W1RETAP Intel Report — 2026-07-16

W1RETAP INTEL REPORT
July 16, 2026
================================================================

SEVERITY: 7/10 HIGH
Justification: Microsoft's largest Patch Tuesday in history landed this week with two zero-days under active exploitation, CISA issued an emergency SharePoint hardening alert amid confirmed in-the-wild attacks, and a fresh Windows zero-day PoC dropped publicly hours after patches shipped.

TOP STORY:
Microsoft's July 2026 Patch Tuesday is the largest single-month security release in the company's history. Reported counts vary by outlet, from roughly 570 to 622 CVEs, but all sources agree on the headline items: two flaws already exploited in the wild. CVE-2026-56155, an elevation of privilege bug in Active Directory Federation Services (CVSS 7.8), and CVE-2026-56164, a SharePoint Server elevation of privilege flaw rated only CVSS 5.3 but carrying a missing-authentication weakness that permits unauthenticated remote attack with no user interaction. AD FS is identity infrastructure, meaning attackers use it to move laterally and escalate, a pattern seen repeatedly in ransomware intrusions. Compounding the chaos, a researcher publicly dropped a proof-of-concept for a new, unpatched Windows zero-day just hours after the updates shipped. Patch now, and assume on-prem SharePoint is being probed.

BREACHES AND INCIDENTS:
TriWest Healthcare Alliance, the TRICARE West Region contractor covering roughly four million military beneficiaries, notified 11,844 people that an unauthorized party accessed and downloaded protected health information back in April, including names, DoD Benefits Numbers, and ZIP codes, with a handful of cases involving SSNs and dates of birth. Notification letters lagged the incident by about two and a half months. Elsewhere, the Unsafe ransomware group claims a third-party breach of Deutsche Bank and has listed the bank on its leak site (unconfirmed by independent forensics). Nintendo of America confirmed employee data exposure via a breach of third-party service TinyPulse, with a 2 million dollar ransom demand. Kubota North America disclosed attackers sat in its network for over a month. Qilin claimed Calgary manufacturer Chemco, and Ford appeared on a leak forum courtesy of the Krybit gang. On the win column, police in Spain disrupted a cyber fraud ring tied to roughly 140 million euros in losses. Also notable: an AI agent dubbed JADEPUFFER reportedly executed a ransomware attack end to end by exploiting a Langflow vulnerability, stealing credentials, and encrypting a database.

VULNERABILITIES AND EXPLOITS:
Beyond the two exploited Microsoft zero-days above, the July update also fixes CVE-2026-55040, a critical SharePoint authentication bypass (CVSS 9.1) allowing a remote unauthenticated attacker to operate as a site user or admin. CISA reports active exploitation of a chain of SharePoint flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) used for RCE and post-exploitation moves like stealing IIS machine keys for persistence. SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 are exploitable for remote code execution. Mozilla patched two critical Firefox flaws (CVE-2026-15718, CVE-2026-15719) with exploit code already public. Progress Software confirmed a high-severity zero-day forced last week's emergency shutdown of ShareFile Storage Zone Controllers and has now shipped fixes. CISA's KEV catalog additions this month also include the Langflow authorization bypass (CVE-2026-55255) and several Joomla ecosystem flaws under active exploitation.

TOOLS AND TECH:
Kali Linux 2026.1 dropped July 14 with a kernel bump to 6.18, 183 package updates, a BackTrack nostalgia mode, and eight new tools: AdaptixC2 (extensible post-exploitation and adversary emulation framework), Atomic-Operator (runs Atomic Red Team tests cross-platform), Fluxion (wireless attack simulation and social engineering auditing), GEF (modern GDB debugging), MetasploitMCP (an MCP server exposing Metasploit to AI agents, worth a look given where tooling is headed), SSTImap (automated server-side template injection detection), and WPProbe (fast WordPress plugin enumeration). Defensive side saw releases including Codenotary AgentMon 3 for AI agent security monitoring.

U.S. GOVERNMENT CYBER MOVES:
CISA issued an alert July 14 urging immediate SharePoint hardening in response to active exploitation, and added four exploited vulnerabilities to the KEV catalog the same day (SonicWall SMA1000, SharePoint, and AD FS flaws) with federal remediation deadlines of July 17 and July 28. Earlier KEV additions this month (July 1, 7, and 10) covered Langflow and multiple Joomla component flaws. In the policy background, agencies continue implementing the June post-quantum cryptography executive order, with NIST, NSA, and CISA jointly tasked with ongoing PQC migration guidance, and NSPM-12 recently restructured governance of National Security Systems with NSA as National Manager. No major new NSA, FBI, or Cyber Command operational announcements surfaced in the last 24 to 48 hours.

TRENDS TO WATCH:
AI is now visibly on both sides of the fight: AI-driven bug hunting is credited with fueling the record CVE volume in this month's Patch Tuesday, while the JADEPUFFER incident marks one of the first reported cases of an autonomous AI agent executing a full ransomware chain. Separately, new analysis finds identity-based attacks have overtaken software exploits as the leading initial cause of ransomware incidents, which reinforces why the AD FS zero-day matters so much. Expect identity infrastructure and AI-agent tooling (note MetasploitMCP shipping in Kali) to dominate offensive research this year.

================================================================
Compiled from open sources covering approximately July 14-16, 2026. Freshness window: last 48 hours.

Read more