~/greenteam/nerd

Thursday, July 16, 2026

Daily digest

cybersec The Register

CISA Sounds Alarm Over Trio of Actively Exploited SharePoint Flaws

CISA added three Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild, with two additional critical flaws also disclosed. Federal agencies and organizations are under pressure to patch promptly. The Register reports two more critical holes could compound the exposure.

Why it matters: SharePoint Online is part of M365 GCC High; even if Microsoft patches the cloud-side, any on-prem SharePoint instances or hybrid configurations in your environment need immediate attention. Confirm your Intune/Defender telemetry is flagging exploitation attempts against SharePoint endpoints.

cybersec BleepingComputer

Zoom Patches Critical Windows Flaw (CVSS 9.8) That Could Enable Account Takeover

Zoom disclosed CVE-2026-53412, a critical improper input validation vulnerability (CVSS 9.8) affecting Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. The flaw could allow an unauthenticated attacker to take over accounts. Security updates have been released.

Why it matters: If Zoom is deployed on your Intune-managed Windows 11 fleet, this is a patch-now situation — CVSS 9.8 with unauthenticated exploitation means no user interaction is required. Verify Intune compliance policies are pushing the updated Zoom client and check VDI images on Nutanix AHV as well.

cybersec BleepingComputer

Russian Hackers Trojanize WebEx and Zoom Apps to Push Starland Malware

A financially motivated Russian threat actor tracked as UAT-11795 is distributing trojanized versions of WebEx and Zoom installers to deploy a new backdoor called Starland RAT, which steals credentials and cryptocurrency. The campaign targets users who download what appear to be legitimate conferencing applications from unofficial sources.

Why it matters: Combined with today's Zoom CVE-2026-53412, this creates a one-two risk: users seeking patched Zoom versions may be steered toward trojanized installers. Enforce software installation exclusively through Intune/Company Portal and block user-initiated downloads from unmanaged sources.

cmmc BleepingComputer

CISA Orders Federal Agencies to Patch Actively Exploited Oracle E-Business Suite Flaw by Saturday

CISA issued an emergency directive requiring federal agencies to patch a critical vulnerability in Oracle E-Business Suite by the end of this week, citing evidence of active exploitation in the wild. The flaw affects a widely deployed financial application used across government and enterprise environments.

Why it matters: If Oracle E-Business Suite runs anywhere in your environment or at a contractor/agency you interface with, the Saturday deadline is non-negotiable for federal systems. Even if you don't run it, CISA KEV additions are directly relevant to CMMC L2 vulnerability management requirements under NIST 800-171 SI.2.

cybersec Microsoft Security Blog

AsyncAPI npm Supply Chain Compromise Delivers Multi-Stage Botnet Malware via CI/CD

Multiple versions of @asyncapi namespace packages on npm were compromised and weaponized to deliver a multi-stage botnet loader and remote access trojan with credential-stealing capabilities. Microsoft's Security Blog confirmed that threat actors exploited trusted CI/CD workflows to distribute the malicious payloads at import time, with four packages confirmed affected.

Why it matters: If Ansible playbooks, automation pipelines, or any developer tooling in your environment pulls npm packages — directly or transitively — audit your dependency trees for @asyncapi packages immediately. This is a CI/CD-vector attack, meaning your Ansible or build infrastructure could be the infection point, not just developer workstations.

cybersec The Hacker News

Researcher Drops Windows Zero-Day PoC (LegacyHive) Hours After Patch Tuesday

Security researcher Chaotic Eclipse published a proof-of-concept exploit called LegacyHive targeting a Windows User Profile Service (ProfSvc) elevation-of-privilege vulnerability, released shortly after July Patch Tuesday. Experts characterize it as a practical post-compromise privilege escalation tool rather than a remote code execution vector. No CVE patch has been issued for this specific variant.

Why it matters: A public EoP PoC with no patch means attackers with any foothold on your Windows 11 fleet can potentially escalate to SYSTEM. Monitor Defender for Endpoint alerts for ProfSvc abuse and ensure privileged access workstations are hardened against local privilege escalation paths.

cybersec Dark Reading

Forgotten UEFI Shim Bootloaders Expose Secure Boot Blind Spot

Researchers identified nearly a dozen vulnerable and officially revoked UEFI shim bootloaders that remained trusted in systems for years, providing attackers a pathway to bypass Secure Boot protections. The bootloaders were not removed from trust databases despite being revoked, leaving systems silently exposed.

Why it matters: Nutanix AHV nodes and any Linux-based infrastructure booting with UEFI Secure Boot should be audited to confirm revocation databases (dbx) are current. This is directly relevant to CMMC L2 configuration management controls — a misconfigured Secure Boot trust chain can invalidate system integrity assumptions.

cybersec BleepingComputer

New Spirals Ransomware Encrypts Victim Network in Under 24 Hours

A newly identified ransomware actor called Spirals completed a full intrusion cycle — initial access, lateral movement, data exfiltration, and full network encryption — in less than 24 hours. The speed of the operation leaves minimal response window once initial access is achieved.

Why it matters: Sub-24-hour dwell time means perimeter detection alone is insufficient — validate that your Defender for Endpoint EDR policies enable automated isolation of compromised hosts and that Nutanix AHV VM snapshots are taken frequently enough to support rapid recovery within your RTO/RPO targets.

cybersec Dark Reading

Identity Attacks Overtake Exploits as Top Ransomware Root Cause; MFA Bypass on the Rise

A new industry report finds that email-based identity attacks surpassed vulnerability exploitation as the leading ransomware entry point in the past year. Critically, MFA was deployed in 97% of credential-based attack cases yet still failed to prevent compromise, indicating widespread MFA fatigue, push-bombing, and session token theft.

Why it matters: M365 GCC High environments relying on standard MFA (push notifications) are at demonstrated risk. Evaluate whether phishing-resistant MFA (FIDO2/Windows Hello for Business) is enforced via Intune conditional access policies, as NIST 800-171r3 increasingly favors phishing-resistant authenticators.

cybersec The Hacker News

Firefox and VMware Updates Fix Multiple Critical Security Flaws; Exploit Code Public

Mozilla released emergency patches for two critical Firefox vulnerabilities — CVE-2026-15718 (invalid pointer in WebAssembly) and CVE-2026-15719 (site isolation bypass) — with exploit code already publicly available. The same release cycle also includes critical VMware security fixes. Mozilla confirmed awareness of public exploit code but has not yet observed in-the-wild exploitation.

Why it matters: Public exploit code for critical browser CVEs demands immediate patching across your Windows 11 fleet via Intune. The VMware fixes are additionally relevant — verify whether any VMware components persist alongside Nutanix AHV in your virtualization stack and apply patches accordingly.

infrastructure BleepingComputer

Windows 11 24H2 Home and Pro Reach End of Support in 90 Days

Microsoft announced that Windows 11 version 24H2 Home and Pro editions will stop receiving security updates in approximately 90 days. Windows 10 Enterprise LTSB 2016 is also approaching end of support on the same timeline.

Why it matters: Unpatched OS versions are a direct CMMC L2 compliance gap under SI.2. If any Intune-managed devices remain on 24H2 Home/Pro past the deadline, they will fall out of compliance. Begin enforcing feature update policies in Intune now to migrate to 25H2 or Enterprise LTSC before the cutoff.

cmmc FedScoop

GSA's Proposed AI Acquisition Rule Still Falls Short, Contractors Say

At a GSA listening session, government contracting experts and AI vendors criticized the agency's revised AI procurement rule as too vague and misaligned with current commercial contracting standards. Contractors have until August 3 to submit formal feedback on the proposed overhaul to LLM acquisition policy.

Why it matters: If your organization is pursuing or maintaining government AI contracts, the August 3 comment deadline is actionable. The rule's vagueness also creates near-term uncertainty about how AI tools — including any self-hosted LLM stack — will be evaluated under future contract compliance reviews.