Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: July 10, 2026 - July 10, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Friday, July 10, 2026 +9% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

ADOBE-CF-2026-CRITICAL — Adobe ColdFusion

Adobe ColdFusion received 11 critical vulnerabilities patched, with 6 carrying maximum CVSS 10.0 score—all enabling unauthenticated arbitrary code execution on ColdFusion servers. Adobe assigned highest priority rating and recommends patching within 72 hours. ColdFusion has 16 CVEs already in CISA KEV catalog.

REMEDIATION

Update to ColdFusion 2025.9 or 2023.20 immediately; restrict network access to ColdFusion servers to authorized personnel only.

Source: NVD  •  Published: 2026-07-10

[CRITICAL]

CVE-2026-40138 — BeyondTrust Remote Support

Critical pre-authentication vulnerability with CVSS 9.2 stemming from improper validation of authentication data that could allow network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Related CVE-2026-40139 and CVE-2026-1731 also affect Remote Support and Privileged Remote Access appliances.

REMEDIATION

Apply April 2026 Security Rollup immediately or upgrade to RS/PRA version 25.3.3 or later. Restrict network access to BeyondTrust appliances.

Source: NVD  •  Published: 2026-07-10

[CRITICAL]

CHROME-151-2026 — Google Chrome

Google released Chrome 151 patching 382 vulnerabilities, including 15 critical flaws enabling remote code execution—an extraordinary number for a single browser release. Multiple critical RCE vulnerabilities could allow attackers to execute arbitrary code through crafted web content.

REMEDIATION

Update Chrome immediately to version 151 or later. Enable automatic updates for Chrome across all endpoints and verify deployment.

Source: Web  •  Published: 2026-07-10

AI & Supply Chain

[CRITICAL]

FBI-TEAMCP-2026 — Trivy, KICS, LiteLLM, Telnyx SDK

FBI FLASH alert identifies TeamPCP compromising widely used developer and security tools to steal credentials at scale. Modified tools including Trivy, KICS, LiteLLM, and Telnyx Python SDK commonly integrated into enterprise CI/CD pipelines. CanisterWorm payload harvests cloud access tokens, credentials, API keys for AWS, GCP, and Azure.

REMEDIATION

Search GitHub repositories for 'tpcp-docs' or 'docs-tpcp' repositories. Enforce least-privilege permissions on CI/CD service accounts. Require phishing-resistant MFA for all code repository accounts. Audit all security and developer tool dependencies. Implement software bill of materials (SBOM) tracking.

Source: CISA  •  Published: 2026-07-02

[HIGH]

AI-CODE-VULN-2026 — AI Code Generation Tools

2026 AI Code Security Report reveals 92% of AI-generated codebases contain at least one critical vulnerability, with average vibe-coded application having 8.3 exploitable findings. 45% of AI-generated code introduces known security flaws. 73% of AI deployments have at least one exploitable vulnerability.

REMEDIATION

Implement mandatory manual security assessments for all AI-generated code before production deployment. Deploy static application security testing (SAST) on all AI-generated code. Establish AI code review processes with security focus. Train developers on secure prompt engineering practices.

Source: Veracode  •  Published: 2026-07-10

[MEDIUM]

PHANTOM-SQUATTING-2026 — LLM Applications

New LLM-driven attack vector called phantom squatting where cybercriminals register nonexistent domains hallucinated by AI models and linked to legitimate brands. Analysis of 913 global brands via 685,339 URL queries generated 250,000 hallucinated domains. One attacker used AI coding assistant to build full phishing kit targeting high-risk phantom domain.

REMEDIATION

Organizations should proactively register commonly hallucinated domain variants of their brands. Implement strict domain validation in AI applications. Monitor for registration of domains similar to your brand. Deploy DNS monitoring and brand protection services.

Source: Web  •  Published: 2026-07-10

Threat Actors & Dark Web

[CRITICAL]

FORTIBLEED-2026 — Fortinet Firewalls

FortiBleed campaign linked to INC Ransom and Lynx ransomware groups involved intercepting SSL VPN authentication hashes from over 430,000 targeted Fortinet firewalls, cracking them with 45-GPU cluster, and using credentials to gain admin-level access and persistence within victim Active Directory. SOC Radar confirmed admin access on 409 targets and full attack chain execution on 354.

REMEDIATION

Fortinet users must ensure PBKDF2 is enabled for credential storage. Verify all admin accounts have recently re-authenticated. Force password resets for all VPN users. Implement certificate-based authentication where possible. Monitor for unusual admin account activity.

Source: Web  •  Published: 2026-07-10

[CRITICAL]

KDDI-BREACH-2026 — KDDI Email System

Japanese telco KDDI disclosed data breach of email system used by five ISPs exposing email addresses and passwords of up to 14.22 million customers. Only some passwords were hashed, with many stored in plaintext. Unclear how many credentials were hashed or what algorithm was used.

REMEDIATION

All affected users must immediately change passwords for KDDI and any accounts using same credentials. Enable MFA where available. KDDI must implement immediate password hashing with strong algorithms (bcrypt/Argon2) and eliminate plaintext storage. Notify all affected customers and provide identity monitoring services.

Source: BleepingComputer  •  Published: 2026-07-10

[CRITICAL]

CONDUENT-RANSOMWARE-2026 — Conduent Healthcare Systems

Conduent ransomware breach expanded to affect more than 62.2 million individuals by July 2026. Exposed data includes Social Security numbers, medical information, health insurance data, and other personal details. One of largest healthcare breaches recorded.

REMEDIATION

All affected individuals should freeze credit immediately with all three bureaus, monitor for identity theft, and enable healthcare fraud alerts. Conduent must provide comprehensive identity monitoring and restoration services. Organizations using Conduent should review contracts and implement additional monitoring of exposed patient data.

Source: BleepingComputer  •  Published: 2026-07-10

[HIGH]

STORM-2603-WARLOCK — Microsoft SharePoint

Microsoft revealed Storm-2603 threat actor deploying Warlock ransomware by exploiting known vulnerabilities in on-premises SharePoint servers since mid-2025. Investigation uncovered two unrelated attackers operating simultaneously within same network, indicating multiple threat actors increasingly targeting same victims.

REMEDIATION

Apply all SharePoint security updates immediately, particularly May 2026 patches. Implement network segmentation to isolate SharePoint servers. Deploy EDR with ransomware detection on all SharePoint infrastructure. Monitor for multiple concurrent intrusion attempts.

Source: MSRC  •  Published: 2026-07-10

[HIGH]

GODDAMN-RANSOMWARE-2026 — Windows Systems

New ransomware family called GodDamn employs PoisonX kernel driver to neutralize security software as part of defense evasion strategy. Represents evolution in ransomware techniques using kernel-level access to disable endpoint protection.

REMEDIATION

Implement driver signature verification policies across all Windows endpoints. Monitor for unauthorized kernel driver installations using EDR. Enable Windows Defender Application Control or similar whitelisting. Deploy behavioral detection for security software tampering.

Source: Web  •  Published: 2026-07-10

[HIGH]

ACCENTURE-BREACH-2026 — Accenture Azure DevOps

Accenture suffered data breach in July 2026 with threat actor claiming theft of 35GB source code including RSA keys, SSH keys, Azure personal access tokens, Azure Storage access keys, and configuration files from private Azure DevOps repository. Accenture confirmed awareness but did not confirm data exfiltration. Serves many Fortune 500 companies creating supply chain attack risk.

REMEDIATION

Accenture must immediately rotate all exposed credentials including RSA keys, SSH keys, Azure PATs, and storage access keys. Conduct forensic investigation to determine full extent of compromise. Notify affected clients of potential supply chain risk. Implement secrets scanning in all repositories and strengthen Azure DevOps access controls.

Source: BleepingComputer  •  Published: 2026-07-10

Priority Action Matrix

01DO NOWADOBE-CF-2026-CRITICAL (Adobe ColdFusion): Update to ColdFusion 2025.9 or 2023.20 immediately; restrict network access to ColdFusion servers to authorized personnel only.
02DO NOWCVE-2026-40138 (BeyondTrust Remote Support): Apply April 2026 Security Rollup immediately or upgrade to RS/PRA version 25.3.3 or later. Restrict network access to BeyondTrust appliances.
03DO NOWCHROME-151-2026 (Google Chrome): Update Chrome immediately to version 151 or later. Enable automatic updates for Chrome across all endpoints and verify deployment.
04DO NOWFBI-TEAMCP-2026 (Trivy, KICS, LiteLLM, Telnyx SDK): Search GitHub repositories for 'tpcp-docs' or 'docs-tpcp' repositories. Enforce least-privilege permissions on CI/CD service accounts. Require phishing-resistant MFA for all code repository accounts. ...
05DO NOWFORTIBLEED-2026 (Fortinet Firewalls): Fortinet users must ensure PBKDF2 is enabled for credential storage. Verify all admin accounts have recently re-authenticated. Force password resets for all VPN users. Implement certificate-based auth...
06DO NOWKDDI-BREACH-2026 (KDDI Email System): All affected users must immediately change passwords for KDDI and any accounts using same credentials. Enable MFA where available. KDDI must implement immediate password hashing with strong algorithms...
07DO NOWCONDUENT-RANSOMWARE-2026 (Conduent Healthcare Systems): All affected individuals should freeze credit immediately with all three bureaus, monitor for identity theft, and enable healthcare fraud alerts. Conduent must provide comprehensive identity monitorin...
08TODAYAI-CODE-VULN-2026 (AI Code Generation Tools): Implement mandatory manual security assessments for all AI-generated code before production deployment. Deploy static application security testing (SAST) on all AI-generated code. Establish AI code re...
09TODAYSTORM-2603-WARLOCK (Microsoft SharePoint): Apply all SharePoint security updates immediately, particularly May 2026 patches. Implement network segmentation to isolate SharePoint servers. Deploy EDR with ransomware detection on all SharePoint i...
10TODAYGODDAMN-RANSOMWARE-2026 (Windows Systems): Implement driver signature verification policies across all Windows endpoints. Monitor for unauthorized kernel driver installations using EDR. Enable Windows Defender Application Control or similar wh...
11TODAYACCENTURE-BREACH-2026 (Accenture Azure DevOps): Accenture must immediately rotate all exposed credentials including RSA keys, SSH keys, Azure PATs, and storage access keys. Conduct forensic investigation to determine full extent of compromise. Noti...
12THIS WEEKPHANTOM-SQUATTING-2026 (LLM Applications): Organizations should proactively register commonly hallucinated domain variants of their brands. Implement strict domain validation in AI applications. Monitor for registration of domains similar to y...

Biggest Risk This Period

BIGGEST RISK

ADOBE-CF-2026-CRITICAL: Adobe ColdFusion received 11 critical vulnerabilities patched, with 6 carrying maximum CVSS 10.0 score—all enabling unauthenticated arbitrary code execution on ColdFusion servers. Adobe assigned highest priority rating and recommends patching within 72 hours. ColdFusion has 16 CVEs already in CISA KEV catalog.