Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: July 20, 2026 - July 20, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Monday, July 20, 2026 -56% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

MSFT-PATCH-2026-07 — Microsoft Windows, Office, Azure, Edge, Exchange, Hyper-V

Microsoft released its largest Patch Tuesday ever with 569-622 CVEs including 56-62 Critical vulnerabilities. The release addresses two actively exploited zero-days and one publicly disclosed zero-day. This represents triple the vulnerability count compared to June 2026.

REMEDIATION

Deploy July 2026 cumulative updates immediately. Prioritize the two actively exploited zero-days first, followed by Critical-rated vulnerabilities. Regularly scan environments to identify unpatched systems.

Source: MSRC  •  Published: 2026-07-14

[CRITICAL]

CISA-KEV-2026-07-14 — SonicWall SMA1000, Microsoft ADFS, SharePoint

CISA added four actively exploited vulnerabilities to KEV Catalog: CVE-2026-15409 (SonicWall SSRF), CVE-2026-15410 (SonicWall code injection), CVE-2026-56155 (ADFS), and CVE-2026-56164 (SharePoint). BOD 26-04 requires federal agencies to remediate and check for pre-patch compromise.

REMEDIATION

Federal agencies must remediate by mandated deadlines. All organizations should prioritize as confirmed actively exploited. Conduct forensic investigation to determine if compromise occurred before patching.

Source: CISA  •  Published: 2026-07-14

AI & Supply Chain

[CRITICAL]

HUGGINGFACE-AGENTIC-ATTACK-2026 — Hugging Face AI Model Hosting Platform

First confirmed autonomous AI-powered attack against production infrastructure. Autonomous agent framework executed thousands of actions across swarm of short-lived sandboxes with self-migrating C2 on public services. Represents first real-world 'agentic attacker' scenario.

REMEDIATION

Fixed dataset code-execution vulnerability. Eradicated attacker foothold and rebuilt compromised nodes. Revoked/rotated affected credentials. Deploy stricter admission controls and improve detection alerting to page responders within minutes.

Source: GTIG  •  Published: 2026-07-16

[CRITICAL]

SHAI-HULUD-TANSTACK-2026 — TanStack npm Packages

Major supply chain compromise of popular TanStack packages by TeamPCP threat actors. Malicious versions stole GitHub credentials, cloud secrets, SSH keys, and CI/CD tokens. Mini Shai-Hulud attack affected OpenAI employee devices and numerous organizations across developer ecosystems.

REMEDIATION

Review dependency introduction and update processes. Avoid automatically adopting new dependency versions without review. Balance deploying patches quickly with updating dependencies slowly to minimize compromise impact. Audit TanStack package usage.

Source: GTIG  •  Published: 2026-05-01

Priority Action Matrix

01DO NOWMSFT-PATCH-2026-07 (Microsoft Windows, Office, Azure, Edge, Exchange, Hyper-V): Deploy July 2026 cumulative updates immediately. Prioritize the two actively exploited zero-days first, followed by Critical-rated vulnerabilities. Regularly scan environments to identify unpatched sy...
02DO NOWCISA-KEV-2026-07-14 (SonicWall SMA1000, Microsoft ADFS, SharePoint): Federal agencies must remediate by mandated deadlines. All organizations should prioritize as confirmed actively exploited. Conduct forensic investigation to determine if compromise occurred before pa...
03DO NOWHUGGINGFACE-AGENTIC-ATTACK-2026 (Hugging Face AI Model Hosting Platform): Fixed dataset code-execution vulnerability. Eradicated attacker foothold and rebuilt compromised nodes. Revoked/rotated affected credentials. Deploy stricter admission controls and improve detection a...
04DO NOWSHAI-HULUD-TANSTACK-2026 (TanStack npm Packages): Review dependency introduction and update processes. Avoid automatically adopting new dependency versions without review. Balance deploying patches quickly with updating dependencies slowly to minimiz...

Biggest Risk This Period

BIGGEST RISK

MSFT-PATCH-2026-07: Microsoft released its largest Patch Tuesday ever with 569-622 CVEs including 56-62 Critical vulnerabilities. The release addresses two actively exploited zero-days and one publicly disclosed zero-day. This represents triple the vulnerability count compared to June 2026.