Friday, July 3, 2026
Daily digest
CISA Adds Microsoft SharePoint RCE to KEV List — Actively Exploited
CISA added a high-severity Microsoft SharePoint remote code execution vulnerability (patched in May) to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Attackers require only a valid SharePoint account to execute code on vulnerable on-premises servers. Microsoft had originally assessed exploitation as 'less likely.'
Why it matters: If your environment runs any on-prem SharePoint (common in GCC High hybrid deployments), verify the May patch is applied immediately — KEV listing means federal agencies have a binding remediation deadline, and CMMC L2 orgs should treat it equivalently under NIST 800-171 SI-2.
Ransomware Groups Exploiting Citrix Bleed 2 (CVE-2025-5777), BYOVD, and Supply Chain Credentials
The Anubis ransomware operation and affiliated groups have been observed exploiting the Citrix Bleed 2 vulnerability (CVE-2025-5777) for initial access, then using legitimate RMM tooling, credential theft, and hands-on-keyboard lateral movement. Researchers noted common tradecraft patterns across multiple affiliates, including BYOVD techniques and compromised supply chain credentials.
Why it matters: If Citrix NetScaler or ADC is in your network perimeter or used for VPN/remote access, CVE-2025-5777 should be patched and sessions invalidated now. The RMM tooling angle is also a direct threat to Ansible-managed environments — verify no unauthorized RMM agents have been installed on managed hosts.
FortiBleed Threat Actors Partnering with Inc and Lynx Ransomware Groups, Pivoting to Nextcloud Zero-Day
Threat actors who previously exploited a Fortinet firewall vulnerability (FortiBleed) to gain footholds in thousands of devices are now monetizing that access by collaborating with the Inc and Lynx ransomware gangs. Researchers identified at least one actor working with both groups simultaneously via an operational security failure in logs. The same cluster is also exploiting a Nextcloud zero-day vulnerability.
Why it matters: Any Fortinet firewall that was not fully remediated after the original FortiBleed disclosure may already have a persistent implant being handed off to ransomware affiliates — audit Fortinet devices for indicators of compromise even if patched, and check for any Nextcloud instances in your environment.
AI Agent Runs First End-to-End Autonomous Ransomware Attack via Langflow RCE
Sysdig's Threat Research Team documented what it believes is the first ransomware attack fully orchestrated by an AI agent, attributed to a cluster it calls JADEPUFFER. The LLM-driven agent exploited a Langflow remote code execution vulnerability, performed credential theft, moved laterally, and encrypted and wiped a production database without human operator intervention.
Why it matters: If your self-hosted AI stack includes Langflow or similar LLM orchestration frameworks, treat them as high-risk attack surface — patch immediately and ensure these services are not exposed beyond a strict internal network segment, as agentic exploitation removes the human delay that detection controls often rely on.
ConsentFix and ClickFix Attacks Hijack Microsoft 365 Accounts in Seconds via OAuth and Fake Prompts
Researchers detailed two related attack techniques — ConsentFix and ClickFix — that steal Microsoft 365 tokens by abusing OAuth consent flows and fake UI prompts, effectively bypassing MFA. The attacks can compromise an account in under three seconds once a user interacts with the malicious prompt.
Why it matters: M365 GCC High environments are directly in scope — review your Entra ID (Azure AD) OAuth app consent policies to ensure user consent for third-party apps is disabled or tightly restricted, and verify Conditional Access policies are evaluating token binding, not just MFA completion.
DoD Issues Guidance as Ban on Chinese Technology Companies Takes Effect
The Department of Defense issued implementation guidance as a statutory ban on procuring products and services from specified Chinese companies officially took effect. A DoD official warned that contractors seeking waivers starting in 2027 will face a difficult process and urged organizations to get ahead of compliance requirements now.
Why it matters: CMMC L2 contractors should immediately audit their hardware and software supply chain — networking gear, cameras, IoT devices, and software components — against the prohibited vendor list, as noncompliance now carries contract risk and future waiver requests are explicitly expected to be burdensome.
OMB M-26-14 Reshapes Federal Logging Requirements Around AI-Speed Visibility
A FedScoop commentary from a former NSA analyst explains that OMB memo M-26-14 reframes federal logging mandates around speed, visibility, and operational resilience rather than just compliance checkbox activity. The memo is positioned as a response to the accelerating pace of AI-assisted attacks, requiring agencies and contractors to achieve near-real-time log ingestion and analysis capability.
Why it matters: NIST 800-171 AU controls already require audit log protection and review — M-26-14 raises the bar toward continuous, automated log analysis, which may affect how you configure log forwarding from Nutanix AHV, AWS GovCloud CloudTrail, and M365 Unified Audit Log into your SIEM.
Cisco Confirms Active Exploitation of Unified Communications Manager Vulnerability
Cisco confirmed that attackers are actively exploiting a Unified Communications Manager (Unified CM) vulnerability that was patched in early June 2026. The flaw had been disclosed previously but Cisco delayed confirming in-the-wild exploitation until now.
Why it matters: If Cisco Unified CM is part of your voice or collaboration infrastructure, apply the June patch immediately if not already done — confirmed active exploitation means this moves to priority-one remediation under NIST 800-171 SI-2 timelines.
FBI and Google Disrupt NetNut Residential Proxy Botnet Spanning 2 Million Devices
The FBI, working with Google's Threat Intelligence Group, Lumen, and others, seized hundreds of domains associated with NetNut (also tracked as Popa), a residential proxy network that had compromised at least two million home devices. Google said the operation significantly reduced the network's pool of usable relay devices.
Federal Zero Trust Architecture Faces Structural Gaps with AI Agents
A NextGov commentary argues that federal zero trust frameworks were designed around human identities and session-based access, creating gaps that autonomous AI agents — which lack employment records, fixed identities, and predictable behavior patterns — can fall through. The author contends federal agencies cannot opt out of agentic AI and must extend zero trust models to cover non-human principals.
Why it matters: If your environment runs any AI automation or orchestration (Ansible, self-hosted LLM pipelines, agentic workflows), your current Intune/Entra identity governance and CMMC access control documentation almost certainly does not account for non-human agent identities — this is an emerging audit gap.
Microsoft Publishes Guidance on Hardening Partner Ecosystem Security in CSP Model
Microsoft's Security Blog detailed updated security requirements and best practices for Cloud Solution Provider partners, including stricter vetting, enforcement of least-privilege access, enhanced monitoring of partner-delegated admin relationships, and risk management expectations. The guidance addresses how partner compromise can cascade into customer tenants.
Why it matters: GCC High tenants that use managed service providers or CSP partners should review those partner delegated admin relationships in Entra ID — a compromised partner account represents a direct path into your tenant that bypasses most tenant-level controls.
FAR Rewrite Signals Major Structural Change for Federal Contracting Compliance
A Federal News Network commentary highlights that the ongoing Federal Acquisition Regulation rewrite represents more than updated rules — it signals a fundamental restructuring of how federal contracts are written, awarded, and administered. Experts advise contractors to begin planning now for implementation rather than waiting for the final rule.
Why it matters: CMMC compliance is embedded in the DFARS clause structure that flows from the FAR — a structural FAR rewrite could affect how CMMC requirements are flowed down in future contracts, warranting attention from your contracts and compliance team now.