Today’s Briefing
Microsoft's July 2026 Patch Tuesday addresses 622 vulnerabilities, including two zero-days exploited in the wild: CVE-2026-56155, an Active Directory Federation Services privilege escalation flaw, and CVE-2026-56164, a missing authentication vulnerability in SharePoint Server. CISA has added four vulnerabilities to the KEV catalogue today, including CVE-2026-56155 and three SharePoint flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) under active exploitation, and two SonicWall SMA1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410). Separately, reporting confirms a ransomware negotiator working with BlackCat secretly assisted the gang in extorting victims rather than representing their interests.
Top Stories
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.
Get the brief at 07:00, every weekday.
The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.