July 19, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

Last week I predicted a patch-Tsunami. That was an understatement. The July Patch Tuesday was a tectonic shift that resulted in flaming lava-like vulnerabilities spewing out for nearly everything Microsoft makes. And then there’s the groundswell and tsunami of other vendors releasing patches for flaws and defects at the same time or in the same week. One commentator called it the “patchcapalypse”, and to me it looks like he is correct. Even Microsoft has publicly stated that, “Customers will see a higher volume of security updates included in each security release”, and that they may become more frequent. The old model is now officially broken; it will be interesting to see how we pivot to keep up in this AI enhanced patch flood.

Headline NEWS:

  • Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack. In a harbinger of things to come, Redmond unleashed an overwhelming quantity of fixes this month. It shouldn’t have been a surprise after seeing how much Google and Oracle patched recently, now that AI is increasingly helping find flaws, but it is still rather shocking and makes you wonder whatever happened to Microsoft’s “Secure by Design” initiative. They announced it in November 2023; nearly 3 years later, we’re seeing more holes, not less. When will the design kick in? Time to exploit from reveal is decreasing dramatically, so don’t wait to vet and deploy the updates.
  • Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat. It doesn’t get much worse than your vendor telling you to turn off their product. But, that’s what ShareFile Storage Zone Controller clients were instructed to do last week on July 10. On July 14 Progress Software lifted the shutdown order provided you’d applied newly released patches. Obviously, if you have this, hopefully you followed the vendors’ recommendations. If not, contact the vendor to vet your device for possible compromise and remediation instructions.
  • SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now. VPN appliances are favorite targets of soulless inhuman scum known as ransomware operators. Indications are that exploitation started last month. If you use any of the SonicWall Secure Mobile Access 1000 models, 6210, 7210, and 8200v, patch immediately. After you do so, follow vendor guidance check to see if your device has been compromised. CISA ordered all Federal agencies have patched this by July 17. Note: these vulnerabilities do not affect SonicWall firewalls, just the SMA 1000 series appliances.
  • WordPress Core “wp2shell” RCE flaws get public exploits, patch now. This is as bad as it gets. When two known defects are chained together, they enable pre-authentication remote code execution (RCE). And adding insult to injury, exploitation has already started. For sites that use Cloudflare’s Web Application Firewall (WAF), they have put mitigations in place to shed the attacks, but clients still need to update to version7.0.2 or 6.9.5 to fully secure their sites.

In Ransomware, Malware, and Vulnerabilities News:

  • Vulnerabilities, Vulnerabilities, and more Vulnerabilities. There are so many this week, not even counting Microsoft’s 622, that focusing on just a few didn’t make sense. The list of vendors and products is extensive; AnyDesk, FortiSandbox, Citrix Secure Access and Endpoint Client for Windows, Claude for Chrome, Notepad++, 7-Zip, VMware Avi Load Balancer, Firefox, Chrome, Adobe, Trend Micro, Tanium, ESET, Tenable, F5, and Zoom. And that’s not all of them. Even Shark Vacuums have an RCE! Be sure to check the full listing of links to get details.

In Other News Events of Note and Interest:

  • VMware exodus continues, with Sheetz taking 11,000 VMs to StorMagic. In the last 30 days I’ve published a surprising number of links about Broadcom VMware clients that are fleeing due to the vendors’ massive price increases, elimination of perpetual licensing, and refusing to offer support for clients that have existing perpetual licenses. The latest one is Sheetz, a US convenience store chain with 838 locations, which has been aggressively migrating, and is about a month away from being VMware-less. The retailer joins T-Mobile, Allstate, grocery store chain Tesco, and Western Union in rejecting Broadcom.

Musings

The Game Has Changed. The movie Tron Legacy had absolutely brilliant music by Daft Punk. The song title, “The Game Has Changed” was brought to mind by this week’s massive patch cycle. The unprecedented changes in The Grid’s digital world in the movie, which the music highlights, somewhat mirrors what we are now seeing here in the physical world. The Grid experienced the spontaneous emergence of ISOs (Isomorphic Algorithms) digital lifeforms that were significantly more capable than the standard code-bound digital lifeforms of The Grid, and unlike them, they had free will. Similarly, our game has changed. We are enmeshed in the emergence of a new digital reality; the advent of algorithms so incredibly advanced that they often rival the capabilities of their creators and are soon predicted to surpass them. Yes, I’m referring to AI. These AI’s, while not currently as advanced as the ISOs in The Grid, are disrupting our world in similar ways, by challenging the status quo of patch cycles, knowledge silos, productivity, and the very nature of work. We must recognize this new digital reality and acquiesce that the old ways are not returning. In order to keep up with the magnitude and velocity of the changes being introduced, we need to become very adept at playing this new game, and we need to do so without delay.

Visc. Jan Broucinek

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

 

Share this with: