Skip to content
Auto-CTI

What has changed?

Comparing 24 July 2026 with the previous day 23 July 2026.

Newly added

34
NEW A2
100

CVE-2026-58275

An authentication vulnerability in Azure DNS allows unauthorized attackers to escalate network privileges, potentially compromising access to cloud-hosted services.

Critical CVSS 10.0 EPSS 0%
NEW Iran-linked APT (Cavern Manticore operators) B3
75

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Cavern Manticore is a modular Iran-controlled C2 framework indicating infrastructure-targeting and distributed attack capabilities threatening Western targets in critical sectors.

Critical
NEW Laundry Bear (Void Blizzard, CL-STA-1114, TA488, UNK_PitStop) C3
75

Russian Attackers Exploit Zero-Click Vulnerability in Zimbra

Russian intelligence-linked APT group Laundry Bear has been exploiting a zero-day in Zimbra since July 2025 to target email systems in Western government institutions, escalating from basic phishing techniques to sophisticated attacks.

Critical
NEW UAC-0099 C3
75

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

UAC-0099 uses trojaned Notepad++ plugins as a social-engineering vector to deliver MATCHBOIL.V2 malware into Windows environments, with the camouflage pattern presenting significant detection risk for organizations relying on signature-based detection of popular development software.

Critical
A3
37

Ubiquiti UniFi OS: Multiple Vulnerabilities

A BSI alert on multiple Ubiquiti UniFi OS vulnerabilities indicates elevated risk to network-perimeter security in European manufacturing environments.

Critical
NEW B3
32

Begun, the Patch Wars have

The July 2026 patch cycle marks a turning point: 622 vulnerabilities (62 critical, 3 zero-days) demonstrate accelerated vulnerability discovery by AI frontier models; simultaneously, novel malware families (StarLand RAT, WLDR C2, ARToken MFA-bypass) are active in campaigns , combined pressure on Windows/Microsoft 365 environments.

Critical
A3
20

Microsoft Edge: Multiple Vulnerabilities

BSI warns of multiple unspecified Edge vulnerabilities with variable exploitability , without CVE numbers or patch status, the concrete threat level is unclear and requires Microsoft security advisories for prioritization.

High
NEW A3
20

7-Zip: Vulnerability Enables Code Execution

An unauthenticated, remotely exploitable heap buffer overflow in 7-Zip enables code execution during XZ file processing, but requires user interaction to trigger.

High
NEW C3
20

Adobe Chrome Extension Enabled Data Theft

A widely deployed browser extension with data access enabled unauthorized data access without disclosing active exploit details or CVE numbers.

High
A3
20

7-Zip: Multiple Vulnerabilities

Multiple vulnerabilities in 7-Zip enable arbitrary code execution through opening malformed archives; patching is critical given the application's widespread use.

High
NEW C3
17

Full Disclosure as Self-Defense: The Cursor Zero Day

The Cursor vulnerability illustrates a fundamental disclosure dilemma: responsible disclosure fails when vendors do not respond promptly, forcing security researchers toward full disclosure as a last resort.

High

Newly KEV-listed

0

No changes in this category.

Score moved

0

No changes in this category.

No longer in report

61
NEW B2
80

Russian Global Webmail Espionage

Russian APT group conducts campaign exploiting zero-click vulnerability in Zimbra Collaboration Suite to exfiltrate credentials and email archives from European organizations.

Critical
NEW C3
63

Microsoft SharePoint: Attacks on further security vulnerability

CISA warns of active exploitation of another SharePoint security vulnerability (in addition to cases reported in July) and CVE-2026-16232 in Check Point SmartConsole (CVSS 9.1), without disclosing details on attack scope or attacker tactics.

Critical
A3
20

[UPDATE] GNU libc: Multiple Vulnerabilities

The BSI warning regarding multiple GNU libc vulnerabilities requires verification of specific CVE numbers and KEV status for prioritizing patches on Ubuntu systems.

High
A3
20

[UPDATE] OpenSSL: Multiple Vulnerabilities

BSI security advisory alerts to multiple OpenSSL vulnerabilities without naming specific CVE numbers or version details; further information is required to determine affected versions.

High
NEW A3
20

[UPDATE] Google Chrome: Multiple Vulnerabilities

BSI warning on multiple Chrome vulnerabilities with potential code execution , exact CVE numbers and CVSS scores not specified, so unclear whether already patched or still actively exploited.

High
NEW A3
20

Google Chrome: Multiple Vulnerabilities

BSI warns of multiple Chrome vulnerabilities without specific CVE details, suggesting a general patch advisory; organizations should deploy Chrome updates promptly.

High
NEW C3
20

Forgotten Bootloaders Expose Secure Boot Blind Spot

Revoked UEFI bootloaders remain visible in trust lists for years even after revocation, enabling Secure Boot bypasses , a governance oversight with implications for firmware integrity on Windows and Linux servers.

High
A3
20

Mozilla Firefox: Multiple Vulnerabilities

BSI warns of multiple unspecified vulnerabilities in Firefox enabling code execution and security bypass , user interaction via file or link opening required.

High
NEW B3
0

Email threat landscape: Q2 2026 trends and insights

Microsoft's disruption of the Tycoon2FA platform resulted in a 92% reduction in associated phishing volume in Q2 2026, but no single service replaced it at comparable scale , threat actors are fragmenting their infrastructure.

Medium
ESC