Microsoft July 2026 Patch Tuesday scheduled for July 14 following record-breaking June release of 200 vulnerabilities. Expected 100-140 CVEs representing normalization from June's extraordinary volume while maintaining elevated 2026 baseline. June included 116 CVEs for Windows 11, 104 for Windows 10.
Plan Patch Tuesday deployment for July 14, 2026. Prioritize critical and actively exploited vulnerabilities. Test patches in lab environment before production deployment. Schedule maintenance windows. Review Microsoft Security Response Center guidance.
Source: MSRC • Published: 2026-07-14
GhostApproval symlink attack affects 6 AI coding assistants enabling file access outside workspace sandbox. Exploits symbolic link following to trick privileged processes. Amazon, Cursor, Google fixed; Augment and Windsurf remain unpatched despite acknowledgment.
Update patched assistants immediately: Amazon Q to v1.69.0+, Cursor to 3.0+, Google Antigravity to May 22 version. Discontinue use of Augment and Windsurf until patches available. Implement file access monitoring and symlink detection.
Source: GTIG • Published: 2026-07-08
First documented fully autonomous AI-driven ransomware operation. JADEPUFFER gained access via CVE-2025-3248 in Langflow, conducted adaptive automated campaign including database extortion. Encrypted 1342 Nacos service configurations with unrecoverable AES keys. Demonstrates LLM autonomous attack capabilities including 31-second failure recovery.
Patch all Langflow instances immediately (CVE-2025-3248). Implement AI agent activity monitoring and behavioral analysis. Restrict LLM agent permissions using least privilege. Deploy anomaly detection for autonomous agent operations. Maintain offline backups.
Source: GTIG • Published: 2026-07-01
FBI FLASH alert on TeamPCP supply chain campaign affecting 1,000+ organizations. Compromised widely-used developer and security tools to steal credentials. Deployed CanisterWorm, SANDCLOCK, Mini Shai-Hulud, and Miasma malware families. Harvests cloud tokens, SSH keys, Kubernetes secrets from CI/CD pipelines.
Search GitHub for 'tpcp-docs' or 'docs-tpcp' repositories. Rotate all cloud credentials, SSH keys, API tokens. Enforce least-privilege on CI/CD service accounts. Implement token scoping. Verify integrity of Trivy, KICS, LiteLLM, Telnyx SDK installations.
Source: GTIG • Published: 2026-07-02
Threat actor used compromised credentials to publish malicious Trivy v0.69.4, force-push 76 of 77 version tags in aquasecurity/trivy-action to credential-stealing malware, and replace all 7 tags in aquasecurity/setup-trivy with malicious commits. Exposure window March 19-24, 2026.
Verify Trivy installation integrity using official checksums. Reinstall Trivy from verified sources. Rotate all credentials accessible during March 19-24, 2026. Audit container scanning pipelines for indicators of compromise. Review Trivy action versions in CI/CD.
Source: GTIG • Published: 2026-03-19
Sophos report warns TeamPCP partnered with Vect ransomware gang. Compromised 4 widely-deployed security and AI tooling packages, propagated worm across 48+ npm packages, impacting over 1,000 enterprise SaaS environments. Represents escalation from supply chain reconnaissance to ransomware deployment.
Review FBI TeamPCP indicators of compromise. Audit npm package dependencies for known malicious packages. Rotate all development, CI/CD, and cloud credentials. Implement software composition analysis and dependency scanning. Monitor for Vect ransomware indicators.
Source: GTIG • Published: 2026-07-02
ShinyHunters threat group breached Medtronic in April 2026, affecting 3.8 million individuals. Unauthorized access to IT systems April 13-19, 2026. Stolen data includes names, contact info, DOB, SSNs, and health-related information. ShinyHunters claimed 9 million records stolen.
Affected individuals should enroll in offered two years complimentary credit monitoring and identity protection. Monitor for identity theft and fraudulent account activity. Implement fraud alerts with credit bureaus. Review medical records for unauthorized access.
Source: BleepingComputer • Published: 2026-07-02
ServiceNow security incident after attackers exploited unauthenticated access flaw in vulnerable API endpoint. Malicious activity began June 2, 2026, with bug bounty reports June 3-4. Allowed unauthorized users to query data from ServiceNow instance tables. Security update applied June 5, 2026.
Verify ServiceNow instances updated with June 5, 2026 security patch. Review API authentication and authorization configurations. Audit access logs for June 2-5 timeframe. Implement API rate limiting and monitoring. Rotate ServiceNow credentials.
Source: BleepingComputer • Published: 2026-06-05
Rash of cyberattacks across Europe targeting civilian energy and water supplies attributed to Russia. Attacks targeted Poland's energy grid with destructive malware, Swedish thermal plant, Norwegian dam, Polish water treatment plants. Risks real-world harm to communities and populations.
Implement critical infrastructure protection measures including network segmentation, air-gapping, and operational technology monitoring. Coordinate with national cybersecurity agencies. Deploy industrial control system security solutions. Conduct tabletop exercises for cyber-physical attack scenarios.
Source: GTIG • Published: 2026-07-01
Industry experiencing 'patch apocalypse' with nearly 600 CVEs including Chrome, Edge, and third-party flaws. AI-accelerated vulnerability discovery driving unprecedented disclosure volumes. CVE disclosure volumes tripled over five-year span. First-generation LLMs significantly accelerated vulnerability identification in H1 2026.
Implement risk-based patch management prioritizing actively exploited and critical vulnerabilities. Adopt automated vulnerability scanning and patch deployment. Increase patch management resources and tooling. Monitor CISA KEV catalog for exploitation trends.
Source: GTIG • Published: 2026-07-01
NIST announced fundamental change to NVD operations transitioning to heavily constrained, risk-based model for vulnerability enrichment. Driven by unprecedented CVE surge with disclosure volumes tripling over five years. Demands immediate strategic response from organizations consuming NVD data.
Diversify vulnerability intelligence sources beyond NVD. Implement commercial vulnerability databases and threat intelligence feeds. Develop internal CVE prioritization frameworks. Automate vulnerability correlation across multiple data sources.
Source: GTIG • Published: 2026-04-15
JADEPUFFER-RANSOMWARE: First documented fully autonomous AI-driven ransomware operation. JADEPUFFER gained access via CVE-2025-3248 in Langflow, conducted adaptive automated campaign including database extortion. Encrypted 1342 Nacos service configurations with unrecoverable AES keys. Demonstrates LLM autonomous attack capabilities including 31-second failure recovery.