Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review

Microsoft’s July 2026 Patch Tuesday delivers security updates for a broad range of products and services, including several vulnerabilities that pose significant risks to enterprise environments. As attackers continue to target unpatched systems, the timely deployment of these updates remains one of the most effective defenses against exploitation. This blog provides an overview of the month’s key security fixes,

BY Diksha Ojha
MIN READ 1 MIN READ
EXPLORE north_east
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
CYBERSECURITY

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by its Security Update Guide count, more than triple June’s previous high of around 200. Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are

1 MIN READ arrow_forward
Microsoft Patches a Record 570 Security Flaws
CYBERSECURITY

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

1 MIN READ arrow_forward
Security Hub adds AI workload protection and multicloud support for Microsoft Azure
CYBERSECURITY

Security Hub adds AI workload protection and multicloud support for Microsoft Azure

Security Hub is our foundation for full-stack enterprise security across clouds. It centralizes your security operations and turns raw signals into prioritized insights, so your team spends its time managing real risk instead of stitching tools together. Today that foundation grows in two directions our customers asked for most. We are adding purpose-built protection for

1 MIN READ arrow_forward
Managing AI Agent Primitives Like Real Software Packages with APM and JFrog
CYBERSECURITY

Managing AI Agent Primitives Like Real Software Packages with APM and JFrog

AI agents are part of the modern development workflow. They write code, review pull requests, generate tests, call tools, interact with MCP servers, and help developers move faster. But behind every useful agent, there is something just as important as the model itself: the context that tells the agent how to behave. That context can

1 MIN READ arrow_forward
Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
CYBERSECURITY

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

56Critical 510Important 3Moderate 0Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild. Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will see a higher volume of security updates included in each security release.” This month’s update includes patches for: .NET .NET Core .NET Framework ASP.NET Core Active Directory Certificate Services (AD CS) Active Directory Domain Services Active Directory Federation Services (AD FS) Azure Active Directory Azure CycleCloud Azure Monitor Agent Azure Spring Apps Code Integrity DLL (ci.dll) Composite Image File System Driver Content Delivery Manager Desktop Window Manager Extensible Storage Engine (ESENT) GitHub Copilot and Visual Studio GitHub Copilot and Visual Studio Code Github Copilot HTTP/2 Microsoft 365 Copilot for iOS Microsoft Bing App for IOS Microsoft Copilot Microsoft Defender Microsoft Defender for Endpoint Microsoft Dynamics NAV Microsoft Edge for Android Microsoft Exchange Server Microsoft Fabric Data Warehouse Microsoft Graphics Component Microsoft Input Method Editor (IME) Microsoft Install Service Microsoft NAT Helper Components (ipnathlp.dll) Microsoft Office Microsoft Office Excel Microsoft Office OneNote Microsoft Office PowerPoint Microsoft Office SharePoint Microsoft Office Word Microsoft Printer Drivers Microsoft Surface Microsoft Windows Microsoft Windows App Store Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows Search Component Microsoft Windows Speech Microsoft XML Microsoft XML Core Services Minecraft Bedrock Dedicated Server Outlook Copilot Power BI Quality Windows Audio/Video Experience (QWAVE) service RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client Role: DNS Server SQL Server SQL Server ODBC driver Universal Plug and Play (upnp.dll) Virtual Hard Disk (VHD) Miniport Driver Visual Studio Visual Studio Code Window PC Manager Windows Active Directory Windows Admin Center Windows Ancillary Function Driver for WinSock Windows App Installer Windows AppX Deployment Service Windows Application Model Windows Audio Compression Manager (ACM) Windows Audio Service Windows Backup Engine Windows BitLocker Windows Bluetooth Port Driver Windows Bluetooth Service Windows Boot Loader Windows Brokering File System Windows Client-Side Caching (CSC) Service Windows Clip Service Windows Clipboard Server Windows Clipboard User Service Windows Cloud Files Mini Filter Driver Windows Common Log File System Driver Windows Connected User Experiences and Telemetry Windows Container Isolation FS Filter Driver (unionfs.sys) Windows CryptoAPI Windows Cryptographic Services Windows DHCP Client Windows DHCP Server Windows DNS Windows DWM Windows DWM Core Library Windows Data.dll Windows Devices Human Interface Windows DirectX Windows Domain Controller Windows Event Logging Service Windows FTP Service Windows File Explorer Windows File History Service Windows Filtering Platform (WFP) Windows GDI Windows GDI+ Windows Graphics Kernel Windows Group Policy Windows HTTP.sys Windows Hyper-V Windows Image Acquisition Windows Installer Windows Internal System User Profile Windows Internal Task Bar Windows Internet Key Exchange (IKE) Protocol Windows Kernel Windows Kernel Mode Driver Windows Kernel-Mode Drivers Windows Key Guard Windows LUAFV Windows Local Security Authority Subsystem Service (LSASS) Windows MIDI Service Module Windows Management Services Windows Media Windows Message Queuing Windows Message Queuing Queue Manager Windows NTFS Windows Narrator Braille Windows Netlogon Windows Network Address Translation (NAT) Windows Network File System Windows Network Policy Server SNMP Windows Notification Windows OLE Windows Operating Systems Windows Overlay Filter Windows PowerShell Windows Presentation Foundation (WPF) Windows Print Spooler Components Windows Projected File System Windows Push Notifications Windows Quality of Service (QoS) Packet Scheduler Windows RDP Windows RPC API Windows Redirected Drive Buffering Windows Remote Access Connection Manager Windows Remote Access Service Infrastructure Windows Remote Desktop Protocol Windows Remote Desktop Services Windows Remote Help Defense Windows Resilient File System (ReFS) Windows Routing and Remote Access Service (RRAS) Windows Runtime Windows SMB Windows SMB Server Windows SMB Server Network Transport Driver (srvnet.sys) Windows Schannel Windows Secure Boot Windows Secure Kernel Mode Windows Secure Socket Tunneling Protocol (SSTP) Windows Sensor Data Service Windows Server Windows Server Backup Windows Server Network driver Windows Server Update Service Windows Spaceport.sys Windows StateRepository API Windows Storage Windows Storage Spaces Direct Windows Subsystem for Linux Windows System Windows TCP/IP Windows Telephony Service Windows Terminal Windows Trusted Runtime Interface Driver Windows USB Audio Class driver (usbaudio.sys) Windows USB Driver Windows USB Hub Driver Windows USB Print Driver Windows USB Video Driver Windows Unified Consent System Windows Universal Disk Format File System Driver (UDFS) Windows User Interface Core Windows VMSwitch Windows Virtual Filtering Platform (VFP) Windows WalletService Windows Web Proxy Auto-Discovery Protocol (WPAD) Windows WebView Windows Win32K Windows Win32K - GRFX Windows Wireless Networking Windows Wireless Wide Area Network Service Elevation of privilege (EoP) vulnerabilities accounted for 43.8% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 25.1%. Important CVE-2026-56155 | Active Directory Federation Services Elevation of Privilege Vulnerability CVE-2026-56155 is an EoP vulnerability affecting Active Directory Federation Services. It received a CVSSv3 score of 7.8 and is rated important. Microsoft notes that this flaw was exploited in the wild as a zero-day and is credited to researchers with the Microsoft Detection and Response Team (DART). Successful exploitation would allow an attacker to gain administrator privileges. Moderate CVE-2026-56164 | Microsoft SharePoint Server Elevation of Privilege Vulnerability CVE-2026-56164 is an EoP vulnerability in Microsoft SharePoint Server. It received a CVSSv3 score of 5.3 and is rated moderate. According to Microsoft, it was exploited in the wild as a zero-day. This vulnerability affects Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, as well as SharePoint Server 2016 and SharePoint Enterprise Server 2016. Microsoft notes that its Antimalware Scan Interface (AMSI) integration can provide mitigation for this vulnerability by scanning for and detecting malicious POST requests. Important CVE-2026-50661 | Windows BitLocker Security Feature Bypass Vulnerability CVE-2026-50661 is a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.1 and is rated as important. It was publicly disclosed prior to a patch being available and assessed as “Exploitation Less Likely” according to Microsoft’s Exploitability Index. While an exploit is public, the advisory notes that exploitation requires physical access to the target device. Microsoft did not provide any attribution other than to “Anonymous” though based on the advisory description, it’s possible this patch addresses GreatXML, a zero-day BitLocker bypass flaw disclosed by the researcher known as Chaotic Eclipse (Nightmare Eclipse). GreatXML was disclosed on June 10th, a day after the June Patch Tuesday release. Critical CVE-2026-55944 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability CVE-2026-55944 is a RCE vulnerability in Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central. It received a CVSSv3 score of 9.8, is rated critical and assessed as “Exploitation More Likely.” Successful exploitation can be achieved by sending a crafted login request to an affected Dynamics NAV or Business Central server in order to trigger a deserialization of untrusted data vulnerability. Microsoft’s advisory cautions that no user-interaction is required, nor is authentication a requirement in order to successfully exploit this vulnerability. Critical Multiple CVEs | Windows DHCP Server and Client Remote Code Execution, Elevation of Privilege and Denial of Service Vulnerabilities This month’s updates included patches to address multiple CVEs affecting DHCP Server and Windows DHCP Client. Of the nine CVEs, five were rated as critical and three were assessed as “Exploitation More Likely.” A breakdown of the CVEs can be found in the table below: CVE Description CVSSv3 Severity Exploitability Index CVE-2026-50518 Windows DHCP Server Remote Code Execution Vulnerability 9.8 Critical Exploitation More Likely CVE-2026-50370 DHCP Server Service Remote Code Execution Vulnerability 8.8 Critical Exploitation More Likely CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability 8.4 Critical Exploitation More Likely CVE-2026-48564 DHCP Server Service Remote Code Execution Vulnerability 8.8 Critical Exploitation Less Likely CVE-2026-49181 Windows DHCP Client Elevation of Privilege Vulnerability 7.5 Important Exploitation Less Likely CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability 9.8 Critical Exploitation Unlikely CVE-2026-50683 Windows DHCP Client Elevation of Privilege Vulnerability 8.0 Important Exploitation Unlikely CVE-2026-50685 Windows DHCP Server Remote Code Execution Vulnerability 7.5 Important Exploitation Unlikely CVE-2026-58627 Windows DHCP Server Denial of Service Vulnerability 7.5 Important Exploitation Unlikely Important Multiple CVEs | Windows Kernel Elevation of Privilege Vulnerability Updates this month include 20 CVEs addressing EoP vulnerabilities in the Windows Kernel. CVSSv3 scores range from 4.7 to 9.3 and six of the 20 were assessed as “Exploitation More Likely.” Additionally, Windows Kernel saw several additional security fixes this month with six CVEs for Information Disclosure flaws and two security feature bypasses. A breakdown of the EoP CVEs can be found in the tables below: Windows Kernel Elevation of Privilege Vulnerabilities CVE CVSSv3 Severity Exploitability Index CVE-2026-49798 9.3 Important Exploitation More Likely CVE-2026-49795 8.8 Important Exploitation More Likely CVE-2026-50332 7.8 Important Exploitation More Likely CVE-2026-50423 7.8 Important Exploitation More Likely CVE-2026-50436 7.8 Important Exploitation More Likely CVE-2026-50390 7.0 Important Exploitation More Likely CVE-2026-50477 8.8 Important Exploitation Less Likely CVE-2026-49173 7.8 Important Exploitation Less Likely CVE-2026-49808 7.8 Important Exploitation Less Likely CVE-2026-50399 7.8 Important Exploitation Less Likely CVE-2026-50478 7.8 Important Exploitation Less Likely CVE-2026-50484 7.8 Important Exploitation Less Likely CVE-2026-50673 7.8 Important Exploitation Less Likely CVE-2026-58532 7.8 Important Exploitation Less Likely CVE-2026-50354 7.1 Important Exploitation Less Likely CVE-2026-50397 7.0 Important Exploitation Less Likely CVE-2026-50459 7.0 Important Exploitation Less Likely CVE-2026-54132 6.8 Important Exploitation Less Likely CVE-2026-50377 5.5 Important Exploitation Less Likely CVE-2026-49167 4.7 Important Exploitation Less Likely Tenable Solutions A list of all the plugins released for Microsoft’s July 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched. For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable. Get more information Microsoft’s July 2026 Security Updates Tenable plugins for Microsoft July 2026 Patch Tuesday Security Updates Join Tenable’s Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats. Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

8 MIN READ arrow_forward
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
CYBERSECURITY

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9), an out-of-bounds write flaw that allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could

1 MIN READ arrow_forward
How Qualys ETM Identity Detects Identity-Based Attacks Faster
CYBERSECURITY

How Qualys ETM Identity Detects Identity-Based Attacks Faster

Key Takeaways Identity-based attacks are among the fastest and most effective intrusion methods because valid credentials let attackers operate as trusted users. Techniques like Pass-the-Hash, Kerberoasting, Domain Controller Synchronization (DCSync), and Authentication Server Response Roasting (AS-REP Roasting) are common Active Directory (AD) attacks that exploit AD trust relationships. Qualys ETM Identity helps organizations discover risky

1 MIN READ arrow_forward
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
CYBERSECURITY

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Any other browser extension that can run a script on claude.ai can still trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc and its comments, and your Calendar. Both this and ClaudeBleed need a rogue extension that can already run a script on claude.ai; the difference is scope. Anthropic restricted the arbitrary-prompt path in May as part of its response to the

1 MIN READ arrow_forward
LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts
CYBERSECURITY

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. “LabubaRAT creates a reusable foothold for hands-on activity,” Blackpoint Cyber researchers Sam Decker and Nevan Beal said in an analysis published today. “Once deployed, it can profile the host,

1 MIN READ arrow_forward
AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI
CYBERSECURITY

AI Controls Matrix v1.1: Strengthening the Foundation for Trustworthy AI

The Cloud Security Alliance (CSA) recently announced the release of the AI Controls Matrix (AICM) v1.1, a significant update to our comprehensive framework for secure and trustworthy AI systems. Building on the strong foundation established with the original AICM release in 2025, this update expands our control coverage, includes a dedicated Model Security domain, AI-specific security controls, and delivers complete mappings to the world’s major AI governance frameworks, inclu…

1 MIN READ arrow_forward