NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Three Microsoft SharePoint Server vulnerabilities are under active exploitation to gain unauthorized access and deploy malware for persistent access; CISA has issued a hardening alert.
Although this vulnerability requires authorized network access, it enables code execution within a core productivity AI system increasingly integrated into enterprise workflows.
Network-accessible heap overflow in Microsoft Account enables remote code execution without user interaction , priority for immediate patching and network isolation of critical authentication systems.
An authentication vulnerability in Exchange Online could allow attackers to access email accounts or tamper with their contents without legitimate credentials , a critical vector for business disruption and data loss in cloud-based environments.
An authentication vulnerability in Azure DNS allows unauthorized attackers to escalate network privileges, potentially compromising access to cloud-hosted services.
The vulnerability allows authenticated network attackers to execute code in Azure APIM, indicating insufficient access control for API management operations.
An authentication vulnerability in Azure Key Vault enables unauthorized access and privilege escalation over the network, affecting core identity and access control infrastructure.
Western intelligence agencies warn of active Russian hacking campaigns against Zimbra mail servers, indicating the use of cyber operations in the context of geopolitical tensions.
A vulnerability in Microsoft Graph allows authenticated attackers to disclose sensitive information over the network; the CVE is already covered by NVD and vendor security advisories.
Critical
CVSS
6.5
EPSS
0%
NEW Iran-linked APT (Cavern Manticore operators) B3
Cavern Manticore is a modular Iran-controlled C2 framework indicating infrastructure-targeting and distributed attack capabilities threatening Western targets in critical sectors.
Critical
NEW Laundry Bear (Void Blizzard, CL-STA-1114, TA488, UNK_PitStop) C3
Russian intelligence-linked APT group Laundry Bear has been exploiting a zero-day in Zimbra since July 2025 to target email systems in Western government institutions, escalating from basic phishing techniques to sophisticated attacks.
UAC-0099 uses trojaned Notepad++ plugins as a social-engineering vector to deliver MATCHBOIL.V2 malware into Windows environments, with the camouflage pattern presenting significant detection risk for organizations relying on signature-based detection of popular development software.
Large-scale npm supply-chain compromise with injected malware loader exfiltrating environment variables (GitHub tokens, API keys, database credentials) and establishing persistence via Node.js masquerade , immediate threat to all organizations with AsyncAPI dependencies.
A BSI alert on multiple Ubiquiti UniFi OS vulnerabilities indicates elevated risk to network-perimeter security in European manufacturing environments.
The July 2026 patch cycle marks a turning point: 622 vulnerabilities (62 critical, 3 zero-days) demonstrate accelerated vulnerability discovery by AI frontier models; simultaneously, novel malware families (StarLand RAT, WLDR C2, ARToken MFA-bypass) are active in campaigns , combined pressure on Windows/Microsoft 365 environments.
Russian-speaking threat group employing multistage campaign with novel RAT and proprietary PowerShell C2 against European targets since June 2025, using HTA/ClickFix as initial exploitation vector.
BSI warns of multiple unspecified Edge vulnerabilities with variable exploitability , without CVE numbers or patch status, the concrete threat level is unclear and requires Microsoft security advisories for prioritization.
An unauthenticated, remotely exploitable heap buffer overflow in 7-Zip enables code execution during XZ file processing, but requires user interaction to trigger.
BSI warns of multiple vulnerabilities in Adobe Creative Cloud without specific CVE details; exploitation requires user interaction (maliciously crafted files).
The vulnerability enables a sandbox escape from the Chrome renderer process, allowing escalation from renderer compromises to full system control if an attacker can already execute code in the renderer.
A use-after-free vulnerability in the WebMCP component allows attackers to execute arbitrary code within the Chrome sandbox without requiring local privilege escalation.
An out-of-bounds write vulnerability enables potential sandbox escape in Chrome, allowing local code execution with elevated privileges following successful website exploitation.
A use-after-free vulnerability in the Blink engine enables remote code execution within Chrome's sandbox via crafted HTML pages; the vulnerability is already documented in NVD and Chromium security advisories and affects all current Chrome installations.
BSI warning for multiple unspecified vulnerabilities in Chrome/Edge without listing specific CVE IDs or version details; likely a generic aggregate notice for ongoing browser updates.
The BSI warns of multiple undisclosed vulnerabilities in two widely-used enterprise browsers that can be exploited by simply opening a malicious webpage,a high attack surface in daily office use.
The BSI warns of multiple unspecified vulnerabilities in Chrome without publication of CVE details; this suggests coordinated disclosure or embargoed vulnerability information not yet fully released.
Multiple vulnerabilities in 7-Zip enable arbitrary code execution through opening malformed archives; patching is critical given the application's widespread use.
An angry security researcher has publicly disclosed a zero-day exploit enabling local administrator privilege escalation on Windows systems before a patch is available, creating immediate risk for exposed or poorly segmented infrastructure.
The Cursor vulnerability illustrates a fundamental disclosure dilemma: responsible disclosure fails when vendors do not respond promptly, forcing security researchers toward full disclosure as a last resort.