The White House has unveiled the AI-backed Gold Eagle initiative to help rapidly detect, prioritize, and patch cybersecurity vulnerabilities, with a focus on industry, critical infrastructure operators, and federal partners. The program’s stated goal is to reduce time-to-fix by combining automation with coordinated disclosure and remediation workflows. For defenders, the headline takeaway is that vulnerability coordination is being positioned as an “AI-enabled” capability—not just an advisory process.
Source: SecurityWeek
Microsoft’s record-breaking July Patch Tuesday: 622 CVEs and three zero-days
Microsoft’s July 2026 Patch Tuesday delivered patches for 622 vulnerabilities, including three zero-days, underscoring how quickly exploitable conditions are reaching production. Several issues were reported as being leveraged by attackers, meaning organizations may need to prioritize known-exploited items and actively verify patch deployment—not just update broadly. The operational lesson: treat patching as a risk-management workflow with proof of remediation, especially when exploits are already in circulation.
Source: MalwareBytes Blog
CISA urges immediate patching of actively exploited SharePoint vulnerabilities
CISA warned that three SharePoint Server vulnerabilities are under active exploitation, including two that were targeted as zero-days. The directive is aimed at fast action by federal agencies and, by extension, any organization running affected SharePoint configurations. If you’re still validating whether mitigations are in place, this is a clear reminder that “patched on paper” isn’t the same as “not reachable” from attacker vantage points.
Source: SecurityWeek
SonicWall warns of active exploitation of two SMA 1000 zero-days
SonicWall has confirmed active exploitation of two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 appliances. These flaws are particularly dangerous because exploitation is already underway, meaning time-to-mitigate is critical and threat hunting should start immediately. For administrators, the immediate takeaway is to check for exposure and apply emergency remediation guidance rather than waiting for “normal” patch cycles.
Source: Security Affairs
AsyncAPI npm supply-chain compromise: malware injected into trusted packages
Multiple AsyncAPI npm packages were reportedly compromised, with malicious code injected into popular packages under the @asyncapi namespace—totaling millions of weekly downloads. This is an especially high-risk pattern because it weaponizes trust in the ecosystem and can turn CI/CD and developer workflows into distribution channels. Defenders should assume “build pipeline compromise” can be as damaging as direct server compromise, and focus on dependency verification, lockfile hygiene, and post-install integrity checks.
Source: Microsoft MMPC
APT-style escalation continues: “LegacyHive” PoC drops hours after Patch Tuesday
A new Windows zero-day proof-of-concept, dubbed “LegacyHive,” was released shortly after Microsoft’s July Patch Tuesday, targeting the Windows User Profile Service (ProfSvc). While the PoC timing suggests active research and rapid iteration, it also highlights the reality that even “fully patched” Windows environments can still face emergent threats through newly disclosed or not-yet-covered technique chains. Organizations should treat vulnerability response as continuous and revisit assumptions about exposure as new PoCs and attacker tradecraft appear.
Source: Security Affairs
Prompt injection testing accelerates: OpenAI’s GPT-Red automates red teaming
OpenAI disclosed GPT-Red, an internal automated red-teaming model designed to find prompt injection weaknesses by iterating toward attacker goals such as data exfiltration. GPT-Red was trained through self-play reinforcement learning alongside defender models, emphasizing scaling adversarial discovery beyond human-only testing. For security teams adopting LLMs and agents, the key insight is that automated adversarial evaluation will increasingly become baseline practice—and attackers will have faster, more repeatable ways to find bypasses.
Source: The Hacker News
You May Also Be Interested In...
ISC Stormcast For Thursday, July 16th, 2026
This fake Apple app can unlock your Mac's password vault
ClickFix is changing the economics of social engineering