehackernews.com/2026/07/firefox-chrome-adobe-and-vmware.html

🧪 Threat Intel & Malware

Ransomware Activity Surge (Qilin & The Gentlemen) — Ransomware incidents increased by 20% in the first half of 2026, with 5,275 recorded attacks. Two competing Ransomware-as-a-Service (RaaS) groups, Qilin and The Gentlemen, are driving this surge. The Gentlemen, formed by former Qilin members, is noted for its rapid expansion. 📌 Source: Fast Company — https://www.fastcompany.com/91167498/ransomware-attacks-rose-20-in-the-first-half-of-2026

Russian APT Targeting of Network Devices — US and allied governments issued a warning about Russian state-sponsored APT groups (e.g., Berserk Bear, Energetic Bear) actively scanning and exploiting poorly secured network devices, particularly routers, to gain access to critical infrastructure across various sectors. 📌 Source: CISA (US and allied governments) — direct link unavailable

🌐 Industry, Brand & Internet Security

23andMe Data Breach Settlement — Michigan reached a settlement with 23andMe over its 2023 data breach that exposed genetic data and personal information of millions. The settlement highlights failures in monitoring, identifying, and remediating known vulnerabilities and employing safeguards. 📌 Source: Michigan Attorney General (via ClassAction.org) — https://www.classaction.org/news/michigan-settles-bankruptcy-claims-against-23andme-over-genetic-data-breach.html

The Washington Post Data Breach Disclosure Delay — A lawsuit indicates The Washington Post waited approximately a year to disclose a breach from July 2025 that exposed SSNs, government IDs, financial, and health insurance information for at least 1,034 individuals. This delay raises significant concerns about timely notification and potential for identity theft. 📌 Source: Emery Reddy — https://www.emeryreddy.com/washington-post-data-breach-lawsuit/

Averhealth Data Breach — Averhealth, a substance use disorder recovery company, reported a data breach where an unauthorized party accessed its network between December 2025 and January 2026, potentially exposing names, clinical information, diagnoses, dates of birth, and driver’s license numbers. 📌 Source: ClassAction.org — https://www.classaction.org/news/averhealth-data-breach-affects-ssns-lawyers-investigating

🤖 AI & LLM Security

NIST Research on AI Security Permanence — NIST senior scientist Apostol Vassilev applied Gödel’s incompleteness theorem to AI security, concluding that no finite set of guardrails can be universally robust against adversarial prompts. This reinforces the need for continuous AI red teaming and an “improvement process” rather than aiming for permanent assurance. 📌 Source: Check Point Software Technologies — https://blog.checkpoint.com/ai-security/ai-security-is-never-finished-building-the-continuous-red-teaming-loop/

OWASP LLM02: Sensitive Information Disclosure — OWASP has ranked Sensitive Information Disclosure (LLM02) as the second most exploited vulnerability in large language models. This involves LLM applications accidentally leaking confidential data, PII, credentials, and internal system details through crafted prompts, especially in Retrieval Augmented Generation (RAG) models. 📌 Source: Asecurityguru.com (OWASP) — https://www.asecurityguru.com/llm-security/owasp-llm02-sensitive-information-disclosure-explained-hands-on-hack-llmgoat/

ISC2 AI Security Certification Development — ISC2 is developing a vendor-neutral certification for AI security, bringing together cybersecurity practitioners to define the knowledge, skills, and abilities required to secure AI systems and manage AI threats. 📌 Source: ISC2 — https://www.isc2.org/News-Events/Press-Room/Posts/2026/07/15/ISC2-Develops-AI-Security-Certification

📋 Compliance & Regulatory

RBI Urges Banks to Strengthen AI Cybersecurity — The Reserve Bank of India (RBI) has called on banks to accelerate AI adoption while simultaneously strengthening cybersecurity frameworks, internal controls, and safeguards against fraud and data misuse. This emphasizes that rapid tech adoption must be balanced with robust security, with governance originating directly from the board. 📌 Source: ET Edge Insights · IBTimes India · CA Sansaar · YouTube (NBFC Cybersecurity Compliance 2026)

US Government Launches “Gold Eagle” Vulnerability Clearinghouse — The Trump administration launched Gold Eagle, a program to coordinate nationwide efforts to rapidly identify and fix vulnerabilities using frontier AI models. This aims to harmonize vulnerability hunting across private companies and researchers to prevent duplication and accelerate fixes. 📌 Source: Cybersecurity Dive — https://www.cybersecuritydive.com/news/vulnerability-clearinghouse-ai-trump-administration/

💡 Marcus’s Take

This past 24 hours reinforces a critical shift: the human element is now the primary attack surface, even as AI takes center stage in both offense and defense. Ransomware’s pivot to identity compromise (79% of attacks!) means all those shiny next-gen boxes won’t save you if your users are clicking bad links or reusing passwords. Patch Tuesday was a beast, and that SharePoint zero-day is a stark reminder that “medium” CVSS can be a five-alarm fire when it’s actively exploited and unauthenticated. Meanwhile, AI isn’t just a threat multiplier; it’s becoming an operator, driving supply chain attacks and novel prompt injection techniques. The RBI’s directive to banks is spot on: innovate with AI, but secure it from the board down. We’re in a continuous red-teaming reality, whether we like it or not. Prioritize identity hygiene, user training, and get your AI security posture in order now.


Share this post on:

Previous Post
CISO Intel Brief — Friday, 17-07-2026
Next Post
CISO Intel Brief — Wednesday, 15-07-2026