Daily Security Intel

Archives
Log in
Subscribe
July 15, 2026

[SecurityIntel] 15 Jul | Record Microsoft Patch Tuesday Fixes Active Zero-Days

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, July 15, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Record Microsoft Patch Tuesday Fixes Active Zero-Days

CRITICAL

5

C2 IPs

69

OTX IOCs

36

ARTICLES

■ ANALYST TLDR

Microsoft's historic July 2026 Patch Tuesday addresses a record-breaking 622 vulnerabilities, including actively exploited zero-days in Active Directory and SharePoint Server. Concurrently, SonicWall has urged immediate patching for two SMA1000 zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) actively exploited in the wild. Additionally, Progress Software has confirmed a zero-day vulnerability behind the emergency shutdown of ShareFile Storage Zone Controllers, while state-sponsored Russian actors continue to compromise critical infrastructure routers and internet-connected cameras.

■ CRITICAL STORIES

CRITICAL#1

SonicWall SMA1000 Zero-Days Exploited in the Wild

SonicWall has warned that threat actors are actively exploiting two zero-day vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in its SMA1000 series appliances. Organizations must patch immediately to prevent unauthorized access and potential network compromise.

CRITICAL#2

Microsoft Patches Record-Breaking 622 Vulnerabilities, Including Two Zero-Days

Microsoft's July 2026 Patch Tuesday is its largest ever, fixing 622 flaws. Crucially, two zero-days affecting Active Directory and SharePoint Server are under active exploitation, requiring urgent deployment of cumulative updates.

HIGH#3

Progress Software Confirms ShareFile Zero-Day Behind Emergency Shutdown

Progress Software has confirmed that a high-severity zero-day vulnerability prompted the emergency shutdown of ShareFile Storage Zone Controllers. Patches have been released to secure the affected controllers.

CRITICAL#4

US and Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers

State-sponsored Russian threat actors are actively compromising poorly secured routers across critical infrastructure sectors to establish persistence and facilitate intelligence gathering.

■ CVEs IDENTIFIED

CVE-2026-15409

SonicWall SMA1000 — Arbitrary Code Execution / Zero-Day

Critical

CVE-2026-15410

SonicWall SMA1000 — Arbitrary Code Execution / Zero-Day

Critical

CVE-2026-44747

SAP NetWeaver Application Server ABAP — Out-of-bounds memory access leading to data exposure or modification

Critical

[CVE-TBD]

Microsoft Active Directory — Active zero-day exploitation leading to privilege escalation or domain compromise

Critical

■ THREAT ACTORS

D1R

Cybercrime Group

Claimed fake data breach of Synopsys and Bosch, attempting extortion.

BlackCat (ALPHV)

Ransomware Group

Involved in extortion schemes aided by a rogue negotiator.

Russian State-Sponsored APTs

Nation-State

Compromising critical infrastructure routers and internet-connected cameras.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) and Progress ShareFile zero-day exploited.
T1566
Phishing | Fake security alerts targeting LastPass and Bitwarden users; BEC fraud rings.
T1036.005
Masquerading: Match Legitimate Name or Location | LabubaRAT masquerading as NVIDIA software; fake GitHub repos impersonating legit software.
T1584.001
Compromise Infrastructure: Domains | Fake GitHub repositories used to distribute infostealer malware.
T1425
Secure Boot Bypass | Exploiting old Microsoft-signed Linux UEFI shims to bypass Secure Boot.
T1210
Exploitation of Remote Services | Exploiting Active Directory and SharePoint Server zero-days.

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL — SonicWall SMA1000 — Active zero-day exploitation of CVE-2026-15409 and CVE-2026-15410 — BleepingComputer

[P3 PATCH NOW]≤1 week

CRITICAL — Microsoft Active Directory & SharePoint — Active zero-day exploitation fixed in July 2026 Patch Tuesday — SecurityWeek

[P3 PATCH NOW]≤1 week

CRITICAL — Progress ShareFile Storage Zone Controllers — High-severity zero-day exploited in the wild — BleepingComputer

[P3 PATCH NOW]≤1 week

CRITICAL — SAP NetWeaver ABAP — CVE-2026-44747 has a CVSS score of 9.9 and allows unauthorized data modification — The Hacker News

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch SonicWall SMA1000 appliances immediately to address actively exploited zero-days CVE-2026-15409 and CVE-2026-15410.
2[P1] Apply Microsoft July 2026 Patch Tuesday updates (KB5099539, KB5101650, KB5099414) to mitigate 622 vulnerabilities, including the Active Directory and SharePoint zero-days.
3[P1] Update Progress ShareFile Storage Zone Controllers to resolve the high-severity zero-day vulnerability that forced recent shutdowns.
4[P1] Apply SAP's July 2026 security updates, specifically patching CVE-2026-44747 (CVSS 9.9) in NetWeaver Application Server ABAP.
5[P2] Update Adobe ColdFusion and VMware Avi Load Balancer to patch critical remote code execution and privilege escalation flaws.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 16 Jul | AsyncAPI npm Supply Chain Compromise Distributes Malware Older → [SecurityIntel] 14 Jul | Active Exploitation of Joomla RCE and Zimbra Flaws
Powered by Buttondown, the easiest way to start and grow your newsletter.