July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs
56Critical 510Important 3Moderate 0Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were…
56Critical 510Important 3Moderate 0Low Microsoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were…
Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated…
“Is Die Hard a Christmas movie?” At every holiday party, without fail, someone’s going to throw that question your way. And whether you’re willing to…
Acknowledgments: Special thanks to the efforts of Stephanie Fairless for the contributions to this investigation. “The call is coming from inside the house.” Defenders often…
Acknowledgments: Special thanks to Dave Kleinatland, Matt Kiely, Jamin Becker, Bryan Masters, Justin Allen, and Arnelle French for their contributions to this investigation. UPDATE @…
When most people hear the word “disruption,” they think about business growth, new markets, or a competitor making a bold move. Ransomware crews have their…
We hope all of our Canadian readers had a happy Canada Day! As you settle back in from what was hopefully a relaxing day off,…
Beginning late last year, an unknown threat actor took advantage of a service offered by Meta meant to connect businesses who use Facebook or Instagram…
At 5:47 p.m. on a Friday, someone runs PowerShell in your environment. Maybe it’s a tired admin finishing one last task before signing off. But…
AI-augmented tradecraft is changing the threat landscape that defenders have operated in. For years, defenders have relied on identifying the signatures and behaviors of off-the-shelf…
Key Takeaways CISA BOD 26–04 mandates remediation of the publicly exposed, highest-risk, known-exploited vulnerabilities within 3 days. The directive applies a risk-based model evaluating exposure,…
In March 2026, our SOC caught a surge of anomalous Microsoft 365 logins across dozens of organizations simultaneously. The source: a handful of IP addresses…