The Lyceum: Cyber Intelligence Daily — Jul 15, 2026
Photo: lyceumnews.com
Wednesday, July 15, 2026
The Big Picture
Two things collided this cycle: the largest Patch Tuesday in Microsoft's history — 622 CVEs, two of them already being exploited — and a SonicWall zero-day disclosure with a federal patch deadline of Thursday, July 17. Underneath the volume, the real story is that patch windows are now measured in hours. SharePoint has hardened into a full campaign with a named backdoor, Russia damaged Ukraine's Ministry of Justice registries overnight, and AI is quietly shrinking the gap between a bug being found and a bug being weaponized. This is a genuinely heavy day — triage sequencing matters more than usual.
What Just Dropped
- CVE-2026-56164 — Microsoft SharePoint Server: actively exploited, added to CISA KEV due July 17. Missing-authentication flaw letting an unauthorized attacker escalate privileges over the network.
- CVE-2026-56155 — Microsoft AD FS: actively exploited, in KEV due July 28. Access-control weakness in the box that signs your organization's logins.
- CVE-2026-15409 — SonicWall SMA1000: actively exploited, in KEV due July 17. Unauthenticated server-side request forgery — the appliance can be tricked into reaching internal systems it should never touch.
- CVE-2026-15410 — SonicWall SMA1000: actively exploited, in KEV due July 17. Post-authentication OS command injection in the management console.
- CVE-2008-4128 — Cisco IOS 12.4: actively exploited, in KEV. An eighteen-year-old CSRF flaw, now tied to Russia's FSB-linked router campaign (Berzerk Bear).
- CVE-2026-48334 / 48336 / 48337 — Adobe Illustrator: patched, no known exploitation. Open-a-file, get-owned code execution bugs.
Today's Stories
Microsoft's Record 622-CVE Patch Tuesday Has Two Zero-Days You Need to Fix Today
If your organization runs on-premises SharePoint or Active Directory Federation Services — and most mid-to-large ones do — you had a problem before the patches even dropped.
Microsoft shipped 622 CVEs in its July 2026 Patch Tuesday, its largest release on record, and two were already being exploited: CVE-2026-56164 (SharePoint Server) and CVE-2026-56155 (AD FS). Both are privilege-escalation bugs in systems that matter more than their scores suggest — the company document store, and the box that signs its logins. The SharePoint flaw lets an unauthenticated attacker escalate privileges remotely, no credentials required. (Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026)
The tell is in the attribution: Microsoft credited the SharePoint discovery to Mandiant's incident responders and Google's FLARE team. When the people who find a bug are the people cleaning up after breaches, it was already weaponized. Compromise AD FS and you can forge the login tokens the rest of your organization trusts — the golden-SAML pattern from past campaigns.
What to watch: if these two CVEs start appearing in public breach write-ups, identity infrastructure has become the target, and token-forgery abuse follows. Patch SharePoint and AD FS first — don't let the moderate-severity label on CVE-2026-56164 talk you into deprioritizing an unauthenticated network flaw. Microsoft also warned this month that AI is compressing the disclosure-to-exploitation gap to hours; record volume is now hiding the dangerous bugs in plain sight.
SonicWall SMA1000 Zero-Days: Federal Deadline Is Thursday — Patch or Pull the Plug
SonicWall's SMA1000 appliances are the remote-access gateways that let employees connect securely from anywhere. Right now, two of them have holes attackers are walking through. (ALERT - SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch no)
CVE-2026-15409 is a CVSS 10.0 server-side request forgery flaw in the Appliance Work Place interface — tricking a trusted box into making requests on the attacker's behalf, reaching internal systems it was never meant to touch. CVE-2026-15410 is a CVSS 7.2 post-authentication code-injection bug that lets an authenticated admin run arbitrary OS commands. Both are in CISA's Known Exploited Vulnerabilities catalog, confirmed active in the wild.
CISA added both on the same day, raising the possibility they're being chained — no public exploit chain is confirmed, but SSRF plus code injection on a VPN gateway is the nightmare scenario. Federal agencies have until July 17, 2026 to patch or discontinue the product under Binding Operational Directive 22-01. That deadline is still approaching. (ALERT - SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch no)
What failure looks like: if these CVEs surface in ransomware intrusion reports, VPN gateways have fully re-entered the "primary initial access vector" category. Affected models are the SMA6210, SMA7210, and SMA8200v — and SonicWall is explicit that patching alone isn't enough. Review logs for indicators of compromise, because a patched box that was already breached is still a breached box.
CISA Names a Third SharePoint CVE — This Is Now a Campaign
The SharePoint story stopped being a single unpatched flaw and became a coordinated operation. CISA confirmed active exploitation across three CVEs simultaneously — CVE-2026-32201, CVE-2026-45659, and the newly-added CVE-2026-56164 — affecting all supported on-premises versions. (CISA Names a Third SharePoint CVE and Issues a Hardening Advisory — This Is Now )
The operationally significant detail: attackers are establishing remote code execution, then stealing IIS machine keys and running deserialization attacks for persistence. Once an attacker holds those keys, they can forge ASP.NET ViewState tokens and maintain authenticated-looking access that survives a patch cycle. CISA also flagged a Microsoft Defender signature — Backdoor:MSIL/LeakFang.A!dha — as a post-exploitation alert. A named backdoor in a CISA advisory means someone has forensic access to a confirmed victim.
Prior activity in this infrastructure class involved Chinese state actors Linen Typhoon, Violet Typhoon, and Storm-2603, the last of which was observed deploying ransomware through the SharePoint path. Attribution for the current wave isn't confirmed, but the TTP overlap is notable — and this landed the same day SharePoint Server 2016 and 2019 reached end of support. If you run on-premises SharePoint and haven't hunted for LeakFang indicators or rotated IIS machine keys, treat this as an active incident response question, not a patch ticket. (CISA Names a Third SharePoint CVE and Issues a Hardening Advisory — This Is Now )
Russia Hits Ukraine's Ministry of Justice — State Registries Taken Offline
Ukrainian-language feeds — confirmed by Ukraine's State Service of Special Communications — report that Russia damaged the Ministry of Justice overnight, taking state registries offline. Interfax-Ukraine reports Deputy Prime Minister Olha Stefanishyna confirmed the attack and attributed it to Russian hackers. (The U.S. Just Indicted Alleged Russian Bulletproof Hosting Operators Behind $62 )
The Ministry manages roughly 60 state databases: births, deaths, property ownership, business registrations. When those go dark, civil society grinds to a halt in ways that don't make headlines but affect millions trying to register a business or transfer property. "Cyberspace is just as much a battlefield as any other domain," said Oleksandr Potii, head of Ukraine's cyber agency. (Ukraine’s state registers hit with one of Russia’s largest cyberattacks, officia)
No specific threat group has been attributed to this new incident, and no technical indicators are public yet. Watch for CERT-UA to publish a UAC designation in the next 24–48 hours — that will be the first signal of whether this is GRU, FSB, or a proxy. Note the timing: it arrived on Ukrainian Statehood Day, which the same cyber agency was publicly celebrating hours before.
⚡ What Most People Missed
Russia's FSB router campaign just got a global amplifier: Nineteen agencies across 13 countries — including NSA, CISA, and FBI — issued a joint advisory that FSB Center 16 (Berzerk Bear) is systematically compromising poorly configured routers fronting energy and communications networks. The primary technique isn't a zero-day; it's default SNMP community strings and Cisco Smart Install left enabled. Router hardening just became table stakes.
The ransomware negotiator was working for the ransomware gang: The DOJ sentenced Florida's Angelo Martino to 70 months for conspiring with BlackCat/ALPHV to extort the very victims he was hired to help. Vet your incident responders the way you'd vet a CFO — they see everything during a crisis. [Source: Xakep.ru — Russian, surfaced ahead of the English DOJ release]
U.S. sanctions First VPN and a cryptor seller: Treasury's OFAC cut off the anonymization plumbing behind billions in ransomware losses. The absurd coda: when Treasury published the sanctioned gang's Telegram channel, someone panicked and briefly globally blocked t.me, breaking Telegram URLs worldwide before quietly reverting a day later.
Apple's "Hide My Email" is reportedly leaking real addresses: A single researcher's writeup — Tier 3, unverified by Apple — claims iCloud+'s privacy relay is exposing users' actual emails. If replicated, it defeats the compartmentalization that journalists, researchers, and executives rely on to dodge spear-phishing.
📅 What to Watch
- If CERT-UA assigns a UAC designation to the Ministry of Justice attack, it tells you which Russian service is prioritizing registry disruption right now — and whether this is escalation or routine.
- If SonicWall's SMA CVEs appear in ransomware intrusion reports, VPN gateways have fully returned to primary-initial-access status, and every unpatched appliance is a countdown.
- If the FSB router advisory's targets show up as named C2 operators in threat feeds, the campaign shifts from advisory to active infrastructure war.
- If Apple revokes or patches Hide My Email quickly, that's the confirmation the leak is real and severe — silence would suggest the opposite.
- If exploit kits bundle the Firefox 152 critical bugs (public PoC already exists), browser patch timing stops being hygiene and becomes frontline defense.
The Closer
Somewhere a SonicWall box is dutifully phoning internal servers on a stranger's orders, a Florida negotiator is trading a consulting rate for a prison cell, and a U.S. Treasury press release accidentally took down half the world's Telegram links. The plumbers, it turns out, are more dangerous than the burglars — and this week we sanctioned the plumbing, indicted the landlords, and jailed the guy we hired to talk the burglars down.
Patch fast; trust slowly.
Forward this to the one person on your team who still thinks "it's just a VPN appliance."
⚡ EDGE Signals
The following signals appeared in the adversarial edge sweep but were not carried forward in the primary synthesis:
- ### Microsoft’s July patch drop quietly loaded SharePoint with two new critical RCEs
- Must-touch item, and worth watching even without a same-day government bulletin in hand: Fortinet’s PSIRT index currently lists FG-IR-25-1052, CVE-2026-22153, as a high-severity authentication bypass in FortiOS’s
fnbamdcomponent, with affected FortiOS 7.6.x builds and a July 4, 2026 advisory update.