Rosetta Daily · Jul 18, 2026
Generated automatically · 30 sources scanned · 28 items selected
Critical Vulnerabilities
-
Microsoft July 2026 Patch Tuesday: record 570 flaws, 3 zero-days — Microsoft, multiple CVEs
Largest Patch Tuesday ever: 570 vulnerabilities (57 critical), volume partly attributed to Microsoft's new AI-powered vulnerability-discovery system scanning the Windows codebase. Includes 254 EoP + 145 RCE.
Bleeping Computer · Krebs · ZDI review -
🔴 Windows VMSwitch Elevation of Privilege — Microsoft, CVE-2026-57092, CVSS 9.9
Use-after-free letting a low-privileged attacker escalate across a VM boundary to full host compromise — highest-rated CVE of the month.
CrowdStrike analysis · Qualys -
⚠️ "LegacyHive" Windows 0-day PoC dropped hours after Patch Tuesday — Windows User Profile Service, unpatched
Researcher "Nightmare Eclipse" published full exploit code for an unpatched privilege escalation: a standard user coerces the SYSTEM-integrity User Profile Service into loading an attacker-controlled registry hive → admin. No patch yet; monitor MSRC.
The Hacker News · Bleeping Computer · The Register -
🔴🔥 Oracle E-Business Suite — Oracle, CVE-2026-46817
Added to CISA KEV on Jul 15 with evidence of active exploitation; ERP internet exposure makes this a priority patch.
CISA alert
In-the-Wild Exploitation (CISA KEV)
-
🔥 SharePoint Server EoP — CVE-2026-56164, CVSS 5.3 (KEV Jul 14) + CVE-2026-58644 (KEV Jul 16)
Actively exploited; attackers chain CVE-2026-56164 with older SharePoint flaws to steal IIS machine keys, persist, and deploy malware. FCEB remediation deadline was Jul 17; CISA issued a separate SharePoint-hardening alert.
CISA hardening alert · TechTimes -
🔥 AD FS Elevation of Privilege — CVE-2026-56155, CVSS 7.8 (KEV Jul 14)
Actively exploited local EoP in Active Directory Federation Services; FCEB deadline Jul 28.
CISA Jul 14 additions -
🔥 SonicWall SMA1000 appliances — CVE-2026-15409 / CVE-2026-15410 (KEV Jul 14)
Two actively exploited flaws in SonicWall SMA1000 remote-access appliances — edge devices remain the #1 initial-access target class.
CISA Jul 14 additions -
🔥 KNX Protocol — CVE-2023-4346 (KEV Jul 15)
Building-automation protocol flaw from 2023 now confirmed exploited in the wild — OT/ICS exposure.
CISA alert
Vendor Advisories
- Microsoft: July cumulative updates ship fixes for the two exploited zero-days above; a command-injection flaw in Microsoft Copilotwas on KEV with a patch-by-Jul-17 deadline.
Qualys Patch Tuesday review - Adobe: July Patch Tuesday updates released alongside Microsoft's (multiple products).
Qualys - Rapid7 / CrowdStrike / Action1triage guides for the record-size release: prioritize SharePoint, AD FS, VMSwitch, then the 57 criticals.
Rapid7· Action1
Web Security Research
- Cross-Site ETag Length Leak— PortSwigger Research
Elegant chain of edge-cases leaking response size cross-domain; latest in the XS-Leaks line of work.
PortSwigger Research - Next.js critical vulnerability analysis— PortSwigger Research
Source-code-analysis-driven attack construction against Next.js internals — worth reading for framework-auditing methodology.
PortSwigger Research - (No fresh <24h publications surfaced from PortSwigger / Project Zero / Trail of Bits / Detectify; items above are their most recent.)
AI Security
- "TuxBot v3 Evolution": IoT botnet built with LLM assistance— The Hacker News (Jul 17)
Previously unreported IoT botnet framework showing clear signs of LLM-assisted development — concrete evidence of AI-accelerated malware engineering.
The Hacker News - Prompt injection remains OWASP #1 LLM risk; attacks up 340% YoY
International AI Safety Report 2026: sophisticated attackers bypass best-defended frontier models ~50% of the time within 10 attempts; Unit 42 documented the first large-scale indirect prompt-injection attacks in the wild earlier this year.
Vectra overview· Securance - Microsoft Copilot command injection actively exploited— on CISA KEV, federal patch deadline Jul 17.
Qualys - Defense side: Microsoft credits AI vuln-discovery systemfor a large share of July's 570 patched flaws — AI now materially shifting both offense and defense.
Dark Reading
Threat Intelligence
- Daxin returns + new "Stupig" backdoor in Taiwan manufacturing— China-linked malware first documented 2022 found still operational after 4+ years inside a Taiwan manufacturer, alongside a previously unreported backdoor.
The Hacker News - "UNK_MassTraction" targets US/Canada university physics & engineering departments— suspected Chinese APT exploiting CVE-2024-4200 to steal browser credentials, then dropping malware on university mail servers; focus on national-security-adjacent research.
CYFIRMA weekly report - MODBEACON trojan via SEO-poisoned installers— tech / education / SOE sectors across Asia; staged modular payloads for long-term espionage.
CYFIRMA weekly report - Iranian APT "Screening Serpens" 2026 espionage campaigns tracked— Unit 42.
Unit 42 - TfL hackers sentenced— two Scattered-Spider-linked men (18, 20) got 5.5 years each for the 2024 Transport for London breach (148 systems down, 27,000 in-person password resets).
Bleeping Computer
Chinese-Language Community Picks
- AI agent finds 21 0-days in FFmpeg; Chrome ships a record 429 fixes— a milestone in AI-automated vulnerability discovery, widely discussed in the Chinese-language community recently.
Infosec Knowledge Base - Pwn2Own Berlin 2026 selling out triggers "retaliatory disclosure"— dozens of rejected researchers chose to publish their vulnerabilities directly, prompting lively community debate.
Yijing Lab - (No confirmed new high-value items from FreeBuf / Xianzhi / Anquanke in the past 24h.)
Ransomware Today
19 new leak-site posts across 10 groups per RansomLook (most recent batch discovered Jul 15 — API lags a bit). Most active: DragonForce (5), Qilin (3), AiLock (3). ⭐ 4 watchlist group hits (qilin ×3, akira ×1) + 2 healthcare victims (Pear group). Standout claim: "LeakNet" alleges 6TB from Anglo Belgian Corp incl. submarine/nuclear-plant documents. Q2 context: "The Gentlemen" overtook Qilin as most prolific group.
Full victim table
Bug Bounty
The Bug Bounty deep-dive is maintained as its own daily report (themed recent disclosures + one deep analysis per day).
Bug Bounty daily report
AI Frontier
OpenAI
- GPT-5.6 released (Jul 9)in three tiers — Sol ($5/$30 per Mtok), Terra ($2.5/$15), Luna ($1/$6) — alongside ChatGPT Work, an agent that "takes a goal to finished work" across apps and files. Axios
- Custom instructions expanded to 5,000 chars (Pro/Enterprise/Business/Edu); unified search across chats/projects/files; ChatGPT back on WhatsApp in the EEA. Releasebot
Anthropic
- Claude for Teachers (Jul 14): free premium Claude access for verified US K-12 educators, curriculum-aligned in all 50 states. Chalkbeat
- Claude Sciencemomentum: 60+ scientific database connectors; AI-for-Science grants (up to $30k credits) closed applications Jul 15, awards by Jul 31. TechCrunch
- Self-serve HIPAA configurationfor Enterprise/API orgs; Claude Code stability update (subagent streaming, permission handling). Releasebot
Google DeepMind / AI
- Gemini 3.5 Pro: reports point to a Jul 17 launch target after a ground-up architectural rebuild (2M context, "Deep Think" reasoning layer) — unconfirmed by Google; delay + researcher departures (Shazeer, Jumper) reportedly weighed on Alphabet. TechTimes
- Nano Banana 2 Lite(fastest/cheapest Gemini image model) and Gemini Omni Flashnatively-multimodal model in public API preview. Google blog
Failed / Degraded Sources
- Direct RSS/Atom feed pulls unavailable in this run environment — brief assembled via web search per category + RansomLook API (timestamps approximate at feed level).
- PortSwigger / Project Zero / Trail of Bits / Detectify / xz.aliyun / FreeBuf / anquanke — no confirmed <24h items surfaced today.
- RansomLook
?days=1returned posts discovered 2026-07-15 (upstream lag); noted in the ransomware section.
Sources used: see intel/sources.yaml