Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-18
Daily Brief·2026-07-18·30 Sources·28 Items

Rosetta Daily · Jul 18, 2026

Generated automatically · 30 sources scanned · 28 items selected

Critical Vulnerabilities

  • Microsoft July 2026 Patch Tuesday: record 570 flaws, 3 zero-days — Microsoft, multiple CVEs
    Largest Patch Tuesday ever: 570 vulnerabilities (57 critical), volume partly attributed to Microsoft's new AI-powered vulnerability-discovery system scanning the Windows codebase. Includes 254 EoP + 145 RCE.
    Bleeping Computer · Krebs · ZDI review

  • 🔴 Windows VMSwitch Elevation of Privilege — Microsoft, CVE-2026-57092, CVSS 9.9
    Use-after-free letting a low-privileged attacker escalate across a VM boundary to full host compromise — highest-rated CVE of the month.
    CrowdStrike analysis · Qualys

  • ⚠️ "LegacyHive" Windows 0-day PoC dropped hours after Patch Tuesday — Windows User Profile Service, unpatched
    Researcher "Nightmare Eclipse" published full exploit code for an unpatched privilege escalation: a standard user coerces the SYSTEM-integrity User Profile Service into loading an attacker-controlled registry hive → admin. No patch yet; monitor MSRC.
    The Hacker News · Bleeping Computer · The Register

  • 🔴🔥 Oracle E-Business Suite — Oracle, CVE-2026-46817
    Added to CISA KEV on Jul 15 with evidence of active exploitation; ERP internet exposure makes this a priority patch.
    CISA alert

In-the-Wild Exploitation (CISA KEV)

  • 🔥 SharePoint Server EoP — CVE-2026-56164, CVSS 5.3 (KEV Jul 14) + CVE-2026-58644 (KEV Jul 16)
    Actively exploited; attackers chain CVE-2026-56164 with older SharePoint flaws to steal IIS machine keys, persist, and deploy malware. FCEB remediation deadline was Jul 17; CISA issued a separate SharePoint-hardening alert.
    CISA hardening alert · TechTimes

  • 🔥 AD FS Elevation of Privilege — CVE-2026-56155, CVSS 7.8 (KEV Jul 14)
    Actively exploited local EoP in Active Directory Federation Services; FCEB deadline Jul 28.
    CISA Jul 14 additions

  • 🔥 SonicWall SMA1000 appliances — CVE-2026-15409 / CVE-2026-15410 (KEV Jul 14)
    Two actively exploited flaws in SonicWall SMA1000 remote-access appliances — edge devices remain the #1 initial-access target class.
    CISA Jul 14 additions

  • 🔥 KNX Protocol — CVE-2023-4346 (KEV Jul 15)
    Building-automation protocol flaw from 2023 now confirmed exploited in the wild — OT/ICS exposure.
    CISA alert

Vendor Advisories

  • Microsoft: July cumulative updates ship fixes for the two exploited zero-days above; a command-injection flaw in Microsoft Copilotwas on KEV with a patch-by-Jul-17 deadline.
    Qualys Patch Tuesday review
  • Adobe: July Patch Tuesday updates released alongside Microsoft's (multiple products).
    Qualys
  • Rapid7 / CrowdStrike / Action1triage guides for the record-size release: prioritize SharePoint, AD FS, VMSwitch, then the 57 criticals.
    Rapid7· Action1

Web Security Research

  • Cross-Site ETag Length Leak— PortSwigger Research
    Elegant chain of edge-cases leaking response size cross-domain; latest in the XS-Leaks line of work.
    PortSwigger Research
  • Next.js critical vulnerability analysis— PortSwigger Research
    Source-code-analysis-driven attack construction against Next.js internals — worth reading for framework-auditing methodology.
    PortSwigger Research
  • (No fresh <24h publications surfaced from PortSwigger / Project Zero / Trail of Bits / Detectify; items above are their most recent.)

AI Security

  • "TuxBot v3 Evolution": IoT botnet built with LLM assistance— The Hacker News (Jul 17)
    Previously unreported IoT botnet framework showing clear signs of LLM-assisted development — concrete evidence of AI-accelerated malware engineering.
    The Hacker News
  • Prompt injection remains OWASP #1 LLM risk; attacks up 340% YoY
    International AI Safety Report 2026: sophisticated attackers bypass best-defended frontier models ~50% of the time within 10 attempts; Unit 42 documented the first large-scale indirect prompt-injection attacks in the wild earlier this year.
    Vectra overview· Securance
  • Microsoft Copilot command injection actively exploited— on CISA KEV, federal patch deadline Jul 17.
    Qualys
  • Defense side: Microsoft credits AI vuln-discovery systemfor a large share of July's 570 patched flaws — AI now materially shifting both offense and defense.
    Dark Reading

Threat Intelligence

  • Daxin returns + new "Stupig" backdoor in Taiwan manufacturing— China-linked malware first documented 2022 found still operational after 4+ years inside a Taiwan manufacturer, alongside a previously unreported backdoor.
    The Hacker News
  • "UNK_MassTraction" targets US/Canada university physics & engineering departments— suspected Chinese APT exploiting CVE-2024-4200 to steal browser credentials, then dropping malware on university mail servers; focus on national-security-adjacent research.
    CYFIRMA weekly report
  • MODBEACON trojan via SEO-poisoned installers— tech / education / SOE sectors across Asia; staged modular payloads for long-term espionage.
    CYFIRMA weekly report
  • Iranian APT "Screening Serpens" 2026 espionage campaigns tracked— Unit 42.
    Unit 42
  • TfL hackers sentenced— two Scattered-Spider-linked men (18, 20) got 5.5 years each for the 2024 Transport for London breach (148 systems down, 27,000 in-person password resets).
    Bleeping Computer

Chinese-Language Community Picks

  • AI agent finds 21 0-days in FFmpeg; Chrome ships a record 429 fixes— a milestone in AI-automated vulnerability discovery, widely discussed in the Chinese-language community recently.
    Infosec Knowledge Base
  • Pwn2Own Berlin 2026 selling out triggers "retaliatory disclosure"— dozens of rejected researchers chose to publish their vulnerabilities directly, prompting lively community debate.
    Yijing Lab
  • (No confirmed new high-value items from FreeBuf / Xianzhi / Anquanke in the past 24h.)

Ransomware Today

19 new leak-site posts across 10 groups per RansomLook (most recent batch discovered Jul 15 — API lags a bit). Most active: DragonForce (5), Qilin (3), AiLock (3). ⭐ 4 watchlist group hits (qilin ×3, akira ×1) + 2 healthcare victims (Pear group). Standout claim: "LeakNet" alleges 6TB from Anglo Belgian Corp incl. submarine/nuclear-plant documents. Q2 context: "The Gentlemen" overtook Qilin as most prolific group.
Full victim table

Bug Bounty

The Bug Bounty deep-dive is maintained as its own daily report (themed recent disclosures + one deep analysis per day).
Bug Bounty daily report


AI Frontier

OpenAI

  • GPT-5.6 released (Jul 9)in three tiers — Sol ($5/$30 per Mtok), Terra ($2.5/$15), Luna ($1/$6) — alongside ChatGPT Work, an agent that "takes a goal to finished work" across apps and files. Axios
  • Custom instructions expanded to 5,000 chars (Pro/Enterprise/Business/Edu); unified search across chats/projects/files; ChatGPT back on WhatsApp in the EEA. Releasebot

Anthropic

  • Claude for Teachers (Jul 14): free premium Claude access for verified US K-12 educators, curriculum-aligned in all 50 states. Chalkbeat
  • Claude Sciencemomentum: 60+ scientific database connectors; AI-for-Science grants (up to $30k credits) closed applications Jul 15, awards by Jul 31. TechCrunch
  • Self-serve HIPAA configurationfor Enterprise/API orgs; Claude Code stability update (subagent streaming, permission handling). Releasebot

Google DeepMind / AI

  • Gemini 3.5 Pro: reports point to a Jul 17 launch target after a ground-up architectural rebuild (2M context, "Deep Think" reasoning layer) — unconfirmed by Google; delay + researcher departures (Shazeer, Jumper) reportedly weighed on Alphabet. TechTimes
  • Nano Banana 2 Lite(fastest/cheapest Gemini image model) and Gemini Omni Flashnatively-multimodal model in public API preview. Google blog

Failed / Degraded Sources

  • Direct RSS/Atom feed pulls unavailable in this run environment — brief assembled via web search per category + RansomLook API (timestamps approximate at feed level).
  • PortSwigger / Project Zero / Trail of Bits / Detectify / xz.aliyun / FreeBuf / anquanke — no confirmed <24h items surfaced today.
  • RansomLook ?days=1returned posts discovered 2026-07-15 (upstream lag); noted in the ransomware section.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jul 16, 2026
Next →
Rosetta Daily · Jul 19, 2026