Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-16
Daily Brief·2026-07-16·27 Sources·18 Items

Rosetta Daily · Jul 16, 2026

Generated automatically · 27 sources scanned · 18 items selected
Window: past 24h (2026-07-15 → 2026-07-16). Feed-level timestamps are approximate; items assembled via WebSearch + verified WebFetch (see Method & failed sources).

Correction to the 2026-07-15 brief (read this first)

Yesterday's edition reported July Patch Tuesday as "127 CVEs" with "no new in-the-wild 0-day this month", and led with a Defender EoP ("RoguePlanet", CVE-2026-50656) as the headline. This was wrong on both counts. Verified today against BleepingComputer's article body and ZDI's review:

  • Microsoft's July 2026 Patch Tuesday fixed 570 flaws(ZDI counts 621–622Microsoft CVEs for the month) — the largest single-month release in Microsoft's history, not a "return to normal".
  • It included 3 zero-days, 2 of them actively exploited— CVE-2026-56155 (AD FS EoP) and CVE-2026-56164 (SharePoint Server EoP). Both were added to CISA KEV on 07-14.

Treat yesterday's "Vendor Advisories" section as retracted. The corrected items are carried below.

Critical Vulnerabilities

  • 🔴⚠️🔥 SonicWall SMA1000 — two zero-days exploited in tandem — SonicWall SMA6210 / SMA7210 / SMA8200v, CVE-2026-15409 (CVSS 10.0, unauthenticated SSRF in the Work Place interface) + CVE-2026-15410 (CVSS 7.2, post-auth code injection in the Appliance Management Console)
    Discovered by the Rapid7 MDR team during live incident response. Chained, they give full appliance takeover: SSRF gets an unauthenticated attacker in, the code injection turns admin access into arbitrary OS commands. Fixed in firmware 12.4.3-03453 and 12.5.0-02835. Both are in CISA KEV (added 07-14); FCEB agencies have until 2026-07-17 under BOD 26-04 to patch or pull the product.
    SonicWall advisory via BleepingComputer · Rapid7 · Help Net Security

  • 🔴 SAP July 2026 patch day — 16 flaws, 3 critical — SAP NetWeaver, Commerce Cloud, AppRouter
    Three critical-rated issues across NetWeaver, Commerce Cloud and AppRouter. NetWeaver remains one of the most consistently targeted enterprise attack surfaces post-disclosure; internet-exposed instances should be prioritised.
    BleepingComputer

  • ⚠️ Progress ShareFile — path traversal zero-day behind the Storage Zone emergency shutdown
    Progress confirmed a high-severity path traversal zero-day was the reason it emergency-shut-down ShareFile Storage Zone Controllers last week; security updates are now out. Managed file transfer / storage products remain the single most reliable ransomware initial-access category — treat as urgent if you run Storage Zone Controllers.
    BleepingComputer

In-the-Wild Exploitation (CISA KEV)

  • KEV 07-14 — four additions, two of them Microsoft zero-days: CVE-2026-15409 + CVE-2026-15410 (SonicWall SMA1000, above), CVE-2026-56155(AD FS, insufficient granularity of access control → local privilege elevation to administrative rights), CVE-2026-56164(SharePoint Server EoP — a missing-authentication flaw, network-reachable with no user interaction; note the deceptively low CVSS 5.3 versus its real reachability).
    CISA 07-14· CISA KEV
  • CISA also issued a standalone SharePoint hardening alert (07-14)following the new exploitation — separate from the KEV entry, worth reading if you self-host SharePoint.
    CISA
  • Still inside BOD deadlines from earlier this month: CVE-2008-4128(Cisco IOS CSRF — an 18-year-old bug re-added on evidence of current abuse of long-lived exposed devices, 07-13) and the 07-10 / 07-07 Joomla-ecosystem upload chain (CVE-2026-48939, CVE-2026-56291) plus Langflow auth bypass CVE-2026-55255.
    CISA 07-13· CISA 07-10· CISA 07-07

Vendor Advisories

  • Microsoft July 2026 Patch Tuesday — 570 flaws, a record— 59 rated Critical (48 RCE, 9 EoP, 1 security bypass, 1 spoofing); ZDI counts 621–622 Microsoft CVEs for the month, ~3x June. A further 468 Edge/Chromium flawsfixed by Google upstream were excluded from the roundup. Also fixed: CVE-2026-50661 (BitLocker security feature bypass — physical access needed, but it exposes encrypted data).
    BleepingComputer· ZDI review· Security Affairs· Rapid7
  • Windows 10 KB5099539 extended security updateshipped — relevant if you are on the ESU track.
    BleepingComputer

Web Security Research

  • PortSwigger — single-packet attack / race condition tooling resurfaced ahead of Black Hat— PortSwigger's Vegas run-up (07-09) re-highlighted the single-packet attack, which nullifies network jitter and lands multiple requests inside a ~1ms window, alongside the newer classes of race condition it enables.
    PortSwigger blog· Research index

    ℹ️ Nothing newly published by PortSwigger inside today's 24h window — carried as context, not as news.

AI Security

  • Prompt injection remains OWASP's #1 LLM threat, and the numbers keep getting worse— The International AI Safety Report 2026 found sophisticated attackers bypass even best-defended models ~50% of the time within 10 attempts, rising to 78.6% by attempt 200. No complete fix exists at any frontier lab; defence in depth remains the only viable posture. Production CVEs continue to land: Microsoft Copilot (CVSS 9.3), GitHub Copilot (9.6), Cursor IDE (9.8).
    Securance· Vectra
  • Unit 42 documented the first large-scale indirect prompt injection in the wild (March 2026)— including ad-review evasion and system prompt leakage on live commercial platforms. The academic side is catching up: "When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins"is accepted to IEEE S&P 2026.
    arXiv

Threat Intelligence

  • Unit 42 — "Screening Serpens" (Iran-nexus) still escalating— Activity has increased since the regional conflict that began February 2026, with two RAT families deployed across entities in up to five countries.
    Unit 42
  • ESET — Iran-aligned APT activity down, proxies up— Iranian internet restrictions suppressed direct APT operations while proxy activity surged; ESET observed wipers against Israel and a UAE defence company compromised with Android spyware targeting Arabic-speaking users.
    ESET APT Activity Report
  • APT28 / "Operation Neusploit"— Russia-linked actor attributed to attacks exploiting a Microsoft Office flaw, targeting Ukraine, Slovakia and Romania.
    Check Point Research — 13th July

Malware

  • CrashStealer — signed, notarized macOS infostealer impersonating Apple's crash reporter— Jamf Threat Labs: a signed and notarized dropper clears Gatekeeper, then fetches, re-signs and launches the payload, which installs as CrashReporter.appwith LaunchAgent com.apple.crashreporter.helperand shows a fake macOS password prompt. Targets 7+ browsers, ~80 crypto wallet extensions and 14 password managers(1Password, Bitwarden, LastPass, Dashlane, Keeper, KeePassXC, NordPass). Notable for client-side AES-GCM encryption of loot plus control-flow flattening and layered anti-debugging — well above commodity-stealer tradecraft. Found in-dev in early May; in-the-wild detections by early July.
    Jamf Threat Labs· BleepingComputer· Help Net Security
  • Phishing: LastPass impersonation + two MFA-defeating kits— LastPass is warning of an ongoing campaign using fake security notices; separately, phishing kits Jaliscoand OmegaLordare hitting Microsoft 365 accounts with techniques that defeat MFA.
    BleepingComputer

Chinese-Language Community Picks

None this cycle. No items with a verifiable date were found from FreeBuf / Xianzhi / Anquanke in the 07-15–07-16 window — handled on a "better empty than padded" basis, with no old items used as filler (yesterday's entry in this section cited the FreeBuf weekly, not same-day content).


Ransomware Today

RansomLook's API is reachable again — today's edition is built on structured source data rather than press reconstruction (the 07-15 brief had to fall back to reporting). 19 new posts across 10 groups in the 07-15 UTC day. Most active: dragonforce (5), qilin (3), ailock (3). Strict watchlist matching hit only 4/19 (qilin ×3, akira ×1) — the watchlist's group list is stale, since ailock / pear / dragonforce / leaknet aren't on it. Standouts: four healthcare victims in one day (pear ×2, plus shinyhunters claiming Abbott-owned Exact Sciences), and a leaknet claim of 6TB of submarine/nuclear-plant material from Anglo Belgian Corp — attacker-stated, unverified.
Full victim table

Bug Bounty

Bug Bounty now has its own daily edition (deep dive + recent disclosures grouped by theme).
View the Bug Bounty daily


AI Frontier

OpenAI

  • NYT sanctions motion— The New York Times and other publishers suing OpenAI over training-data use have filed a motion seeking sanctions, alleging OpenAI withheld training-data evidence.
  • GPT-5.6 (Sol / Terra / Luna), GA since 07-09, remains the current line.

Anthropic

  • Andrej Karpathy and Tom Blomfield reported to have joined(Blomfield to the AI compute team).
  • Future of Life Institute 2026 AI Safety Index: Anthropic took the highest grade of any frontier lab — a C+. OpenAI and Google DeepMind landed at C, Meta D+; xAI, DeepSeek and Mistral effectively failed. The ceiling being a C+ is the story here.

Google DeepMind / Google AI

  • Gemini 3.5 Pro delayed to 2026-07-17— the 2.5 Pro architecture was scrapped for a full rebuild targeting mathematical reasoning, SVG scene generation and image quality, positioned against GPT-5.6 and Anthropic's Fable 5. GA lands tomorrow — expect it in the 07-17 brief.
  • Google fixed 468 Chromium flawsupstream this month (see Vendor Advisories) — a reminder that the browser remains the largest single patch surface.

🛡 = security-relevant


Method & Failed Sources

Per the standing constraint (see project memory), direct RSS/Atom/HTML feed fetching does not work from this runner: web_fetch enforces a provenance gate (feed URLs read out of sources.yaml are not in provenance) and the sandbox shell has no network. This edition was therefore assembled from WebSearch per category, with web_fetchused to verify URLs that surfaced in search results.

  • All RSS/Atom feeds in sources.yaml(CISA KEV XML, NVD, GitHub Advisories, MSRC, PortSwigger, Project Zero, THN, BleepingComputer, Mandiant, DFIR Report, Unit 42, FreeBuf, 安全客, arXiv, OpenAI/DeepMind/Google AI) — not fetched directly; provenance gate. Covered indirectly via WebSearch.
  • RansomLook API— success this run(URL is in the task prompt → in provenance). Returned 19 posts. Note the ?days=1endpoint gives only group_name/ post_title/ discovered— no victim sector, geo or link fields.
  • CISA 07-14 alert page— web_fetchreturned an empty body; content confirmed via search result text and cross-referenced against the BleepingComputer article. Link retained.
  • Chinese community (FreeBuf / 先知 / 安全客)— no date-specific results surfaced for the 07-15/16 window. Section omitted from today's English edition rather than padded with stale items.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 15, 2026
Next →
Rosetta Daily · Jul 18, 2026