View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CyberPulse Digest β€” July 15, 2026

🚨 ACTIVE EXPLOITS & INCIDENTS

  • SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attacks-patch-now/ β€” SonicWall reports active exploitation of two zero-day vulnerabilities (CVE-2026-15409, CVE-2026-15410) in SMA1000 appliances. Immediate patching is critical to prevent unauthorized access and compromise.
  • Continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) https://www.tenable.com/blog/faq-about-the-continued-exploitation-of-cisco-catalyst-sd-wan-vulnerabilities-uat-8616 β€” Critical authentication bypass (CVSS 10.0) exploited by advanced threat actor UAT-8616 and others since 2023. POCs public; CISA mandates remediation. Patch all affected Cisco Catalyst SD-WAN Controller and Manager versions ASAP.
  • Drupal Core SQL Injection (CVE-2026-9082) https://www.tenable.com/blog/cve-2026-9082-highly-critical-sql-injection-vulnerability-in-drupal-core-sa-core-2026-004 β€” Highly critical SQLi affecting PostgreSQL-backed Drupal sites. Public PoC and exploitation attempts reported. Patch all supported Drupal branches immediately.
  • Mini Shai-Hulud: TeamPCP npm/PyPI supply chain worm https://www.tenable.com/blog/mini-shai-hulud-frequently-asked-questions β€” Self-propagating worm compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance. Targets developer and cloud credentials, including OpenAI and Mistral AI environments. Treat all installs as fully compromised and rotate credentials.

πŸ”“ VULNERABILITIES & CVEs

  • Microsoft July 2026 Patch Tuesday: 569 CVEs, 3 zero-days https://www.tenable.com/blog/microsofts-july-2026-patch-tuesday-addresses-569-cves-cve-2026-56155-cve-2026-56164 β€” Largest Patch Tuesday ever with 56 critical and 510 important fixes. Includes zero-days exploited in the wild. Key affected components: .NET, ASP.NET Core, Active Directory, Certificate Services. Prioritize deployment immediately.
  • Oracle June 2026 Critical Security Patch Update: 243 CVEs https://www.tenable.com/blog/oracle-june-2026-critical-security-patch-update-addresses-243-cves-cve-2026-35273 β€” 122 critical fixes, primarily targeting Oracle Fusion Middleware (106 patches). Monthly CSPU cadence introduced for faster high-severity patching. Urgent patching recommended.
  • Linux Kernel Privilege Escalation (CVE-2026-46300 β€œFragnesia”) https://www.tenable.com/blog/fragnesia-cve-2026-46300-faq-about-new-linux-kernel-xfrm-esp-in-tcp-priv-esc β€” New local priv-esc with public PoC targeting XFRM ESP-in-TCP subsystem. Patch released May 13; existing Dirty Frag mitigations insufficient. Confirmed on Ubuntu; no in-the-wild exploitation reported yet.
  • Multiple ASUS vulnerabilities (CVE-2026-13385, CVE-2026-15029, CVE-2026-15030, CVE-2026-13585, CVE-2026-8919, CVE-2026-8920) https://cve.threatint.eu β€” Includes remote MITM, local privilege escalation, memory disclosure, and NTLM hash theft via permissive cross-domain policies. Affected ASUS routers, System Control Interface, Business Manager, and GameSDK. Patch and mitigate accordingly.
  • TP-Link Kasa EC70/EC71 vulnerabilities (CVE-2026-13230, CVE-2026-9770) https://cve.threatint.eu β€” Information disclosure of geolocation and hardcoded cryptographic keys in firmware. Firmware update strongly advised.
  • jadx decompiler vulnerabilities (CVE-2026-54684, CVE-2026-42447, CVE-2026-42049) https://cve.threatint.eu β€” RCE via Groovy code injection, HTML injection, and arbitrary file write via crafted .xapk archives. Update jadx to 1.5.6 or later.
  • rclone authorization bypass and arbitrary file write (CVE-2026-59733, CVE-2026-54572) https://cve.threatint.eu β€” Authorization bypass in serve restic --private-repos and unvalidated symlink target leading to arbitrary file writes. Patch to rclone 1.74.4 or later.
  • HCL BigFix user enumeration (CVE-2026-21840) https://cve.threatint.eu β€” Timing-based user enumeration vulnerability. Monitor and apply vendor mitigations.

πŸ•΅οΈ THREAT RESEARCH & DEEP DIVES

  • Verizon DBIR 2026: Vulnerability exploitation surges as top breach vector https://www.tenable.com/blog/key-findings-from-the-verizon-dbir-2026 β€” Exploitation accounts for 31% of breaches; median patch time increased by 11 days. AI-driven vulnerability discovery accelerates risk. Emphasizes need for continuous exposure management and automated remediation.
  • CrowdStrike uncovers new prompt injection techniques https://www.crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques/ β€” Emerging attack vector targeting AI-driven workflows. Relevant for SOC teams integrating AI tools.
  • New abuse of ClickOnce technology (Parts 1 & 2) https://www.crowdstrike.com/en-us/blog/new-abuse-of-the-clickonce-technology-part-one/ https://www.crowdstrike.com/en-us/blog/new-abuse-of-the-clickonce-technology-part-two/ β€” Detailed analysis of threat actor techniques leveraging ClickOnce for persistent footholds.

πŸ“‹ VENDOR BULLETINS & ADVISORIES

  • White House β€˜Gold Eagle’ clearinghouse for AI cyber threats https://cyberscoop.com/trump-gold-eagle-ai-cyber-clearinghouse/ β€” Centralized intelligence sharing on AI-related vulnerabilities and prioritization of patches. Relevant for organizations managing AI security risks.
  • AWS June 2026 Security Updates https://aws.amazon.com/blogs/security/icymi-june-2026-aws-security/ β€” New features and compliance updates focused on identity, access management, network security, and AI-powered security tooling. Review for cloud security posture improvements.

πŸ“° LESSER-KNOWN / UNDER-REPORTED

  • Ciena Navigator and Blue Planet authentication bypasses (CVE-2026-5269, CVE-2026-5270) https://cve.threatint.eu β€” Hidden system accounts with default passwords and auth bypass in network management suites. Patch and audit credentials immediately.
  • Multiple zhinianboke xianyu-auto-reply API authorization flaws (CVE-2026-15752, CVE-2026-15753) https://cve.threatint.eu β€” Authorization bypasses in payment and user endpoints. Assess exposure and apply fixes.
  • @metacurity: β€œbugmageddon is here!” https://infosec.exchange/@metacurity/116920505055440672 β€” Community alert on unprecedented volume of vulnerabilities this month, aligning with record-breaking Patch Tuesday.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check