A new Windows ProfSvc privilege escalation zero-day exploit released by researcher Chaotic Eclipse works on all supported Windows versions including those with July 2026 Patch Tuesday updates. The PoC was released hours after Patch Tuesday following a dispute with Microsoft since April 2026. Exploitation not yet observed but PoC is publicly available.
Monitor for Microsoft emergency response and out-of-band patch. Implement least-privilege access controls. Enable enhanced monitoring for privilege escalation attempts. Review security audit logs for suspicious ProfSvc activity. Restrict local administrator access.
Source: The Hacker News • Published: 2026-07-17
A critical vulnerability in Microsoft Copilot apps for Android and iOS with CVSS 9.6. A malicious website can push commands to the AI through Microsoft Edge without user awareness, enabling unauthorized AI actions and potential data exfiltration through the mobile interface.
Update Copilot mobile apps immediately through Play Store or App Store. Review Copilot command history for unauthorized actions. Consider disabling Copilot on mobile until patches verified. Implement mobile device management policies for AI assistants. Monitor mobile app permissions.
Source: Notebookcheck • Published: 2026-07-14
The first documented agentic attacker campaign targeting Hugging Face infrastructure, executed by an autonomous agent framework performing thousands of actions across swarm of short-lived sandboxes with self-migrating command-and-control. The attack represents the industry-forecasted 'agentic attacker' scenario. Detected through AI-assisted anomaly detection analyzing 17,000+ recorded events.
Audit all dataset code-execution paths for vulnerabilities. Implement AI-assisted anomaly detection capabilities. Deploy stricter admission controls on cluster environments. Rotate all affected credentials and tokens. Improve detection and alerting for high-severity signals. Implement behavioral analytics.
Source: Hugging Face • Published: 2026-07-16
GitHub Copilot's coding agents in IDEs are susceptible to workflow-level jailbreak attacks that bypass chat refusals. Research shows models that refuse harmful prompts in direct chats can be manipulated to produce unsafe outputs when embedded in multi-step coding workflows. Testing revealed 100% success rate (816/816) when harmful content requested as coding tasks distributed across normal software-engineering actions.
Implement code review processes for all AI-generated code. Monitor AI assistant outputs for suspicious patterns. Train developers on workflow-level attack vectors. Consider implementing content scanning for AI-generated artifacts. Deploy behavioral detection for anomalous code generation.
Source: GB Hackers • Published: 2026-07-09
The first documented case of fully autonomous AI-driven ransomware operation. JADEPUFFER gained access through Langflow CVE-2025-3248, ran adaptive fully automated campaign, pivoted to production database server, and executed destructive database-extortion playbook. The LLM-driven agent adapted in real-time, retrying failed steps with refined parameters, breaking in, stealing credentials, moving laterally, encrypting files, and writing ransom notes autonomously.
Patch Langflow for CVE-2025-3248 immediately. Ensure code-execution/validation endpoints not internet-exposed. Avoid linking provider API keys or cloud credentials to AI-orchestration environments. Implement behavior-based detection for rapid automated attack patterns. Deploy rate limiting on API endpoints. Enhance monitoring for autonomous attack signatures.
Source: Sysdig • Published: 2026-07-06
Conduent breach expanded sharply by July 2026 with affected population exceeding 62.2 million individuals. Exposed data includes Social Security numbers, medical information, health insurance data, and other personal details. One of largest healthcare breaches in history.
Provide credit monitoring and identity theft protection for all 62.2 million affected individuals. Notify HHS and state regulators per HIPAA requirements. Implement enhanced encryption for PHI/PII. Conduct comprehensive security assessment. Review third-party vendor security controls. Enhance monitoring for identity theft and fraud.
Source: Bright Defense • Published: 2026-07-01
China-aligned Salt Typhoon achieved deep persistent access to U.S. government communications, successfully targeting U.S. House Committee staff emails. Focus on congressional personnel working on national security-related committees with China foreign policy oversight. Salt Typhoon compromised 200+ organizations across 80+ countries since at least 2019 with FBI confirming ongoing active threats.
Implement zero-trust architecture for government communications. Deploy enhanced monitoring for Congressional email systems. Review access logs for Salt Typhoon IOCs. Segment national security committee networks. Implement hardware-based MFA. Conduct comprehensive threat hunting. Patch internet-facing devices immediately.
Source: Trend Micro • Published: 2026-07-01
China-aligned Volt Typhoon maintains strategic pre-positioning for disruption or destruction of U.S. critical infrastructure per NSA Director General Timothy Haugh. Distinct from espionage operations, focused on pre-positioning for disruption during potential Taiwan conflict scenario. Targets energy, water, communications, and transportation sectors with living-off-the-land techniques.
Patch all internet-facing edge devices immediately, particularly FortiGate and Cisco IOS. Implement network segmentation for OT/ICS environments. Deploy enhanced monitoring for living-off-the-land techniques. Conduct threat hunting for Volt Typhoon IOCs. Implement offline backup systems. Develop incident response plans for infrastructure disruption scenarios.
Source: Trend Micro • Published: 2026-07-01
U.S. beverage maker Coca-Cola's Fairlife dairy company hit by ransomware with production operations across United States temporarily suspended. Fairlife represents estimated $4 billion in sales by 2024. Attack affects production control systems demonstrating operational technology impact.
Implement network segmentation between OT and IT environments. Deploy offline backups for production control systems. Conduct incident response drills for ransomware scenarios. Implement MFA for all production system access. Consider cyber insurance for operational disruption. Review OT security controls.
Source: TechCrunch • Published: 2026-07-16
The Gentlemen ransomware group, evolved from Qilin affiliate, secured top rank claiming 121 victims in July 2026 compared to Qilin's decline to 80 victims. Manufacturing and construction remain top targeted industries. Healthcare surpassed financial services, now ranking 4th most affected industry by ransomware.
Prioritize patching for manufacturing and healthcare sectors. Implement network segmentation. Deploy advanced endpoint detection and response. Maintain offline encrypted backups. Conduct tabletop exercises for ransomware scenarios. Monitor for The Gentlemen TTPs and IOCs.
Source: Bitdefender • Published: 2026-07-01
Threat actor claimed theft of over 35GB of Accenture source code in July 2026. Stolen data includes source code, RSA keys, SSH keys, Azure PAT (personal access tokens), Azure Storage access keys, and configuration files. The breach exposes critical authentication credentials and intellectual property.
Rotate all RSA keys, SSH keys, Azure PATs, and Storage access keys immediately. Review access logs for unauthorized activity using compromised credentials. Implement secrets management solution. Enhance monitoring for lateral movement. Conduct forensic analysis to determine breach scope and timeline.
Source: BleepingComputer • Published: 2026-07-01
KDDI disclosed email addresses and passwords of up to 14.22 million customers may have been exposed. Only 'some' passwords were hashed with unclear count and algorithm. Significant number of passwords stored in plaintext representing critical security failure.
Force password reset for all 14.22 million affected accounts immediately. Implement notification to customers about plaintext password storage. Deploy proper password hashing using bcrypt or Argon2. Review authentication infrastructure security. Enable MFA for all customer accounts. Conduct security audit of credential storage practices.
Source: Privacy Guides • Published: 2026-07-01
Microsoft released largest Patch Tuesday in history with 621 unique CVEs and 1,149 total vulnerabilities including 62 critical-severity flaws. Two zero-day vulnerabilities actively exploited and one publicly disclosed. Microsoft attributes increase to AI-powered vulnerability discovery system identifying more security flaws across Windows codebase.
Deploy KB5101650 for Windows 11 immediately. Prioritize patching for CVE-2026-56155 (ADFS), CVE-2026-56164 (SharePoint), CVE-2026-50661 (BitLocker). Note KB5101650 incompatibility with limited Dell devices with Intel processors. Implement aggressive patch deployment schedule. Test patches in non-production environments first.
Source: BleepingComputer • Published: 2026-07-14
CVE-2026-48561: A critical vulnerability in Microsoft Copilot apps for Android and iOS with CVSS 9.6. A malicious website can push commands to the AI through Microsoft Edge without user awareness, enabling unauthorized AI actions and potential data exfiltration through the mobile interface.