SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, July 15, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Record Microsoft Patch Tuesday Fixes Active Zero-Days | CRITICAL |
|
5 C2 IPs | 69 OTX IOCs | 36 ARTICLES |
|
■ ANALYST TLDR Microsoft's historic July 2026 Patch Tuesday addresses a record-breaking 622 vulnerabilities, including actively exploited zero-days in Active Directory and SharePoint Server. Concurrently, SonicWall has urged immediate patching for two SMA1000 zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) actively exploited in the wild. Additionally, Progress Software has confirmed a zero-day vulnerability behind the emergency shutdown of ShareFile Storage Zone Controllers, while state-sponsored Russian actors continue to compromise critical infrastructure routers and internet-connected cameras. |
|
■ CRITICAL STORIES SonicWall SMA1000 Zero-Days Exploited in the Wild SonicWall has warned that threat actors are actively exploiting two zero-day vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in its SMA1000 series appliances. Organizations must patch immediately to prevent unauthorized access and potential network compromise. |
Microsoft Patches Record-Breaking 622 Vulnerabilities, Including Two Zero-Days Microsoft's July 2026 Patch Tuesday is its largest ever, fixing 622 flaws. Crucially, two zero-days affecting Active Directory and SharePoint Server are under active exploitation, requiring urgent deployment of cumulative updates. |
Progress Software Confirms ShareFile Zero-Day Behind Emergency Shutdown Progress Software has confirmed that a high-severity zero-day vulnerability prompted the emergency shutdown of ShareFile Storage Zone Controllers. Patches have been released to secure the affected controllers. |
US and Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers State-sponsored Russian threat actors are actively compromising poorly secured routers across critical infrastructure sectors to establish persistence and facilitate intelligence gathering. |
|
■ CVEs IDENTIFIED CVE-2026-15409 SonicWall SMA1000 — Arbitrary Code Execution / Zero-Day |
CVE-2026-15410 SonicWall SMA1000 — Arbitrary Code Execution / Zero-Day |
CVE-2026-44747 SAP NetWeaver Application Server ABAP — Out-of-bounds memory access leading to data exposure or modification |
[CVE-TBD] Microsoft Active Directory — Active zero-day exploitation leading to privilege escalation or domain compromise |
|
■ THREAT ACTORS Claimed fake data breach of Synopsys and Bosch, attempting extortion. |
BlackCat (ALPHV) | Ransomware Group |
Involved in extortion schemes aided by a rogue negotiator. |
Russian State-Sponsored APTs | Nation-State |
Compromising critical infrastructure routers and internet-connected cameras. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) and Progress ShareFile zero-day exploited. |
| T1566 | | Phishing | Fake security alerts targeting LastPass and Bitwarden users; BEC fraud rings. |
| T1036.005 | | Masquerading: Match Legitimate Name or Location | LabubaRAT masquerading as NVIDIA software; fake GitHub repos impersonating legit software. |
| T1584.001 | | Compromise Infrastructure: Domains | Fake GitHub repositories used to distribute infostealer malware. |
| T1425 | | Secure Boot Bypass | Exploiting old Microsoft-signed Linux UEFI shims to bypass Secure Boot. |
| T1210 | | Exploitation of Remote Services | Exploiting Active Directory and SharePoint Server zero-days. |
|
■ PATCH PRIORITY CRITICAL — SonicWall SMA1000 — Active zero-day exploitation of CVE-2026-15409 and CVE-2026-15410 — BleepingComputer |
CRITICAL — Microsoft Active Directory & SharePoint — Active zero-day exploitation fixed in July 2026 Patch Tuesday — SecurityWeek |
CRITICAL — Progress ShareFile Storage Zone Controllers — High-severity zero-day exploited in the wild — BleepingComputer |
CRITICAL — SAP NetWeaver ABAP — CVE-2026-44747 has a CVSS score of 9.9 and allows unauthorized data modification — The Hacker News |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch SonicWall SMA1000 appliances immediately to address actively exploited zero-days CVE-2026-15409 and CVE-2026-15410. |
| 2 | [P1] Apply Microsoft July 2026 Patch Tuesday updates (KB5099539, KB5101650, KB5099414) to mitigate 622 vulnerabilities, including the Active Directory and SharePoint zero-days. |
| 3 | [P1] Update Progress ShareFile Storage Zone Controllers to resolve the high-severity zero-day vulnerability that forced recent shutdowns. |
| 4 | [P1] Apply SAP's July 2026 security updates, specifically patching CVE-2026-44747 (CVSS 9.9) in NetWeaver Application Server ABAP. |
| 5 | [P2] Update Adobe ColdFusion and VMware Avi Load Balancer to patch critical remote code execution and privilege escalation flaws. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |