STORIES LAST WEEK
CISA orders fast SharePoint patching after active exploitation
CISA added CVE-2026-45659 to KEV after confirmed SharePoint Server exploitation, giving federal agencies until July 4 to patch. The flaw affects collaboration servers that often hold sensitive internal documents and workflows. The Hacker News, July 2, 2026
Cisco confirms exploitation of Unified CM flaw
Cisco confirmed attackers are exploiting CVE-2026-20230 in Unified Communications Manager, a core voice system. Administrators should patch or disable WebDialer, because successful SSRF exploitation can write files and support deeper compromise. BleepingComputer, July 2, 2026
Oracle E-Business Suite attacks target exposed enterprise systems
More than 900 Oracle E-Business Suite instances were exposed as attackers exploited CVE-2026-46817. The unauthenticated takeover risk hits finance, procurement, and payment workflows that often connect directly to sensitive back-office data. BleepingComputer, July 1, 2026
BlueHammer exploitation moves into ransomware campaigns
The Microsoft Defender flaw CVE-2026-33825, known as BlueHammer, is now linked to ransomware activity. Endpoint teams should verify April updates, because the bug can help attackers gain SYSTEM privileges. SecurityWeek, June 30, 2026
Azure CLI password spray campaign hits Microsoft 365 tenants
Huntress observed more than 81 million login attempts against Microsoft 365 environments using Azure CLI and exposed credentials. The campaign shows how weak conditional access and ROPC exposure can undermine MFA assumptions. SecurityWeek, July 1, 2026
Hackers breach DHS information-sharing platform
Hackers breached the Homeland Security Information Network, a sensitive but unclassified sharing platform for government, international, and private-sector partners. The incident raises operational risk around incident coordination, event security, and partner communications. Nextgov/FCW, June 30, 2026
ARToken panel exposes mature Microsoft 365 phishing operations
Cisco Talos detailed ARToken, an EvilTokens-linked phishing-as-a-service panel with more than 80 API endpoints for device-code phishing, token persistence, mailbox access, BEC, and SharePoint exfiltration. Cisco Talos, July 1, 2026
ChocoPoC campaign hides malware in exploit dependencies
YesWeHack and Sekoia found trojanized GitHub proof-of-concept repositories targeting researchers and pentesters. The payload hides in PyPI dependencies, making casual code review less effective and turning exploit testing into credential theft. YesWeHack, July 1, 2026
SimpleHelp exploitation delivers new credential-stealing malware
Attackers exploited CVE-2026-48558 in SimpleHelp to deploy TaskWeaver and Djinn Stealer. The malware targets credentials across cloud, code, AI, and developer environments, increasing downstream compromise risk after remote support server exposure. The Hacker News, June 30, 2026
Cursor flaws turn prompt injection into code execution
Cato AI Labs disclosed DuneSlide, two critical Cursor IDE flaws that let zero-click prompt injection escape the sandbox and execute code. The findings show agentic coding tools can expose classic local compromise paths. Cato Networks, July 1, 2026
Unit 42 warns AI hallucinated domains are becoming an attack surface
Unit 42 found LLM-generated brand URLs can create exploitable domain opportunities. Its tests produced 2.1 million URLs, more than 13,000 confirmed malicious URLs, and about 250,000 unregistered domains attackers could claim. Unit 42, July 1, 2026
Fake bug reports can hijack AI coding agents
Researchers demonstrated agentjacking, where a poisoned bug report can cause AI coding agents to execute attacker-controlled instructions. The risk matters for development teams connecting agents to issue trackers, repositories, and local tooling. Dark Reading, June 30, 2026
China-linked group targets critical systems in Southeast Asia
A China-linked threat group targeted Southeast Asian critical systems, according to reporting from Palo Alto Networks. The activity matters to U.S. operators because it reinforces persistent risk to energy, industrial, and regional infrastructure partners. Dark Reading, July 1, 2026
Alleged Scattered Spider member extradited to the U.S.
The Justice Department said alleged Scattered Spider member Peter Stokes was extradited from Finland to face charges tied to cyber intrusion and fraud. Prosecutors linked the group to more than 100 intrusions and major ransom losses. Justice Department, July 1, 2026
KDDI breach exposes credentials across six ISPs
KDDI disclosed a breach affecting up to 14.22 million email credentials across six Japanese ISPs after attackers exploited third-party software. Shared service infrastructure made one compromise a multi-provider credential exposure event. TechRadar, June 29, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
