Policy, geopolitics, and vulnerability management shifts
Record July Patch Tuesday 722 CVEs reinforces AI-driven patch inflation and structural shift. CISA urges immediate SharePoint hardening with segmentation-over-patch-speed argument. CrowdStrike warns of AI zero-day flood as operational crisis. Trump lifts export controls on Anthropic Fable 5 and Mythos 5. CISA BOD 26-04 formalizes risk-based prioritization. CISA issues 3-day patch directive for federal agencies (including FortiSandbox). Check Point Exposure Gap Report finds critical vulns doubled, only 7.8% need urgent action. NVD collapse combined with AI vulnerability wave creates systemic prioritization crisis. Pearson breach case highlights gap between knowing and acting — SEC enforcement signals materiality defined by impact. AI arms race asymmetry: US policy vacuum vs China's 37x investment. The Intercept Signal tip line hijacked highlights third-party risk. Apple shifts to rapid unbundled security updates. MOVEit settlement (GRIPA $2.15M) reinforces long-tail supply chain liability. SharePoint RCE added to KEV after Microsoft downplayed exploitability. Microsoft Patch Tuesday 244 CVEs (previous) now superseded by 722. AI attack vectors article details Grok prompt injection, Galileu legal deception, under-8-minute AWS takeover. Oracle PeopleSoft zero-day added to CISA KEV. Nightmare Eclipse-Microsoft dispute highlights legal threats chilling researcher trust. VM failure analysis highlights exploitability-first triage. AI clearinghouse proposal. CISA adds three KEVs. 'Patch Apocalypse' article frames AI-driven discovery outpacing remediation. Microsoft releases fix for RoguePlanet Defender flaw. Defender patch side effect can fill disks. Microsoft formalizes MDASH. Mythos-class AI could change risk calculus around Chinese hardware. Mitiga joins Anthropic CVP. Zero-Hour lifecycle analysis. Business case for burning down security debt. Three Microsoft Defender zero-days (two unpatched) actively exploited. Ubiquiti UniFi patches critical CVEs. Palo Alto patches 13 vulns. July Patch Tuesday forecast questions CVE tracking practicality. CVE-2026-47291 Windows HTTP.sys RCE. RoguePlanet patch side effect criticism. Unverified $2.5M M365 Exchange Online zero-day auction. ENISA publishes official view on frontier AI cybersecurity. Decision-oriented vulnerability prioritization paper validates context-aware risk estimation. Apple emergency patches for two WebKit zero-days. Edge RCE CVE-2026-58281. Langflow RCE deep-dive. New: CISA adds SharePoint RCE CVE-2026-58644 to KEV. New: AD FS privilege escalation CVE-2026-56155 added to KEV. New: .NET SslStream bypass CVE-2026-50528 patched. New: Apple class action over Hide My Email flaw. New: Attackers exploiting trust (identity, AI social engineering) article. New: State cyber threat assessment details Chinese APT Salt Typhoon/Volt Typhoon. New: FortiSandbox CISA 3-day patch directive highlights trust chain risk. New: SharePoint zero-day pattern shows patching alone insufficient (IIS key theft). New: AI-driven patch inflation confirmed by Windows 11 570-vuln update. New: Google Chrome two critical updates in 48 hours. New: ServiceNow sandbox escape exploited in wild. New: Mid-July threat report adds 10 CISA KEVs (FortiSandbox, SMA1000, SharePoint, legacy Cisco) and 2,757 new vulns. New: WP2Shell WordPress RCE with public exploits reinforces AI-driven patch urgency. New: Critical NGINX heap overflow (CVE-2026-42533) adds to infrastructure zero-day wave. New: Joint CISA/FBI/NSA advisory on Russian router hijacking. New: OpenAI sandbox escape incident raises policy questions about AI agent containment and evaluation. Bug bounty bottleneck highlights need for AI-era triage processes. The next arms race is fixing first, not finding first. New: CISA BOD 26-04 and Five Eyes statement reinforce AI-driven vulnerability window collapse, shifting to risk-tiered prioritization. New: Splunk zero-day added to CISA KEV with 3-day deadline, highlighting SIEM trust chain risk. New: Default Azure Automation setting (CVSS 9.9) enables cross-tenant identity takeover — patched, no exploits yet, but must-audit for Azure shops. New: Certighost AD CS exploit (public PoC) reinforces identity infrastructure attack trends. New: Shrinking exploit window article reiterates AI acceleration and need for visibility over patch-only strategies. New: Claude Mythos article reinforces fixing-first paradigm. New: Frontier AI and OT gap article highlights OT-specific challenges.