Vulnerabilities and CVEs Microsoft July 2026: exploited SharePoint and AD FS flaws
CVE-2026-56164 and CVE-2026-56155 are being exploited. Learn how to establish SharePoint and AD FS exposure, patch safely and collect defensible validation evidence.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs CVE-2026-56164 and CVE-2026-56155 are being exploited. Learn how to establish SharePoint and AD FS exposure, patch safely and collect defensible validation evidence.
Vulnerabilities and CVEs SonicWall confirms active exploitation of SSRF and RCE flaws in SMA 1000. Check affected builds, hunt vendor IOCs and decide whether to patch or rebuild.
Vulnerabilities and CVEs Mozilla has fixed CVE-2026-15718 and CVE-2026-15719. Public exploit code is not confirmed exploitation, but it sharply reduces the time available to update.
Penetration Testing and AppSec GitHub has added AI detections to code scanning and a /security-review command. Understand the prerequisites, limitations and a safe rollout plan for engineering teams.
Penetration Testing and AppSec GitHub's 18-hour test exposed legacy TLS clients before permanent SHA-1 removal on 15 September. Find risk across Git, APIs, CI/CD and vendor integrations.
AI Security The US is launching a clearinghouse for scanning, validation and vulnerability prioritisation. We assess what GOLD EAGLE may change and what evidence is still missing.
Vulnerabilities and CVEs PTC released critical fixes for additional Windchill and FlexPLM versions on 14 July. Review affected releases, web-shell IOCs and a safe PLM patching plan.
Vulnerabilities and CVEs SAP’s July update fixes critical flaws in NetWeaver, Approuter and Commerce Cloud. Understand the 9.9 risk, patch order and the evidence needed to close remediation.
Threats and Incidents Authorities warn that Russian actors are exploiting poorly secured routers. Review the observed risk, hardening priorities and an evidence-led edge-device checklist.
AI Security Muse Image could reference public Instagram accounts when generating images. We examine Meta's reversal and the lessons for AI products using customer data.
AI Security How to audit LLM, RAG and AI agent security: scope, prompt injection, data controls, tools, reporting, remediation and retesting.
AI Security Understand AI Act roles, risk classes, the 2026–2028 timeline, AI literacy, transparency, documentation, human oversight and cybersecurity.
Penetration Testing and AppSec How professional web application penetration testing works: scope, OWASP methodology, reporting, retesting, pricing and vendor selection.
AI Security AI red teaming methodology for LLMs, RAG and agents: scope, attack scenarios, metrics, safe execution, reporting and differences from a classic pentest.
Penetration Testing and AppSec A practical API penetration testing checklist for REST, GraphQL, OAuth, JWT, BOLA, access control, rate limits, business logic, reporting and retesting.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.