Skip to content
Auto-CTI

What has changed?

Comparing 23 July 2026 with the previous day 16 July 2026.

Newly added

61
NEW B2
80

Russian Global Webmail Espionage

Russian APT group conducts campaign exploiting zero-click vulnerability in Zimbra Collaboration Suite to exfiltrate credentials and email archives from European organizations.

Critical
NEW C3
63

Microsoft SharePoint: Attacks on further security vulnerability

CISA warns of active exploitation of another SharePoint security vulnerability (in addition to cases reported in July) and CVE-2026-16232 in Check Point SmartConsole (CVSS 9.1), without disclosing details on attack scope or attacker tactics.

Critical
A3
20

[UPDATE] GNU libc: Multiple Vulnerabilities

The BSI warning regarding multiple GNU libc vulnerabilities requires verification of specific CVE numbers and KEV status for prioritizing patches on Ubuntu systems.

High
A3
20

[UPDATE] OpenSSL: Multiple Vulnerabilities

BSI security advisory alerts to multiple OpenSSL vulnerabilities without naming specific CVE numbers or version details; further information is required to determine affected versions.

High
NEW A3
20

[UPDATE] Google Chrome: Multiple Vulnerabilities

BSI warning on multiple Chrome vulnerabilities with potential code execution , exact CVE numbers and CVSS scores not specified, so unclear whether already patched or still actively exploited.

High
NEW A3
20

Google Chrome: Multiple Vulnerabilities

BSI warns of multiple Chrome vulnerabilities without specific CVE details, suggesting a general patch advisory; organizations should deploy Chrome updates promptly.

High
NEW C3
20

Forgotten Bootloaders Expose Secure Boot Blind Spot

Revoked UEFI bootloaders remain visible in trust lists for years even after revocation, enabling Secure Boot bypasses , a governance oversight with implications for firmware integrity on Windows and Linux servers.

High
A3
20

Mozilla Firefox: Multiple Vulnerabilities

BSI warns of multiple unspecified vulnerabilities in Firefox enabling code execution and security bypass , user interaction via file or link opening required.

High
NEW B3
0

Email threat landscape: Q2 2026 trends and insights

Microsoft's disruption of the Tycoon2FA platform resulted in a 92% reduction in associated phishing volume in Q2 2026, but no single service replaced it at comparable scale , threat actors are fragmenting their infrastructure.

Medium

Newly KEV-listed

0

No changes in this category.

Score moved

0

No changes in this category.

No longer in report

0

No changes in this category.

ESC