Cybersecurity Intelligence Report — 2026-07-15
CRITICAL SECTION
- [16] SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) (HelpNetSecurity) CVE-2026-15410, CVE-2026-15409
<p>SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise. If the outlined indicators of compromise are present on the system, the company advises re-imaging (hardware) or re-deploying (virtual) appliances, changing user and administrator passwords, and resetting TOTP tokens - [10] SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (BleepingComputer) CVE-2026-15410, CVE-2026-15409
SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […] - [10] [RANSOMWARE] dragonforce leaked Intron Technology Holdings (ransomware.live/dragonforce)
Victim: Intron Technology Holdings | Group: dragonforce | Website: www.intron-tech.com | Country: TW | Details: Intron Technology Holdings Limited is a fast-growing automotive electronics solutions provider in China focuses on providing solutions targeting critical automotive electronic components applied in New Energy, Body Control, Safety and Powertrain systems. The Group utilizes its research and developme
CISA KEV SECTION (Known Exploited Vulnerabilities)
| CVE | Vendor/Product | Score | Required Action |
|---|---|---|---|
| CVE-2026-56164 | [CISA KEV] CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability – Microsoft SharePoint Server | 9 | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability – Microsoft SharePoint Server. Required action: Apply mitigations in accordance with vendor instructions, ensurin |
| CVE-2026-56155 | [CISA KEV] CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability – Microsoft Active Directory Federation Services | 6 | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability – Microsoft Active Directory Federation Services. Required action: Apply mitigations in accorda |
| CVE-2026-15409 | [CISA KEV] CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability – SonicWall SMA1000 Appliances | 6 | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability – SonicWall SMA1000 Appliances. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance wi |
| CVE-2026-15410 | [CISA KEV] CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability – SonicWall SMA1000 Appliances | 6 | SonicWall SMA1000 Appliances Code Injection Vulnerability – SonicWall SMA1000 Appliances. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD |
RANSOMWARE VICTIMS (DLS Monitoring)
dragonforce: [RANSOMWARE] dragonforce leaked Intron Technology Holdings, [RANSOMWARE] dragonforce leaked Edison Global Networks Limited, [RANSOMWARE] dragonforce leaked SITAV SpA, [RANSOMWARE] dragonforce leaked Graphic International Centre, [RANSOMWARE] dragonforce leaked Road Ahead Technologies Consultant, [RANSOMWARE] dragonforce leaked Atcom, [RANSOMWARE] dragonforce leaked Midal Cables, [RANSOMWARE] dragonforce leaked Omax Autos, [RANSOMWARE] dragonforce leaked Ifage, [RANSOMWARE] dragonforce leaked asimar.com
chaos: [RANSOMWARE] chaos leaked aphenapharma.com, [RANSOMWARE] chaos leaked sleemanbreweries.ca, [RANSOMWARE] chaos leaked spectrumchemical.com
blacknevas: [RANSOMWARE] blacknevas leaked Arkın Group, [RANSOMWARE] blacknevas leaked L'azurde
incransom: [RANSOMWARE] incransom leaked VantagePoint Management & Autoclear, [RANSOMWARE] incransom leaked Golden Glasko & Associates
securotrop: [RANSOMWARE] securotrop leaked ProDirectional Drilling
shinyhunters: [RANSOMWARE] shinyhunters leaked Abbott owned Exact Sciences Corporation
coinbasecartel: [RANSOMWARE] coinbasecartel leaked Axiom GlobalNEW
arcusmedia: [RANSOMWARE] arcusmedia leaked Perpustam, [RANSOMWARE] arcusmedia leaked gemese.pt, [RANSOMWARE] arcusmedia leaked Distribox, [RANSOMWARE] arcusmedia leaked Be Travel, [RANSOMWARE] arcusmedia leaked COREBI(NowVertical), [RANSOMWARE] arcusmedia leaked I-FITNESS
qilin: [RANSOMWARE] qilin leaked THL, [RANSOMWARE] qilin leaked Sedemi
nightspire: [RANSOMWARE] nightspire leaked Cedar Crest College
payoutsking: [RANSOMWARE] payoutsking leaked Casta Diva Group
AiLock: [RANSOMWARE] AiLock leaked WBF Construction
cmdorganization: [RANSOMWARE] cmdorganization leaked Target Energy Solutions
NEWS SECTION
- [8] Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown (BleepingComputer) — Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. […]
- [8] 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer (SecurityWeek) — <p>The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.</p>
<p>The post <a href="https://www.securityweek.com/7-severe-vulnerabilities-patched-in-vmware-avi-load-balancer/">7 Severe Vulnerabilities Patched in VMware Avi Load Balancer</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p> - [8] US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers (SecurityWeek) — <p>Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.</p>
<p>The post <a href="https://www.securityweek.com/us-allies-warn-of-russian-cyberattacks-targeting-critical-infrastructure-routers/">US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p> - [7] SAP warns of critical flaws in NetWeaver and Commerce Cloud (BleepingComputer) — SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. […]
- [7] Adobe Patches Critical ColdFusion Vulnerabilities (SecurityWeek) — <p>The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges.</p>
<p>The post <a href="https://www.securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities/">Adobe Patches Critical ColdFusion Vulnerabilities</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p> - [7] SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud (SecurityWeek) — <p>The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization.</p>
<p>The post <a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/">SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p> - [6] Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days (BleepingComputer) — Today is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. […]
- [6] Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack (TheHackerNews) — Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its Security Update Guide count, more than triple June's previous high of around 200.
Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are
- [6] Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days (SecurityWeek) — <p>Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed.</p>
<p>The post <a href="https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days/">Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p> - [6] New macOS malware steals passwords by posing as Apple’s crash-reporting tool (HelpNetSecurity) — <p>Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under development. By early July, Jamf was seeing in-the-wild detections, indicating it had moved into active use. “Unlike much of the commodity stealer activity on macOS, which is built on AppleScript droppers or thin Objective-C wrapper
- [6] “Context bombs” can frustrate AI-driven attacks, researchers found (HelpNetSecurity) — <p>A new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not to hijack AI agents, but to defend against them. Canaries with context bombs Tracebit offers customers a range of canaries, i.e., decoy resources and credentials that, when targeted by attackers, provide early warning
- [5] Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims (SecurityWeek) — <p>The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. </p>
<p>The post <a href="https://www.securityweek.com/synopsys-finds-no-evidence-of-data-breach-following-bosch-hack-claims/">Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
SUMMARY
Total new items: 84. Critical count: 3. Ransomware groups active: 13. Top CVEs to patch urgently: CVE-2026-15410, CVE-2026-15409, CVE-2026-56164, CVE-2026-56155, CVE-2026-44747.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Companion HTML report: HTML report
Leave a Reply