logo

Critical zero-days in Microsoft Active Directory, SonicWall SMA1000, GitHub malware campaign

ID: 9700f19e-0374-5602-9973-c36a90a8203a

STIX ID: report--9700f19e-0374-5602-9973-c36a90a8203a

Feed Name: defend.network

Threat Score
90/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: defend.network

...
...

Microsoft pushed a record 622 fixes including two zero-days being actively exploited against Active Directory and SharePoint; SonicWall released emergency patches for two actively-exploited SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410). A coordinated supply-chain campaign published nearly 300 fake GitHub repositories to distribute infostealer malware, SAP patched a critical NetWeaver ABAP flaw (CVE-2026-44747, CVSS 9.9), and Spanish police dismantled a €140M BEC/money-laundering ring. Immediate actions recommended are emergency patching, log/audit monitoring, repository/dependency audits, and enforcement of email authentication controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.