Check Point’s 2026 research highlights a major shift: vulnerability response timelines have collapsed from days to hours, driven by AI-assisted exploit generation at scale. The report also warns that exposed AI assets—model servers, inference endpoints, and agent control panels—are being actively probed from the internet, often without security teams realizing they’re reachable. Finally, data leakage via “approved” AI use doubled in one year as employees share credentials and source code in everyday workflows.
Source: Check Point Blog
Email Agent Hijacking: Attackers hide instructions in email to manipulate AI actions before humans notice
New research focuses on a post-delivery blind spot: AI agents increasingly read and write emails instantly, sometimes before any human reviews the message. “Email agent hijacking” hides malicious instructions inside email content to steer AI interpretation, outputs, or decisions. The key takeaway is that post-delivery controls are often too late—organizations need preventive protections for AI-consumed content and validation mechanisms for AI-generated responses.
Source: Check Point Blog
Progress ShareFile Storage Zone Controllers: Customers told to shut down on-prem servers amid “credible threat”
Progress Software issued urgent guidance to ShareFile customers that use Storage Zone Controllers (SZCs), directing them to disable access and manually shut down on-prem servers while it investigates a credible threat. While Progress states it has no evidence of unauthorized access, the recommended action is one of the most disruptive containment steps available—signaling potential risk to file-sharing integrity. For defenders, the lesson is operational: time-to-isolate matters more than time-to-diagnose when third-party infrastructure is involved.
Source: SecurityWeek
Microsoft Entra ID OAuth client ID spoofing helps attacks bypass sign-in telemetry
Researchers report that adversaries conducting account enumeration can spoof OAuth client IDs to reduce visibility in Microsoft Entra ID sign-in logs. Because the client_id is treated as an application identifier, unfamiliar identifiers can create gaps that attackers then exploit operationally. The practical implication: defenders should re-check how they correlate sign-in events with app registrations and validate telemetry coverage for “unrecognized” OAuth client_id patterns.
Source: Help Net Security
OAuth/passkeys policy shift: Entra ID to make passkeys default in September 2026
Microsoft announced a timeline to roll out passkeys as the default authentication experience for Microsoft Entra ID starting September 1, 2026. Organizations with SMS/voice MFA enabled will be automatically enabled for passkeys, and starting February 1, 2027 users relying on SMS/voice will be required to register a passkey before they can sign in. For security teams, this is a governance and enablement project—not just an IT rollout—requiring identity workflows, hardware-backed support planning, and user readiness.
Source: Help Net Security
EU + UK sanctions target Russian cyber actors tied to long-running critical infrastructure sabotage
The EU and UK imposed sanctions on multiple individuals and entities accused of supporting a long-running cyber ecosystem linked to Russian intelligence activity. The action follows blame and attribution related to attempts targeting critical infrastructure, including disruption scenarios. While sanctions are not a technical control, they can reshape threat actor operations, finance, and tool access—so defenders should expect changes in TTPs alongside enforcement pressure.
Source: Help Net Security
U-Boot vulnerabilities: multiple issues in FIT signature verification could enable stealthy firmware attacks
SC Media reports six U-Boot vulnerabilities affecting FIT signature verification logic, with impacts ranging from denial of service to arbitrary code execution. Because U-Boot sits on the boot chain, exploitation can be particularly dangerous: it may allow attackers to establish persistence below the OS level. Organizations running affected embedded or appliance platforms should review exposure and prioritize patching or compensating controls for boot-chain integrity.
Source: SC Media
You May Also Be Interested In...
ISC Stormcast For Tuesday, July 14th, 2026 (SANS Internet Storm Center)
RabbitMQ vulnerability threatens enterprise systems
Pentagon suspends CMMC Phase 2 as it rethinks contractor cybersecurity rules