
Hello all,
Last week I predicted a patch-Tsunami. That was an understatement. The July Patch Tuesday was a tectonic shift that resulted in flaming lava-like vulnerabilities spewing out for nearly everything Microsoft makes. And then there’s the groundswell and tsunami of other vendors releasing patches for flaws and defects at the same time or in the same week. One commentator called it the “patchcapalypse”, and to me it looks like he is correct. Even Microsoft has publicly stated that, “Customers will see a higher volume of security updates included in each security release”, and that they may become more frequent. The old model is now officially broken; it will be interesting to see how we pivot to keep up in this AI enhanced patch flood.
Headline NEWS:
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack. In a harbinger of things to come, Redmond unleashed an overwhelming quantity of fixes this month. It shouldn’t have been a surprise after seeing how much Google and Oracle patched recently, now that AI is increasingly helping find flaws, but it is still rather shocking and makes you wonder whatever happened to Microsoft’s “Secure by Design” initiative. They announced it in November 2023; nearly 3 years later, we’re seeing more holes, not less. When will the design kick in? Time to exploit from reveal is decreasing dramatically, so don’t wait to vet and deploy the updates.
- Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat. It doesn’t get much worse than your vendor telling you to turn off their product. But, that’s what ShareFile Storage Zone Controller clients were instructed to do last week on July 10. On July 14 Progress Software lifted the shutdown order provided you’d applied newly released patches. Obviously, if you have this, hopefully you followed the vendors’ recommendations. If not, contact the vendor to vet your device for possible compromise and remediation instructions.
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now. VPN appliances are favorite targets of soulless inhuman scum known as ransomware operators. Indications are that exploitation started last month. If you use any of the SonicWall Secure Mobile Access 1000 models, 6210, 7210, and 8200v, patch immediately. After you do so, follow vendor guidance check to see if your device has been compromised. CISA ordered all Federal agencies have patched this by July 17. Note: these vulnerabilities do not affect SonicWall firewalls, just the SMA 1000 series appliances.
- WordPress Core “wp2shell” RCE flaws get public exploits, patch now. This is as bad as it gets. When two known defects are chained together, they enable pre-authentication remote code execution (RCE). And adding insult to injury, exploitation has already started. For sites that use Cloudflare’s Web Application Firewall (WAF), they have put mitigations in place to shed the attacks, but clients still need to update to version7.0.2 or 6.9.5 to fully secure their sites.
In Ransomware, Malware, and Vulnerabilities News:
- Vulnerabilities, Vulnerabilities, and more Vulnerabilities. There are so many this week, not even counting Microsoft’s 622, that focusing on just a few didn’t make sense. The list of vendors and products is extensive; AnyDesk, FortiSandbox, Citrix Secure Access and Endpoint Client for Windows, Claude for Chrome, Notepad++, 7-Zip, VMware Avi Load Balancer, Firefox, Chrome, Adobe, Trend Micro, Tanium, ESET, Tenable, F5, and Zoom. And that’s not all of them. Even Shark Vacuums have an RCE! Be sure to check the full listing of links to get details.
In Other News Events of Note and Interest:
- VMware exodus continues, with Sheetz taking 11,000 VMs to StorMagic. In the last 30 days I’ve published a surprising number of links about Broadcom VMware clients that are fleeing due to the vendors’ massive price increases, elimination of perpetual licensing, and refusing to offer support for clients that have existing perpetual licenses. The latest one is Sheetz, a US convenience store chain with 838 locations, which has been aggressively migrating, and is about a month away from being VMware-less. The retailer joins T-Mobile, Allstate, grocery store chain Tesco, and Western Union in rejecting Broadcom.
Musings
The Game Has Changed. The movie Tron Legacy had absolutely brilliant music by Daft Punk. The song title, “The Game Has Changed” was brought to mind by this week’s massive patch cycle. The unprecedented changes in The Grid’s digital world in the movie, which the music highlights, somewhat mirrors what we are now seeing here in the physical world. The Grid experienced the spontaneous emergence of ISOs (Isomorphic Algorithms) digital lifeforms that were significantly more capable than the standard code-bound digital lifeforms of The Grid, and unlike them, they had free will. Similarly, our game has changed. We are enmeshed in the emergence of a new digital reality; the advent of algorithms so incredibly advanced that they often rival the capabilities of their creators and are soon predicted to surpass them. Yes, I’m referring to AI. These AI’s, while not currently as advanced as the ISOs in The Grid, are disrupting our world in similar ways, by challenging the status quo of patch cycles, knowledge silos, productivity, and the very nature of work. We must recognize this new digital reality and acquiesce that the old ways are not returning. In order to keep up with the magnitude and velocity of the changes being introduced, we need to become very adept at playing this new game, and we need to do so without delay.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
- Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record
- Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
- Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
- WordPress Core “wp2shell” RCE flaws get public exploits, patch now
- WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- US and allies warn of Russian critical infrastructure attacks
- The US government warns that Russia state hackers are coming after your router
- CISA warns admins to patch actively exploited SharePoint flaws
- CISA urges immediate action on actively exploited Fortinet flaws
- CISA orders feds to patch actively exploited Oracle flaw by Saturday
- CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance
- Pentagon suspends CMMC phase two requirements, launches review of program
- DOD halts cybersecurity requirements for CMMC Phase 2: ‘The math just simply doesn’t math’
- CMMC may be paused, but cybersecurity audits likely to return: Industry, experts
- NSA revives ‘Tailored Access Operations’ name for elite hacking unit
- US To Launch AI Cybersecurity Coordination Groups To Protect Critical Infrastructure, Strengthen Vulnerability Response
- White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
- Gold Eagle Clearinghouse Targets Real Gap, but How Is Unclear
- ‘We decided not to limit VPNs’: UK government U-turns on age-gating privacy tools
- Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charge
- Teen hackers jailed after live streaming cyber attack on TfL
- Vulnerabilities and Exploits
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
- Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
- SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
- AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service
- FortiSandbox Vulnerability Allows Attackers to Access VNC Servers of VMs
- Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
- Forgotten UEFI shims undermining Secure Boot
- Citrix Secure Access and Endpoint Client for Windows Vulnerability Enables Privilege Escalation
- Fake OAuth client IDs are helping attackers slip past sign-in logs
- Teen accused of using ChatGPT to delete 46,000 anime accounts
- Defending SaaS-based applications against ShinyHunters OAuth abuse
- Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs, and Calendar Data
- Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection Attacks
- Windows BitLocker 0‑Day Vulnerability Allows Hackers to Bypass Security Feature
- 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
- Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
- Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
- Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow
- Zoom Patches Critical Windows Flaw That Could Enable Account Takeover
- Zoom warns of critical account takeover vulnerability
- F5 Patches Multiple NGINX Vulnerabilities Enabling Heap Buffer Overflow and Code Execution Attacks
- Multiple Dell PowerProtect Vulnerabilites Allow Hackers to Gain Full System Access Remotely
- ‘The bots are alive!’ Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
- OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities
- No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
- Phishing, Malware, and Similar
- LastPass, Bitwarden users targeted with fake security alerts
- ClickFix’s Mushrooming Ecosystem Demands New Defense Tactics
- US sanctions VPN, malware providers for enabling ransomware attacks
- New CrashStealer malware poses as Apple crash reporting tool
- New ClickLock macOS malware traps users into revealing login password
- ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
- Timor-Leste scam centre compounds uncovered as police arrest Chinese, Indonesians, Cambodians
- AsyncAPI npm packages infected with credential-stealing malware
- OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
- Phishing Campaign Hides Lua Loader as TrueType Font File
- Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
- Chrome Sync increasingly abused to stalk unsuspecting victims
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
- Breaches, Leaks, and Ransomware
- Miinto fesses up to breach, says customers open to phishing
- Lifeline confirms data breach
- Japan’s largest taxi operator shuts systems after cyberattack
- Centers Laboratory Data Breach Affects 540,000 Individuals
- Tech support scam caused massive data breach at Australian airline Qantas
- New Spirals ransomware encrypts victim network in under 24 hours
- Coca-Cola Suspends Fairlife Operations in US Following Cybersecurity Breach
- Ransomware curdles production at Coca-Cola’s Fairlife dairy biz
- Abbott probes two cyber incidents amid extortion claims
- Cyberattack threatens utterly critical infrastructure in Japan: KFC
- The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat
Other News Events of Note and Interest
- Cool Tool: PeaZip 11.2 Open-Source Archive Manager Is Out with Support for ZIM Archives
- Cool Tool: Sandboxie Plus 1.18.0 / Classic 5.73.0
- Cool Tool: Clonezilla Live 3.3.3 Disk Imaging Tool Adds Reverse-Connection Network Cloning
- Sheetz is quitting VMware, migrating 11,000 virtual machines
- A hard drive reliability check on 341,263 drives, from 4TB to past 20TB
- Book: Fundamentals of Wireless Communication
- Meta breaches laws with ‘addictive’ Instagram, Facebook designs, EU says
- Meet the 9 new emoji to help sum up 2026
- Google comes out against blocks on DNS resolvers, VPNs, and IP addresses
- Google Opposes Site Blocking in Europe as U.S. Piracy Blocking Plans Gain Momentum
- Mozilla Firefox to follow Google Chrome, Microsoft Edge with new release cadence
- BitTitan pitches partners on migrations as recurring revenue
- How to Keep Android Backups From Filling Up Your Google Drive Storage
- Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
- Google announces Gemma 4 optimized for the Pixel 10’s TPU
- Third-party app stores coming to Google Play next week as Epic settlement withdrawn
- Air Force network lockouts hit troops and civilians
- TSMC Adds $100 Billion to Its U.S. Spending Plan
- NTP server that traveled back in time caused massive Aussie mobile outage
- Here’s how to update every app on your Windows PC with a single command
- AI, LLM’s, and Skynet
- Apple is suing OpenAI over theft of trade secrets in blockbuster lawsuit
- Anthropic’s newest ad is creeping people out
- Anthropic is giving teachers free access to premium Claude features, details here
- Reading Between the Apple v. OpenAI Lawsuit Lines
- Fable gets another bump
- Meta pulls new AI image feature after days of backlash
- OpenAI’s First Device Will Be Home Speaker Built as AI Companion
- Google DeepMind chief calls for US to lead AI standards body
- Google required to open up to AI, search engine rivals under EU-mandated changes
- ChatGPT Access Tied To 9% Drop In Traditional Search
- China’s open-weight Kimi model stuns AI world with frontier-level results
- Hack suggests AI music generator Suno scraped YouTube for training data
- AI brain implant restores a paralysed man’s movement
- Microsoft
- Microsoft has a hidden Windows 11 edition that supports 6TB of RAM and 256 CPU cores
- Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
- Microsoft Entra ID gets passkeys default authentication starting September
- Microsoft is Finally Fixing Windows Search, No More Promotional Content
- Microsoft demystifies how Windows updates work
- I tested Windows 11 July 2026 Updates. Here’s everything new, improved, and fixed
- Microsoft’s fix for RoguePlanet has its own new disk space bug
- ‘A single entry point can rapidly expand to greater enterprise impacts’: Microsoft introduces changes to tackle ShinyHunters
- Microsoft releases Windows 10 KB5099539 extended security update
- Microsoft pauses Windows 11’s July update for some Dell devices because they’re randomly shutting down
- Released: July 2026 Exchange Server Security Updates
- Windows 11 gets new registry policy to give IT admins more control
- Microsoft CEO Satya Nadella Says IQ Without EQ Is ‘a Waste.’
- Windows 11 finally gets an undo button for your entire PC
- Windows 11’s 500GB storage bug is fixed. How to check if you’re good
- Microsoft confirms WSUS service degradation impacting all versions of Windows
- A note on this month’s Patch Tuesday, from Microsoft
- Windows 11 KB5121767 out to fix system performance issues caused by KB5101650, KB5095093
