Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: July 27, 2026 - July 27, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Monday, July 27, 2026 -25% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

Oracle-CPU-July-2026 — Oracle E-Business Suite, Fusion Middleware, Communications

Largest-ever Oracle Critical Patch Update with 1,235 CVEs in 1,449 security updates. E-Business Suite received 410 patches (28.3% of total) with 261 critical severity. 663 vulnerabilities are remotely exploitable without credentials.

REMEDIATION

Apply July 2026 CPU immediately, prioritizing Oracle E-Business Suite versions impacted by 410 new fixes. Focus on internet-facing Oracle Fusion Middleware and Communications systems first. Test in staging before production deployment.

Source: MSRC  •  Published: 2026-07-21

AI & Supply Chain

[CRITICAL]

MCP-Supply-Chain-2026 — Model Context Protocol (MCP) Implementations

Over 40 CVEs disclosed against MCP implementations between January-April 2026. Command injection affects 43% of tested servers, path traversal affects 82% of 2,614 implementations, SSRF affects 36.7% of 7,000+ servers. CVE-2025-6514 (mcp-remote) has CVSS 9.6 OS command injection with 437,000+ downloads.

REMEDIATION

Implement policy validation of MCP tool metadata before ingestion. Review workspace trust model configurations for Amazon Q and IDE extensions. Disable automatic MCP server loading from untrusted repositories. Audit all MCP server configurations for command injection vulnerabilities.

Source: Web  •  Published: 2026-04-30

[CRITICAL]

Mastra-NPM-Compromise — Mastra AI Framework (npm)

North Korean APT Sapphire Sleet (BlueNoroff/APT38) compromised stolen developer account and republished 140+ packages in @mastra scope within 19 minutes. First confirmed nation-state mass npm supply chain attack targeting AI agent frameworks.

REMEDIATION

Implement package signature verification immediately. Use dependency pinning for all AI framework dependencies. Monitor for unexpected package updates. Apply AI coding assistant output validation. Review and remove compromised @mastra packages. Rotate npm credentials.

Source: Web  •  Published: 2026-06-17

Threat Actors & Dark Web

[CRITICAL]

Salt-Typhoon-2026 — U.S. Telecommunications Infrastructure

Chinese APT Salt Typhoon compromised 200+ organizations across 80 countries including 8+ U.S. telecom providers (FBI, Verizon, AT&T, Lumen). FBI confirmed threats remain active and ongoing as of February 2026. Over 1 million people's metadata compromised. Pre-positioned access for potential infrastructure disruption.

REMEDIATION

Implement zero-trust architecture immediately. Segment OT/IT networks. Deploy EDR with behavioral analytics. Monitor for living-off-the-land techniques. Review authentication logs for unusual patterns. Conduct comprehensive network forensics. Harden telecom infrastructure per CISA guidance.

Source: CISA  •  Published: 2026-02-15

[CRITICAL]

Volt-Typhoon-2026 — U.S. Critical Infrastructure (Energy, Water, Communications, Transportation)

Chinese APT Volt Typhoon maintained persistent access inside U.S. critical infrastructure for at least five years. Intelligence community assesses targeting is preparation to disrupt U.S. infrastructure rather than espionage. Confirmed dormant presence in power grids, water systems, and telecommunications.

REMEDIATION

Deploy comprehensive network monitoring for critical infrastructure. Implement air-gapped OT environments where possible. Review all authentication systems for unauthorized access. Deploy behavioral analytics for anomaly detection. Segment critical systems. Follow CISA AA24-038A mitigation guidance.

Source: CISA  •  Published: 2024-02-07

[CRITICAL]

Iranian-APT-PLC-Attack — Rockwell Automation PLCs in U.S. Critical Infrastructure

Iranian-affiliated APT targeting U.S. critical infrastructure PLCs, escalating in response to U.S.-Israel-Iran hostilities. Attackers download malicious project files to PLCs using configuration software, adding logic that overrides safety parameters while retaining normal downstream function. Updated advisory July 22, 2026 adds detection guidance for malicious reusable code modules.

REMEDIATION

Segment ICS/SCADA networks immediately. Implement application whitelisting on engineering workstations. Monitor for unauthorized PLC configuration changes. Deploy integrity monitoring for ladder logic. Review all PLC project files for malicious modifications. Implement change control for PLC programming.

Source: CISA  •  Published: 2026-07-22

Priority Action Matrix

01DO NOWOracle-CPU-July-2026 (Oracle E-Business Suite, Fusion Middleware, Communications): Apply July 2026 CPU immediately, prioritizing Oracle E-Business Suite versions impacted by 410 new fixes. Focus on internet-facing Oracle Fusion Middleware and Communications systems first. Test in st...
02DO NOWMCP-Supply-Chain-2026 (Model Context Protocol (MCP) Implementations): Implement policy validation of MCP tool metadata before ingestion. Review workspace trust model configurations for Amazon Q and IDE extensions. Disable automatic MCP server loading from untrusted repo...
03DO NOWMastra-NPM-Compromise (Mastra AI Framework (npm)): Implement package signature verification immediately. Use dependency pinning for all AI framework dependencies. Monitor for unexpected package updates. Apply AI coding assistant output validation. Rev...
04DO NOWSalt-Typhoon-2026 (U.S. Telecommunications Infrastructure): Implement zero-trust architecture immediately. Segment OT/IT networks. Deploy EDR with behavioral analytics. Monitor for living-off-the-land techniques. Review authentication logs for unusual patterns...
05DO NOWVolt-Typhoon-2026 (U.S. Critical Infrastructure (Energy, Water, Communications, Transportation)): Deploy comprehensive network monitoring for critical infrastructure. Implement air-gapped OT environments where possible. Review all authentication systems for unauthorized access. Deploy behavioral a...
06DO NOWIranian-APT-PLC-Attack (Rockwell Automation PLCs in U.S. Critical Infrastructure): Segment ICS/SCADA networks immediately. Implement application whitelisting on engineering workstations. Monitor for unauthorized PLC configuration changes. Deploy integrity monitoring for ladder logic...

Biggest Risk This Period

BIGGEST RISK

Oracle-CPU-July-2026: Largest-ever Oracle Critical Patch Update with 1,235 CVEs in 1,449 security updates. E-Business Suite received 410 patches (28.3% of total) with 261 critical severity. 663 vulnerabilities are remotely exploitable without credentials.