THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft’s “Patchpocalypse”: July 2026 ships 622 fixes, including two zero-days under active exploitation

Microsoft’s July 2026 Patch Tuesday delivered updates for 622 vulnerabilities, including 57 marked “critical,” across Windows and a wide range of enterprise products. The release also notes that two vulnerabilities disclosed this month have already been exploited in the wild—an urgent reminder that even newly published flaws can move quickly from advisory to incident.

For defenders, the key takeaway is prioritization: quickly validate internet-exposed services and identity-adjacent infrastructure (AD FS, SharePoint, RDP, Exchange) first, then address the rest of the stack on an expedited rollout plan.

Source: SecurityWeek


SonicWall warns of active exploitation of two SMA 1000 zero-days (CVE-2026-15409, CVE-2026-15410)

SonicWall has confirmed active attacks targeting its Secure Mobile Access (SMA) 1000 Series appliances, tied to two zero-day vulnerabilities: CVE-2026-15409 and CVE-2026-15410. The company urges customers to upgrade to fixed firmware and to search for indicators of compromise, including guidance such as password resets and TOTP token handling.

The operational insight: network edge and remote-access appliances remain high-value targets, and “patch then re-image/redeploy” scenarios should be assumed when exploitation is confirmed.

Source: Help Net Security


New macOS stealer “CrashStealer” poses as Apple CrashReporter to steal passwords and crypto wallets

Jamf Threat Labs reports a new macOS infostealer, CrashStealer, disguised as Apple’s crash-reporting tool. The malware targets sensitive data including Keychain items, browser data, and cryptocurrency wallets, and Jamf observed a transition from detection in development to in-the-wild activity by early July.

For incident responders, this reinforces a broader trend: on macOS, signed-looking or legitimate-branded themes are increasingly used to reduce user and security friction, so verification controls and behavioral detection matter.

Source: Help Net Security


ShinyHunters targets Salesforce via OAuth trust abuse—malicious apps trick users into authorizing permissions

Reported activity by the ShinyHunters group focuses on exploiting OAuth trust by tricking Salesforce users into authorizing a malicious Salesforce Data Loader application. The attack then uses OAuth permissions to progress beyond initial access while blending into normal authorization flows.

The defender’s takeaway: authorization events are not a guarantee of legitimacy—security teams should monitor for abnormal OAuth consent patterns, newly seen applications, and permission scopes that exceed typical behavior.

Source: SC Media


White House launches “Gold Eagle” AI clearinghouse to coordinate vulnerability intelligence and patching

The White House has announced an AI-driven initiative (“Gold Eagle”) intended to coordinate vulnerability intelligence for AI-related cyber threats. The program is positioned as a response to an earlier executive order calling on advanced AI developers to provide early access to capabilities that could help address vulnerabilities.

Policy implication: the operational security impact may be significant—rapid triage and prioritization could change how quickly AI-relevant flaws get surfaced and remediated, shifting the vulnerability lifecycle toward earlier collaboration.

Source: CyberScoop


Compromised npm ecosystem: multiple Jscrambler packages poisoned to drop cross-platform credential stealers

Security reporting indicates that several Jscrambler npm packages were impacted by a supply-chain attack, resulting in a cross-platform credential stealer. Similar patterns continue to appear across the JavaScript package ecosystem: attackers poison specific versions to reach developers through routine dependency installation.

Key defense insight: SBOMs and dependency inventory are table stakes, but teams also need version pinning, integrity checks, and fast revocation/containment procedures when package compromise is confirmed.

Source: SecurityWeek


You May Also Be Interested In...
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft Entra ID authentication overhaul to start in September 2026
SingGuard-NSFA: Open-source guardrails for agentic AI
Cybersecurity — July 15, 2026 | Briefing24