// daily digest ยท 2026-07-15
Wednesday·15 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

9 stories5 sectors3 sourcesGlobal focus

Executive Summary

Microsoft shipped its largest Patch Tuesday on record โ€” 622 CVEs, including two zero-days under active attack in SharePoint Server and Active Directory Federation Services โ€” with the company attributing the surge to AI-aided vulnerability discovery. CISA urged SharePoint hardening following new exploitation and added four more CVEs to its KEV catalog. SAP patched a critical CVSS 9.9 NetWeaver ABAP flaw. The US unsealed an indictment against alleged operators of a Russian bulletproof hosting service, while Finland issued a wanted notice for the hacker behind the Vastaamo psychotherapy data breach. The Record reported that hackers stole customer data from German retailer Lidl via an external service provider compromise.

3
IT / Technology
2
Government
1
Healthcare
1
Defence
2
General / Cross-Sector

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
3
Russia
2
Finland
1
Germany
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 2

4 countries ยท 9 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 6/9 stories located directly from text (67%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 6/9 stories located directly from text (67%). Low-confidence (region-bucket only, check): United States.

IT / Technology 3 stories

1

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft shipped its largest Patch Tuesday on record โ€” 622 CVEs, more than triple June's previous high. Two zero-days are under active exploitation: CVE-2026-56164 (SharePoint Server, privilege escalation) and CVE-2026-56155 (Active Directory Federation Services, privilege escalation). A third zero-day, CVE-2026-50661, is a BitLocker security feature bypass publicly disclosed but not yet exploited. Microsoft attributed the record volume to AI-aided vulnerability discovery.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-14
2

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

SAP released July 2026 security updates including a critical out-of-bounds write flaw in SAP NetWeaver Application Server ABAP (CVE-2026-44747, CVSS 9.9) that could allow an authenticated attacker to cause memory corruption leading to unauthorized data access, modification, or system unavailability. Two other critical flaws were also patched including an HTTP request/response smuggling issue in SAP Approuter (CVE-2026-27690, CVSS 9.1).

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-14
3

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

Manifold Security disclosed a vulnerability in Claude for Chrome (v1.0.80) that allows any browser extension with script access to claude.ai to trigger automated tasks reading Gmail, Google Docs, and Calendar data. The flaw persists eight versions after Anthropic's response to the ClaudeBleed vulnerability. The "Act without asking" mode is most at risk; the "ask before acting" mode still requires user approval.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-14

Government 2 stories

1

US Unseals Indictment Against Alleged Operators of Russian Bulletproof Hosting Service

The US Department of Justice unsealed an indictment charging the alleged operators of a Russian bulletproof hosting service that enabled cybercriminal operations, including ransomware attacks and data breaches, by providing infrastructure resistant to law enforcement takedown.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-14
2

CISA Urges SharePoint Hardening After New Exploitations

CISA issued an alert urging organizations to harden Microsoft SharePoint deployments following newly observed exploitation activity. The advisory comes alongside the addition of CVE-2026-56164 to the Known Exploited Vulnerabilities catalog.

CISAโ— Tier 1/4 โ€” Very High2026-07-14

Healthcare 1 story

1

Finland Issues Wanted Notice for Hacker Behind Massive Psychotherapy Data Breach

Finland issued an international wanted notice for the hacker responsible for the Vastaamo psychotherapy data breach โ€” one of the most notorious data breaches in Nordic history, where the records of tens of thousands of psychotherapy patients were stolen and ransomed. The case has been a major driver of stricter data breach notification and cybersecurity legislation in Finland and the EU.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-14

Defence 1 story

1

NATO Logistics, Ukrainian Troops Are Top Subjects of Russian Camera Hacks, Advisory Says

A joint advisory warned that Russian threat actors are conducting systematic camera hacks targeting NATO logistics infrastructure and Ukrainian troops, using compromised security cameras and IoT devices to gather intelligence on military movements and supply chains.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-14

General / Cross-Sector 2 stories

1

Hackers Steal Lidl Customer Data From External Service Provider

German supermarket chain Lidl confirmed that customer data was stolen after hackers compromised an external service provider. The breach highlights the ongoing supply-chain risk that retailers face from third-party vendor access to customer data.

The Record from Recorded Future Newsโ— Tier 2/4 โ€” High2026-07-14
2

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA added four new CVEs to its Known Exploited Vulnerabilities catalog, including flaws affecting widely deployed enterprise software. Federal agencies are required to remediate within specified timelines.

CISAโ— Tier 1/4 โ€” Very High2026-07-14

Analytics

Sector distribution

IT / Technology
3
Government
2
Healthcare
1
Defence
1
General / Cross-Sector
2

Source breakdown

The Record from Recorded Future News
4
The Hacker News
3
CISA
2
9stories
IT / Technology 3
Government 2
Healthcare 1
Defence 1
General / Cross-Sector 2

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified