HomeCybersecurity NewsCybersecurity news weekly roundup July 6, 2026
July 6, 2026

Cybersecurity news weekly roundup July 6, 2026

San Mateo, CA, July 6, 2026 — Developments, threats, and responses in the news last week.

STORIES LAST WEEK

CISA orders fast SharePoint patching after active exploitation

CISA added CVE-2026-45659 to KEV after confirmed SharePoint Server exploitation, giving federal agencies until July 4 to patch. The flaw affects collaboration servers that often hold sensitive internal documents and workflows. The Hacker News, July 2, 2026

Cisco confirms exploitation of Unified CM flaw

Cisco confirmed attackers are exploiting CVE-2026-20230 in Unified Communications Manager, a core voice system. Administrators should patch or disable WebDialer, because successful SSRF exploitation can write files and support deeper compromise. BleepingComputer, July 2, 2026

Oracle E-Business Suite attacks target exposed enterprise systems

More than 900 Oracle E-Business Suite instances were exposed as attackers exploited CVE-2026-46817. The unauthenticated takeover risk hits finance, procurement, and payment workflows that often connect directly to sensitive back-office data. BleepingComputer, July 1, 2026

BlueHammer exploitation moves into ransomware campaigns

The Microsoft Defender flaw CVE-2026-33825, known as BlueHammer, is now linked to ransomware activity. Endpoint teams should verify April updates, because the bug can help attackers gain SYSTEM privileges. SecurityWeek, June 30, 2026

Azure CLI password spray campaign hits Microsoft 365 tenants

Huntress observed more than 81 million login attempts against Microsoft 365 environments using Azure CLI and exposed credentials. The campaign shows how weak conditional access and ROPC exposure can undermine MFA assumptions. SecurityWeek, July 1, 2026

Hackers breach DHS information-sharing platform

Hackers breached the Homeland Security Information Network, a sensitive but unclassified sharing platform for government, international, and private-sector partners. The incident raises operational risk around incident coordination, event security, and partner communications. Nextgov/FCW, June 30, 2026

ARToken panel exposes mature Microsoft 365 phishing operations

Cisco Talos detailed ARToken, an EvilTokens-linked phishing-as-a-service panel with more than 80 API endpoints for device-code phishing, token persistence, mailbox access, BEC, and SharePoint exfiltration. Cisco Talos, July 1, 2026

ChocoPoC campaign hides malware in exploit dependencies

YesWeHack and Sekoia found trojanized GitHub proof-of-concept repositories targeting researchers and pentesters. The payload hides in PyPI dependencies, making casual code review less effective and turning exploit testing into credential theft. YesWeHack, July 1, 2026

SimpleHelp exploitation delivers new credential-stealing malware

Attackers exploited CVE-2026-48558 in SimpleHelp to deploy TaskWeaver and Djinn Stealer. The malware targets credentials across cloud, code, AI, and developer environments, increasing downstream compromise risk after remote support server exposure. The Hacker News, June 30, 2026

Cursor flaws turn prompt injection into code execution

Cato AI Labs disclosed DuneSlide, two critical Cursor IDE flaws that let zero-click prompt injection escape the sandbox and execute code. The findings show agentic coding tools can expose classic local compromise paths. Cato Networks, July 1, 2026

Unit 42 warns AI hallucinated domains are becoming an attack surface

Unit 42 found LLM-generated brand URLs can create exploitable domain opportunities. Its tests produced 2.1 million URLs, more than 13,000 confirmed malicious URLs, and about 250,000 unregistered domains attackers could claim. Unit 42, July 1, 2026

Fake bug reports can hijack AI coding agents

Researchers demonstrated agentjacking, where a poisoned bug report can cause AI coding agents to execute attacker-controlled instructions. The risk matters for development teams connecting agents to issue trackers, repositories, and local tooling. Dark Reading, June 30, 2026

China-linked group targets critical systems in Southeast Asia

A China-linked threat group targeted Southeast Asian critical systems, according to reporting from Palo Alto Networks. The activity matters to U.S. operators because it reinforces persistent risk to energy, industrial, and regional infrastructure partners. Dark Reading, July 1, 2026

Alleged Scattered Spider member extradited to the U.S.

The Justice Department said alleged Scattered Spider member Peter Stokes was extradited from Finland to face charges tied to cyber intrusion and fraud. Prosecutors linked the group to more than 100 intrusions and major ransom losses. Justice Department, July 1, 2026

KDDI breach exposes credentials across six ISPs

KDDI disclosed a breach affecting up to 14.22 million email credentials across six Japanese ISPs after attackers exploited third-party software. Shared service infrastructure made one compromise a multi-provider credential exposure event. TechRadar, June 29, 2026

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles