Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Microsoft shipped its largest Patch Tuesday on record โ 622 CVEs, including two zero-days under active attack in SharePoint Server and Active Directory Federation Services โ with the company attributing the surge to AI-aided vulnerability discovery. CISA urged SharePoint hardening following new exploitation and added four more CVEs to its KEV catalog. SAP patched a critical CVSS 9.9 NetWeaver ABAP flaw. The US unsealed an indictment against alleged operators of a Russian bulletproof hosting service, while Finland issued a wanted notice for the hacker behind the Vastaamo psychotherapy data breach. The Record reported that hackers stole customer data from German retailer Lidl via an external service provider compromise.
Incident Map
IT / Technology 3 stories
Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
Microsoft shipped its largest Patch Tuesday on record โ 622 CVEs, more than triple June's previous high. Two zero-days are under active exploitation: CVE-2026-56164 (SharePoint Server, privilege escalation) and CVE-2026-56155 (Active Directory Federation Services, privilege escalation). A third zero-day, CVE-2026-50661, is a BitLocker security feature bypass publicly disclosed but not yet exploited. Microsoft attributed the record volume to AI-aided vulnerability discovery.
SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data
SAP released July 2026 security updates including a critical out-of-bounds write flaw in SAP NetWeaver Application Server ABAP (CVE-2026-44747, CVSS 9.9) that could allow an authenticated attacker to cause memory corruption leading to unauthorized data access, modification, or system unavailability. Two other critical flaws were also patched including an HTTP request/response smuggling issue in SAP Approuter (CVE-2026-27690, CVSS 9.1).
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Manifold Security disclosed a vulnerability in Claude for Chrome (v1.0.80) that allows any browser extension with script access to claude.ai to trigger automated tasks reading Gmail, Google Docs, and Calendar data. The flaw persists eight versions after Anthropic's response to the ClaudeBleed vulnerability. The "Act without asking" mode is most at risk; the "ask before acting" mode still requires user approval.
Government 2 stories
US Unseals Indictment Against Alleged Operators of Russian Bulletproof Hosting Service
The US Department of Justice unsealed an indictment charging the alleged operators of a Russian bulletproof hosting service that enabled cybercriminal operations, including ransomware attacks and data breaches, by providing infrastructure resistant to law enforcement takedown.
CISA Urges SharePoint Hardening After New Exploitations
CISA issued an alert urging organizations to harden Microsoft SharePoint deployments following newly observed exploitation activity. The advisory comes alongside the addition of CVE-2026-56164 to the Known Exploited Vulnerabilities catalog.
Healthcare 1 story
Finland Issues Wanted Notice for Hacker Behind Massive Psychotherapy Data Breach
Finland issued an international wanted notice for the hacker responsible for the Vastaamo psychotherapy data breach โ one of the most notorious data breaches in Nordic history, where the records of tens of thousands of psychotherapy patients were stolen and ransomed. The case has been a major driver of stricter data breach notification and cybersecurity legislation in Finland and the EU.
Defence 1 story
NATO Logistics, Ukrainian Troops Are Top Subjects of Russian Camera Hacks, Advisory Says
A joint advisory warned that Russian threat actors are conducting systematic camera hacks targeting NATO logistics infrastructure and Ukrainian troops, using compromised security cameras and IoT devices to gather intelligence on military movements and supply chains.
General / Cross-Sector 2 stories
Hackers Steal Lidl Customer Data From External Service Provider
German supermarket chain Lidl confirmed that customer data was stolen after hackers compromised an external service provider. The breach highlights the ongoing supply-chain risk that retailers face from third-party vendor access to customer data.
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA added four new CVEs to its Known Exploited Vulnerabilities catalog, including flaws affecting widely deployed enterprise software. Federal agencies are required to remediate within specified timelines.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |