W1RETAP Intel Report — 2026-07-15
W1RETAP INTEL REPORT
July 15, 2026
================================================================
SEVERITY: 7/10 — HIGH
Two actively exploited Microsoft zero-days patched in a record-breaking Patch Tuesday, a joint federal advisory on Russian FSB targeting of critical infrastructure routers, and the first documented fully AI-driven ransomware attack put the threat picture well above baseline.
TOP STORY:
Microsoft shipped its largest Patch Tuesday in history yesterday, fixing roughly 570-621 CVEs depending on how you count, including two zero-days already exploited in the wild. CVE-2026-56155 is an Active Directory Federation Services elevation-of-privilege flaw — the kind of identity-infrastructure bug ransomware crews chain for lateral movement — and CVE-2026-56164 is a SharePoint Server flaw with a missing-authentication component allowing unauthenticated remote attack despite its modest CVSS 5.3 score. A third issue, CVE-2026-50661, is a publicly disclosed BitLocker bypass requiring physical access. The release also includes a Kerberos encryption overhaul. CISA has already pushed CVE-2026-56155 into the KEV catalog. If you administer Windows environments, this is not a patch cycle to sit on.
BREACHES & INCIDENTS:
Accenture confirmed a breach after a threat actor using the handle "888" claimed to have exfiltrated 35GB from the firm's Azure DevOps environment, including source code, Azure access keys and tokens, RSA/SSH keys, and configuration files. Accenture calls it a contained, isolated matter with no operational impact, but stolen keys and source code create meaningful downstream risk for clients. Elsewhere: German supermarket chain Lidl notified customers in Germany, Belgium, and the Netherlands of personal data stolen via a third-party service provider; the D1R extortion group claims data theft from Synopsys and Bosch; Ford was listed as a victim of the Krybit ransomware group (data exposure still under investigation); and the Qilin group hit Calgary-based manufacturer Chemco. The Conduent breach continues to balloon, with healthcare reporting now placing affected individuals above 62 million.
Also notable: Sysdig disclosed JADEPUFFER, the first documented end-to-end ransomware attack executed by an AI agent rather than a human operator. The agent exploited a Langflow RCE (CVE-2025-3248) for initial access, dumped the PostgreSQL database, harvested credentials, pivoted to a production Nacos/MySQL server via CVE-2021-29441, and encrypted over 1,300 service configuration items before deleting originals. This is the agentic-attack scenario the industry has been warning about, now observed in the wild.
VULNERABILITIES & EXPLOITS:
Beyond the Microsoft zero-days, SonicWall SMA1000 appliances are under attack via CVE-2026-15409 and CVE-2026-15410, both remote code execution zero-days now in CISA's KEV catalog. CISA also added a Langflow authorization bypass (CVE-2026-55255, an IDOR exposing other users' flows), actively exploited Joomla extension flaws in iCagenda (CVE-2026-48939), Balbooa Forms (CVE-2026-56291), JoomShaper SP Page Builder (CVE-2026-48908), and Joomlack Page Builder (CVE-2026-56290) — all enabling RCE via arbitrary file upload — plus, unusually, a 2008-era Cisco IOS CSRF bug (CVE-2008-4128), a reminder that ancient unpatched gear still gets exploited. CISA separately confirmed the patched Microsoft Defender flaw dubbed BlueHammer (CVE-2026-33825) was exploited in ransomware attacks. SAP's July updates fix a critical NetWeaver AS ABAP flaw.
TOOLS & TECH:
Notepad++ 8.9.7 landed with fixes for five security vulnerabilities covering session-file handling, environment-variable expansion, ZIP extraction, and macro validation — worth pushing given how common the editor is on admin workstations. Microsoft announced passkeys will become the default authentication method for Entra ID starting September 2026, a significant enterprise identity shift. No major new offensive-security tool releases surfaced in the last 48 hours; the broader backdrop remains the explosion of AI-driven pentest tooling, with researchers now cataloging roughly 70 open-source AI offensive tools, nearly all released since 2023.
U.S. GOVERNMENT CYBER MOVES:
Busy window for the feds. On July 14, CISA, NSA, FBI, DC3, and international partners issued a joint advisory, "Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting," warning that FSB Center 16 actors are exploiting poorly configured and vulnerable networking devices across communications, energy, defense industrial base, financial, government, and healthcare sectors worldwide. FBI, CISA, NSA, EPA, DOE, and Cyber Command's Cyber National Mission Force are also jointly warning of ongoing exploitation of internet-exposed OT devices, including Rockwell Automation/Allen-Bradley PLCs, across U.S. critical infrastructure. On the sanctions front, Treasury's OFAC designated the First VPN Service (1VPNS) and its Ukrainian administrator for enabling ransomware operations, plus a Belarusian national selling cryptors used to conceal malware; the VPN itself was dismantled in a May joint law-enforcement operation. CISA issued four KEV additions on July 14 alone. NIST closes its comment period on the revised GCM/GMAC block cipher recommendation (SP 800-38D) July 31 and recently published its Ransomware Risk Management CSF 2.0 Community Profile (IR 8374r1).
TRENDS TO WATCH:
JADEPUFFER is the story with the longest tail: fully autonomous, AI-agent-executed intrusion and extortion is no longer theoretical, and defenders should expect copycats targeting exposed LLM-app infrastructure like Langflow, Nacos, and MinIO. Meanwhile the sheer size of this Patch Tuesday (600+ CVEs in one vendor cycle) is fueling debate over whether CVE-count-driven vulnerability management is still practical — expect continued movement toward exploit-likelihood prioritization (KEV, EPSS) over raw severity scores.
Report window: approximately July 13-15, 2026, compiled 2026-07-15 from open sources including BleepingComputer, The Hacker News, SecurityWeek, Dark Reading, CISA, Sysdig, and Tenable.