HomeCybersecurity NewsCybersecurity news weekly roundup, July 20 2026
July 20, 2026

Cybersecurity news weekly roundup, July 20 2026

San Mateo, CA, July 20, 2026 — Developments, threats, and responses in the news last week.

STORIES LAST WEEK

Microsoft patches record 622 vulnerabilities

Microsoft issued 622 fixes, including 62 critical vulnerabilities and two zero-days under active exploitation. The record release, driven partly by AI-accelerated research, strains testing and deployment processes built for smaller monthly patch volumes. The Hacker News, July 14, 2026

SonicWall SMA 1000 zero-days exploited before disclosure

Rapid7 observed attackers chaining two SonicWall SMA 1000 flaws for unauthenticated root-level command execution before disclosure. Internet-facing remote access appliances require emergency patching because attackers harvested credentials and established enterprise footholds. Rapid7, July 15, 2026

Progress keeps ShareFile storage controllers offline during threat investigation

Progress disabled ShareFile access using Storage Zone Controllers and told customers to shut down self-managed servers while investigating a credible external threat. The incident shows how hybrid storage control points can require abrupt isolation, even without confirmed data access. SecurityWeek, July 13, 2026

AsyncAPI compromise turns GitHub Actions flaw into npm attack

Attackers exploited a misconfigured GitHub Actions workflow to steal a privileged AsyncAPI token, then published four malicious npm packages with more than 3 million weekly downloads. The payload executed when imported, exposing developer, build, and CI environments. Wiz, July 14, 2026

Compromised jscrambler releases execute hidden cross-platform binaries

A compromised jscrambler release added hidden binaries for Windows, macOS, and Linux, initially running through a preinstall hook and later on import. Teams must inspect developer workstations and CI systems, then rotate exposed build and deployment credentials. Socket, July 11, 2026

Russian state hackers target poorly secured critical infrastructure routers

U.S. and allied agencies warned that Russian state-sponsored groups are compromising poorly secured routers across critical infrastructure networks. Administrators should harden management interfaces and investigate configuration changes and suspicious outbound traffic. CISA, July 13, 2026

6 GHz Wi-Fi coordination flaws threaten critical communications

Researchers found Automated Frequency Coordination systems trust client-supplied location, DNS, and time data. Spoofed inputs could disrupt 6 GHz Wi-Fi coordination, extending risk beyond enterprise wireless deployments. Dark Reading, July 14, 2026

OAuth client ID spoofing hides Entra ID account enumeration

Proofpoint found attackers spoofing OAuth client IDs to enumerate Entra ID accounts, infer password validity, and avoid successful sign-in events. One campaign targeted more than 2 million users, creating a detection gap in standard authentication monitoring. Proofpoint, July 13, 2026

ClickLock Stealer bypasses macOS defenses through user-executed commands

ClickLock Stealer uses fake Cloudflare verification pages to convince macOS users to paste malicious commands into Terminal. The scripts steal browser, wallet, password manager, Keychain, FTP, and shell-history data, then install a persistent backdoor. SecurityWeek, July 16, 2026

LLM-assisted TuxBot framework targets 17 IoT architectures

Unit 42 recovered an LLM-assisted IoT botnet framework compiled for 17 architectures, with 1,496 credential pairs, more than 30 device exploits, encrypted command channels, and DDoS tooling. AI-generated coding errors limited some functions. Palo Alto Networks Unit 42, July 15, 2026

White House launches AI-assisted vulnerability coordination clearinghouse

The White House launched Gold Eagle, a voluntary AI-assisted clearinghouse for vulnerability intake, validation, prioritization, and patch coordination across critical infrastructure. The initiative aims to reduce duplicate scanning, though implementation details and authority remain unclear. Dark Reading, July 17, 2026

Forg365 industrializes Microsoft 365 phishing and session theft

Forg365 combines device-code phishing, adversary-in-the-middle session theft, AI-generated lures, antibot evasion, token vaulting, and mailbox operations in a subscription service. The integrated platform lowers the skill and infrastructure required for scalable Microsoft 365 compromise. The Hacker News, July 13, 2026

U.S. indicts operators of bulletproof hosting infrastructure

U.S. prosecutors charged three Russian nationals and two companies with operating bulletproof hosting that supported attacks causing more than $62 million in losses. Victims included banks, hospitals, schools, government entities, and media organizations across 21 states. U.S. Department of Justice, July 14, 2026

Scattered Spider members sentenced for Transport for London attack

Two Scattered Spider members received five-and-a-half-year prison terms for the Transport for London attack. The intrusion disabled 148 systems, forced 27,000 employee password resets, disrupted public services, and caused £29 million in losses and recovery costs. National Crime Agency, July 16, 2026

More cybersecurity news

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles