Government Updates UK’s National Risk Register with Cyber Warnings
The UK government is warning of the potential impact of catastrophic cyber-attacks
The UK government is warning of the potential impact of catastrophic cyber-attacks
Microsoft released updates addressing at least 570 security vulnerabilities across Windows and other software products, nearly tripling the number patched in the previous month's record-setting update. The company attributed the substantial increase in discovered flaws to artificial intelligence-assisted vulnerability research efforts.
Microsoft's July 2026 patch release is a record-breaking 621 CVEs—exceeding the year-to-date totals of any prior year—with 63 critical vulnerabilities including two actively exploited flaws in Active Directory Federation Services and SharePoint, plus multiple 9.8-9.9 CVSS issues in Windows VMSwitch, SharePoint RCE, and DHCP Server that demand immediate prioritization. Adobe released 88 CVEs across 12 bulletins with ColdFusion (CVSS 9.9) and Commerce as top priorities, though neither vendor's patches are currently under active exploit. The release spans an unusually broad attack surface from identity infrastructure and remote access services to filesystems and media frameworks, with notable clusters including 21 NTFS/ReFS RCEs, 95 total RCEs, and 260+ elevation-of-privilege bugs requiring urgent assessment and expedited patching schedules.
The US Department of Defense has announced an immediate suspension of Cybersecurity Maturity Model Certification Phase II requirements for defense contractors pending further review. This suspension pauses the implementation timeline for the elevated security maturity standards that were scheduled to take effect for the defense industrial base.
Bishop Fox has developed snowpick, a testing tool that identifies public data exposure in ServiceNow instances by examining both portal widgets and API endpoints, which can leak backend records despite appearing secure. In authorized testing across 166 ServiceNow instances, nearly one-third were found to be returning sensitive data through these public-facing mechanisms.
Researchers at Jamf Threat Labs have identified CrashStealer, a new macOS malware that leverages a legitimate developer ID to masquerade as Apple's crash reporter application. The malware is designed to steal sensitive data including passwords and cryptocurrency wallets from compromised systems. This attack demonstrates how threat actors can abuse trusted signing mechanisms to increase the credibility and effectiveness of their malicious campaigns.
Supermarket giant Lidl has revealed details of a supplier breach impacting customer data
ESET researchers have identified 11 vulnerable UEFI shim bootloaders that carry Microsoft signatures, enabling attackers to circumvent UEFI Secure Boot protections by exploiting security flaws dating back a decade. These forgotten shims represent a persistent attack surface that could allow adversaries to load malicious code during the boot process on affected systems. The findings highlight how legacy signed components can continue to pose security risks long after they've been superseded by newer versions.
Five UK residents have been charged in relation to supplying Russian Coms fraud devices and apps
A ransomware negotiation firm trusted by victim companies to handle communications with criminal gangs was simultaneously providing attackers with sensitive details about victims' cyber-insurance policies and negotiation strategies. This conflict of interest gave the criminal operators a significant advantage in extortion negotiations, allowing them to exploit inside knowledge of their targets' financial limits and defensive postures. The breach of trust highlights a critical vulnerability in the ransomware incident response supply chain where intermediaries have access to highly sensitive information on both sides of negotiations.
A misconfigured open directory has exposed operational details for three separate phishing operators leveraging Evilginx, a framework designed to bypass multi-factor authentication protections. The exposure of these threat actors' infrastructure and activities provides valuable intelligence on active MFA-evasion campaigns currently targeting organizations.
CISA has released a postmortem following a significant data leak where a contractor exposed dozens of internal credentials, including AWS Govcloud keys, in a public GitHub repository for nearly six months before KrebsOnSecurity alerted the agency. The incident revealed critical gaps in CISA's detection and response processes that security professionals should examine for applicability to their own organizations. The agency's analysis offers practical lessons on credential management, secret scanning, and incident response timelines that extend beyond government infrastructure.
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
Researchers have identified a novel OAuth Client ID spoofing technique that allows attackers to spoof OAuth Client IDs within Microsoft Entra ID to gain unauthorized access to cloud environments. This attack method provides adversaries with a stealthy mechanism for infiltrating cloud infrastructure, representing a significant threat to organizations relying on Entra ID for authentication and authorization.
Progress Software has warned customers of an external security threat affecting ShareFile and is instructing them to shut down servers hosting the Storage Zone Controller component. The advisory indicates a potential compromise to the widely-used file-sharing and data storage platform, though specific attack details and remediation steps beyond the shutdown directive were not disclosed.
Trail of Bits has released a comprehensive Testing Handbook chapter on security testing for Rust programs, covering dynamic analysis tools (Miri, proptest, coverage measurement), static analysis with Clippy, memory zeroization techniques, and specialized testing approaches like model checking with Kani. The chapter also documents common Rust security gotchas discovered during real audits and introduces rust-review, a Claude Code plugin for automated Rust security reviews that targets over a dozen vulnerability classes including memory safety, concurrency hazards, and FFI issues.
Cybersecurity agencies from 12 countries have issued a joint advisory warning that Russian state-backed hackers are actively exploiting vulnerable routers worldwide, leveraging weak SNMP credentials to gain access. The coordinated alert highlights a widespread campaign targeting infrastructure that often receives lower security attention than other network assets.
An Armenian man extradited from Ukraine has pleaded guilty to charges related to his involvement in the Ryuk ransomware operation. The case represents a significant development in law enforcement efforts against one of the more notorious ransomware groups that has targeted organizations globally.
The Australian Cyber Security Centre has issued a warning about widespread scanning and exploitation activity targeting content management systems globally. The campaign appears to involve mass reconnaissance efforts aimed at identifying and compromising vulnerable CMS installations across multiple organizations.
GreyNoise has launched a Threat Brief Library within its Visualizer platform, enabling users to access and manage curated threat intelligence reports including weekly At The Edge briefs and Executive Situation Reports. The library allows security teams to browse, search, filter, and download these briefs, which are generated from GreyNoise's primary-source sensor data for threat analysis and situational awareness.