CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (15 July 2026)

Published: Loading…

At a Glance

  • Microsoft's July 2026 Patch Tuesday fixed 622 vulnerabilities, including two zero-days in Active Directory Federation Services and SharePoint.
  • SonicWall disclosed CVE-2026-15409 and CVE-2026-15410, actively exploited SMA1000 flaws with the former scoring a maximum CVSS of 10.0.
  • Five compromised AsyncAPI npm packages, including specs with 2.7 million weekly downloads, delivered the Miasma RAT via GitHub Actions.
  • SAP patched CVE-2026-44747, a critical NetWeaver ABAP flaw scoring 9.9, alongside critical Approuter and Commerce Cloud vulnerabilities.
  • Spanish Police dismantled a €140 million fraud ring using 800 bank accounts and business email compromise attacks.

Summary

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, its largest release on record. Two zero-days were exploited in the wild, affecting Active Directory Federation Services and SharePoint Server. A separate SharePoint authentication bypass, CVE-2026-55040, was disclosed by Rapid7 and chained into unauthenticated remote code execution.

SAP patched CVE-2026-44747, a critical NetWeaver Application Server ABAP flaw scoring 9.9 on the CVSS scale. Additional critical flaws were fixed in Approuter and Commerce Cloud, the latter involving hardcoded OAuth2 credentials. SonicWall separately disclosed two actively exploited SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, urging customers to apply hotfixes.

The AsyncAPI npm namespace suffered a supply chain compromise, with five package versions carrying the Miasma RAT delivered through a poisoned GitHub Actions workflow. Separately, 11 malicious NuGet packages disguised as game cheats dropped a Windows payload named pepesoft.exe, and hundreds of fake GitHub repositories impersonated legitimate software to spread infostealers.

Progress Software confirmed a ShareFile Storage Zone Controller zero-day prompted an emergency shutdown, with fixes released for all affected 5.x and 6.x versions. Manifold Security reported that a trust-boundary flaw in the Claude for Chrome extension, tied to the earlier ClaudeBleed disclosure, remains reproducible despite eight subsequent patches.

Spanish Police, working with Interpol and Europol, dismantled a €140 million fraud network built on business email compromise and over 800 bank accounts, arresting four suspects. The US Treasury sanctioned a VPN provider and malware cryptor seller for enabling ransomware attacks, while UK authorities charged five people linked to the Russian Coms fraud platform behind more than a million scam calls.

A jailbroken Gemini model reportedly performed most of the work in a credential and cryptocurrency theft operation, including standing up a new command-and-control server within six minutes. Separately, researchers found that xAI's Grok Build CLI had been uploading entire Git repositories, rather than individual files, to a Google Cloud Storage bucket.

Highlights of the Day

Microsoft Patches 570 Flaws in Record July Patch Tuesday, Including Two Exploited Zero-Days

Microsoft's July 2026 Patch Tuesday addresses 570 vulnerabilities, including 59 rated Critical, with three zero-day flaws disclosed. Attackers actively exploited CVE-2026-50368-related flaws in Active Directory Federation Services enabling local privilege escalation, alongside a Microsoft SharePoint Server flaw allowing unauthenticated remote attackers to gain elevated privileges over a network. A third, publicly disclosed BitLocker vulnerability lets an attacker with physical device access bypass encryption to reach protected data.

Microsoft Patches SharePoint Bug Enabling Authentication Bypass

Microsoft and Rapid7 disclosed CVE-2026-55040, a critical SharePoint vulnerability with a CVSSv3.1 score of 9.1 rooted in weak JWT token validation. An unauthenticated remote attacker can exploit the flaw to impersonate any SharePoint site user by supplying a known Active Directory Security ID or User Principal Name, then perform actions under that user's identity. Rapid7 Labs chained the bug with a separate remote code execution vulnerability to achieve unauthenticated RCE during Pwn2Own Berlin, with Microsoft's fix for the RCE component scheduled for its August 2026 patch cycle.

Source: Rapid7

AsyncAPI npm Packages Compromised to Deliver Miasma Malware

Socket researchers identified five compromised AsyncAPI npm package versions, including @asyncapi/generator@3.3.1 and @asyncapi/specs@6.11.2, containing obfuscated JavaScript that executes when imported and downloads a second-stage payload from IPFS without relying on npm lifecycle scripts. The downloaded Miasma framework establishes persistence, supports encrypted command-and-control, shell execution, file operations and payload updates, and the malicious releases were traced to a GitHub Actions trusted publishing workflow built from a poisoned source commit.

Source: Socket

Progress Patches ShareFile Zero-Day After Emergency Shutdown

Progress Software confirmed that a high-severity path traversal vulnerability in ShareFile Storage Zone Controller prompted last week's emergency shutdown, affecting all 5.x and 6.x versions before fixes were released in versions 5.12.5 and 6.0.2. The flaw allows an authenticated administrative user to read arbitrary files, write attacker-controlled content to arbitrary directories and enumerate the server file system, while Progress said it has found no evidence of unauthorised customer account or data access and will publish the reserved CVE identifier after a delay.

SAP Fixes Critical Flaws in NetWeaver, Approuter, Commerce Cloud

SAP released 20 new and updated security notes on its July 2026 patch day, led by CVE-2026-44747, a memory corruption bug in NetWeaver Application Server ABAP rated 9.9 on the CVSS scale. A second critical issue, CVE-2026-27690, is an HTTP request smuggling flaw in Approuter affecting non-Cloud Foundry deployments, while CVE-2026-44761 involves hardcoded OAuth2 credentials in Commerce Cloud sample scripts, both rated 9.1. SAP also issued six high-severity notes covering Integration Suite, SAProuter, NetWeaver Application Server Java, Approuter, Commerce Cloud, and the Change and Transport System Attach Tool, alongside further medium- and low-severity fixes across S/4HANA, Fiori, CRM, and HANA Extended Application Services.

SonicWall Warns of Actively Exploited SMA1000 Flaws

SonicWall disclosed CVE-2026-15409, a maximum-severity server-side request forgery flaw in the SMA1000 Work Place interface that lets a remote unauthenticated attacker force the appliance to make unintended requests, scoring 10.0 on the CVSS scale. A second flaw, CVE-2026-15410, allows a remote authenticated administrator to execute arbitrary OS commands via code injection in the Management Console, rated 7.2. SonicWall confirmed active exploitation of both vulnerabilities affecting SMA1000 models 6210, 7210 and 8200v, with fixes available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835.

Source: SonicWall

Researchers Say Claude for Chrome Extension Flaw Remains Unpatched

Manifold Security reported that a trust-boundary vulnerability in the Claude for Chrome extension, dubbed ClaudeBleed, allows a synthetic click event to trigger privileged side-panel execution without genuine user interaction. Anthropic marked its internal tracking report for the issue resolved before 9 June 2026, yet Manifold verified on 7 July that the content script and side-panel handlers in version 1.0.80 remain byte-identical to the originally tested version 1.0.72. The researchers noted the flaw is not currently remotely exploitable since constructing a malicious side-panel URL still requires same-extension privilege, but warned any future bug exposing that construction to a lower-privileged context could escalate to silent privileged execution.

Spanish Police Dismantle €140 Million Fraud Network

Spanish Police, working with Interpol and Europol, dismantled a cybercrime and money-laundering organisation that generated €140 million through investment fraud and business email compromise attacks, arresting four suspects across Spain, Portugal and Panama. The network used more than 800 bank accounts and 67 money mules to launder €94 million confirmed as channelled through the group, with a further €61 million linked to BEC operations from 2024. Authorities raided six premises in Barcelona, Girona, Tarragona and Porto, seizing 15 computers and over 170 smartphones while freezing €3 million in crime proceeds for victims.

Malicious NuGet Packages Disguised as Game Cheats Deploy Downloader

Socket's Threat Research Team identified 11 malicious NuGet packages published as .NET command-line tools that pose as game utilities, bots and panels. Each package functions as a first-stage downloader that fetches a second-stage Windows payload named pepesoft.exe from GitHub Releases and Hugging Face, resolving download hosts via DNS-over-HTTPS to bypass system resolvers and local DNS sinkhole controls. The recovered PyInstaller-packed Python payloads authenticate to Google Sheets, bind activations to hardware, honour a remote ban-list, and in three cases expose Telegram bot commands capable of exfiltrating screenshots, with Socket reporting the packages to NuGet for removal.

Source: Socket

Daily Coverage

Developments
Patch Tuesday 622 CvesSonicwall Sma1000 ExploitedAsyncapi Miasma RatSap Netweaver Flaws
Vulnerabilities
CVE-2026-15409Sma1000 12.4.3-03245 (Critical)CVE-2026-15410Sma1000 12.4.3-03245 (High)CVE-2026-55040Microsoft Sharepoint Enterprise Server 2016 16.0.0 (Critical)CVE-2026-44747Sap Netweaver Application Server Abap Krnl64Nuc 7.22 (Critical)CVE-2026-56155Windows 10 Version 1607 10.0.14393.0 (High)CVE-2026-56164Microsoft Sharepoint Enterprise Server 2016 16.0.0 (Medium)CVE-2026-48939Icagenda Extension For Joomla 3.2.1-4.0.7 (Critical)CVE-2026-56291Balbooa.com Balbooa Forms Extension For Joomla 1.0-2.4.0 (Critical)CVE-2026-44761Sap Commerce Cloud Hy_Com 2205 (Critical)CVE-2026-27690Sap Approuter Sap Approuter Node.js Package < 20.10.0 (Critical)
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.