Cyber Roundup — Week of July 13

Microsoft's 622-CVE Patch Tuesday hid an exploited SharePoint zero-day. EY lost client tax data for 15 days undetected. WordPress pre-auth RCE hits 500M sites.

Here are the five main stories you missed last week.

1. Microsoft: A record 622-CVE Patch Tuesday buried an actively exploited SharePoint zero-day with a misleading CVSS score

The headline: Microsoft shipped its largest Patch Tuesday in company history on July 14, fixing 622 CVEs across Windows, Office, Azure, SharePoint, Exchange, SQL Server, and development tools. Two zero-days are confirmed under active exploitation: CVE-2026-56164, a missing-authentication privilege escalation in on-premises SharePoint Server discovered by Mandiant and Google FLARE incident responders during live attacks, and CVE-2026-56155, an Active Directory Federation Services elevation of privilege discovered by Microsoft’s own DART incident response unit. CISA added CVE-2026-56164 to its Known Exploited Vulnerabilities catalog on July 14 with a federal remediation deadline of July 17. Microsoft assigned the SharePoint flaw a CVSS score of 5.3. The National Vulnerability Database independently scored it 9.8.

What we’re actually watching: CVE-2026-56164 is the story inside the story. An unauthenticated attacker can escalate privileges on SharePoint Server over the network with no credentials and no user interaction, and Microsoft rated it Moderate. The NVD rated it Critical. CISA added it to KEV the day it shipped. The disconnect between vendor score and operational reality is not new, but the scale here is worth naming: 622 CVEs create noise that security teams must cut through to find the flaw that is already being weaponized. The CVSS score nearly buried it.

The timing compounds the exposure. SharePoint Server 2016 and 2019 reached end-of-extended-support on July 14, 2026, the same day the patch shipped. Organizations running those versions received their last official security update and a confirmed zero-day in the same release. Those that do not apply this patch have no further update path. CISA’s advisory notes that attackers are chaining CVE-2026-56164 with older SharePoint weaknesses to steal IIS machine keys, establish persistence, and deploy malware, the same mechanical fingerprint as the ToolShell campaign that swept through finance, healthcare, government, and energy sectors in 2025.

The record volume itself signals something structural. Microsoft attributed part of the increase to MDASH, its multi-model agentic scanning harness that uses AI to surface vulnerabilities faster across the Windows codebase. When AI-powered research accelerates vulnerability discovery at Microsoft, it accelerates it everywhere. CybelAngel has tracked SharePoint as a persistent exploitation target throughout 2026, with Storm-2603 and multiple nation-state actors returning to the same platform repeatedly because unpatched on-premises deployments remain common across enterprise environments.

The CISO question: For every on-premises SharePoint Server deployment in your environment, have you applied the July 14 patch, enabled AMSI in Full Mode as an immediate mitigation, and confirmed that SharePoint Server 2016 or 2019 instances have a migration path now that extended support has ended?

2. EY: Attackers spent 15 days inside a third-party IT helpdesk platform downloading client tax files before anyone noticed

The headline: Ernst and Young began notifying affected clients on July 13 that an unauthorized third party accessed a vendor-managed IT service management platform used by EY’s tax practice between March 28 and April 12, 2026. EY detected anomalous activity on April 23, meaning attackers operated undetected for approximately 15 days before the breach was identified. The platform was used by EY’s IT personnel to support teams performing tax-related client work. Support tickets submitted through the platform routinely included attachments containing sensitive client tax documents. The exfiltrated data may include Social Security numbers, financial account codes, credit and debit account information, and personal information tied to individuals’ investment holdings. EY filed breach notifications with the California Attorney General on July 15 and Vermont regulators on July 16. Class action investigations are underway.

What we’re actually watching: EY’s support ticketing software became a document repository for sensitive client tax files because that is how enterprise IT support actually works: employees attach the relevant files to the ticket so the IT team can help them. Nobody audited what a breach of that platform would expose. The attacker did not need to compromise EY’s core systems. They compromised the helpdesk.

This is EY’s third significant third-party data security incident in less than three years. In May 2023, the Cl0p ransomware gang exploited a zero-day in Progress Software’s MOVEit Transfer tool, which EY used for data file transfers. The July 2026 incident follows the same structural pattern: a third-party platform that accumulated sensitive data without adequate protection, accessed during a window that lasted long enough to extract significant volume before detection. The 15-day detection gap is not unusual. It is the baseline in enterprise environments where third-party platforms receive less security monitoring than core systems.

The Big Four breach pattern matters beyond EY. Professional services firms, audit houses, and tax advisors sit at the intersection of their clients’ most sensitive financial data and their most trusted vendor relationships. A breach at the IT support layer of one Big Four firm exposes data from dozens or hundreds of enterprise clients simultaneously. CybelAngel’s investigation of the Accenture data breach documents how the same professional services supply chain attack pattern creates downstream exposure across the entire client ecosystem, not just the primary vendor.

3. Scattered Spider: Two members sentenced to five and a half years each in the UK’s largest cybercrime prosecution.

The headline: A UK court sentenced Thalha Jubair, 20, and Owen Flowers, 18, to five years and six months each on July 16 for Scattered Spider’s 2024 attack on Transport for London, which disabled 148 systems, forced 27,000 employees to reset passwords in person, and cost TfL £29 million. The prosecution is the largest cybercrime case in UK legal history, brought under Section 3ZA of the Computer Misuse Act. The NCA stated the action effectively halted the group’s criminal activity. A separate threat cluster operating under the D1R alias claimed data theft from Synopsys and Bosch this week, threatening to leak data unless ransoms are paid.

What we’re actually watching: The UK sentences are the second significant Scattered Spider prosecution in 2026, following US convictions in May. The NCA states the action against Jubair and Flowers effectively halted the group’s criminal activity. Whether the D1R alias activity this week represents surviving members, copycat actors, or a separate group using the Scattered Spider brand is not yet confirmed. What is confirmed is that the tradecraft, the social engineering techniques, and the targeting profile that made Scattered Spider effective did not disappear with the arrests.

Scattered Spider’s operational continuity despite prosecutions reflects the group’s recruitment model. New members are brought in through English-language cybercrime communities where social engineering skills are the primary qualification, not technical expertise. The group’s tradecraft, including SIM swapping, helpdesk social engineering, and MFA fatigue attacks, is documented, shared, and reproducible by any new recruit regardless of whether the original members are imprisoned.

The D1R claims against Synopsys and Bosch this week use the same techniques, target profile, and extortion model as prior Scattered Spider campaigns. Whether this represents surviving members, associates, or a separate group borrowing the brand has not been confirmed. What is clear is that the social engineering tradecraft Scattered Spider pioneered, helpdesk impersonation, SIM swapping, MFA fatigue attacks — is now widely documented and reproducible. Prosecution removes individual actors. It does not remove the playbook.

The CISO question: Scattered Spider’s primary initial access vectors are helpdesk social engineering and SIM swapping, not technical exploits. Does your organization’s security training and helpdesk verification process specifically address requests to reset MFA, transfer phone numbers, or grant remote access to callers who cannot complete standard verification?

4. China: State-linked actors weaponized Claude Code and DeepSeek to attack government networks

The headline: Hunt.io researchers published findings this week confirming that suspected China-linked operators actively used Claude Code and DeepSeek-v4-pro as working components of an intrusion campaign targeting government entities in Afghanistan, Thailand, and Taiwan, as well as financial services organizations. Claude Code served as the execution engine handling agentic tool use and bash commands, while DeepSeek-v4-pro handled offensive reasoning and script generation. In a separate campaign, a China-aligned threat cluster tracked as UNK_MassTraction exploited Roundcube webmail vulnerabilities (CVE-2024-42009 and CVE-2025-49113) to infiltrate US and Canadian university departments conducting physics and defense engineering research, establishing persistent access via webshells and backdoors.

What we’re actually watching: Claude Code and DeepSeek being confirmed as active attack tools used by state-sponsored actors is a different category of concern from theoretical AI attack research. The technique has moved from proof-of-concept to operational deployment in targeted campaigns against government and critical research infrastructure.

The Roundcube exploitation vector is worth specific attention. CVE-2024-42009 was patched in 2024 and CVE-2025-49113 in 2025. Both remain effective against organizations that have not applied those patches, which in government and university environments with constrained IT resources is a significant population. The AI tooling accelerates what happens after initial access: scripting persistence mechanisms, enumerating Active Directory, and automating data staging, tasks that previously required skilled operators working manually.

The split-model workflow documented by Hunt.io is the operationally significant detail. Offensive logic ran through a Chinese domestic LLM (DeepSeek) while leveraging Anthropic’s agentic execution infrastructure (Claude Code). This is not theoretical AI misuse. Researchers found 2,431 files across 80 subdirectories on an exposed server including victim source code, exploit scripts, cloned login pages, and operator logs written in Simplified Chinese. The attack notes document Claude Code version 2.1.165 conducting operations across persistent sessions spanning multiple geographic targeting campaigns.

The CISO question: If AI coding assistants are now confirmed attack tools in state-sponsored campaigns, does your organization’s acceptable use policy for AI development tools account for the risk that the same tools used to build software are being used to automate attacks against the environments those tools can access?

5. WordPress: wp2shell gives any unauthenticated attacker remote code execution on stock WordPress installations

The headline: WordPress shipped emergency patches on July 17 for wp2shell, a pre-authentication remote code execution chain in WordPress Core requiring no plugins, no themes, and no special configuration. The chain combines CVE-2026-63030, a REST API batch-route confusion flaw, with CVE-2026-60137, a SQL injection in WordPress’s core database query class, to achieve remote code execution from an anonymous HTTP request. WordPress 6.9.5 and 7.0.2 contain the fix. WordPress powers approximately 500 million websites globally. Active exploitation had not been confirmed as of July 18, but a public proof-of-concept is circulating and WordPress took the unusual step of force-pushing the update via its auto-update system to all affected sites.

What we’re actually watching: A pre-authentication RCE in WordPress Core with no preconditions is a mass exploitation event waiting to happen. WordPress’s market share means that automated scanning tools will find vulnerable installations faster than most web hosting providers can push patches to shared hosting customers.

The “no plugins required” element changes the risk calculation for every WordPress deployment. Organizations that have hardened their WordPress installations, audited plugins, enforced two-factor authentication, and implemented web application firewall rules are still exposed if they have not patched the core installation. The attack surface is every WordPress site running an unpatched version, regardless of how well everything else is configured.

Web hosting providers face the most acute exposure. Shared hosting environments running WordPress across thousands of customer sites under a single managed update process have a narrow window before automated exploitation tools integrate wp2shell into mass scanning campaigns. The pattern from previous WordPress Core vulnerabilities suggests that weaponization timelines are measured in days from public disclosure, not weeks. Organizations relying on their hosting provider to push the patch should confirm that timeline explicitly rather than assuming it has already happened.

The CISO question: For every WordPress installation in your environment, including those managed by third-party agencies, developers, or hosting providers, can you confirm that the wp2shell patch has been applied, and do you have a process for verifying patch status across managed WordPress deployments that are outside your direct control?

The pattern across all five stories

Every story this week exploited the gap between what organizations monitor and what attackers can reach.

Microsoft’s misleading CVSS score nearly buried an actively exploited SharePoint zero-day inside a 622-CVE release. EY’s attackers spent 15 days inside a helpdesk platform that nobody was watching closely enough. Scattered Spider’s tradecraft outlived its members’ freedom, with new actors already using the same techniques under a new alias. China-linked operators embedded AI tools that organizations had already approved into live intrusion campaigns across four countries. WordPress’s pre-auth RCE will reach sites that are well-configured everywhere except the core installation that nobody remembered to patch.

CybelAngel monitors your external attack surface, dark web exposure, and third-party risk continuously, finding the gaps attackers find before they use them.

À propos de l'auteur