Wednesday 15 July 2026 | Join Free | Upgrade

Hi there, this is your daily ☕️ Cyberpresso.

In today's Cyberpresso:

🛡️ Microsoft patches record 622 flaws two under attack

🚕 Cyberattack downs Japan's biggest taxi operator

📌 Secure Boot broken for a decade unnoticed

🔓 SonicWall VPN flaws let hackers run code

Plus: 💡 4 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and 📚 5 papers.

The AI Agent You Can Trust

Some things you can always count on. Catch is one of them. Your AI admin is always on, handling the calls, the bookings, the follow-ups, day or night. It never drops the ball and never forgets. Meet the admin that's always there, always at catchagent.ai.

🛡️ Microsoft patches record 622 flaws two under attack LINK
  • Microsoft's July Patch Tuesday set a record by fixing 622 CVEs across its products, 58 of them critical, with two already under active attack and one publicly disclosed but not yet exploited.
  • One actively exploited flaw lets an attacker who already has local access gain administrator privileges due to weak access control, while a SharePoint bug missing authentication also allows privilege escalation over a network.
  • The publicly disclosed but unexploited issue lets anyone with local access to a BitLocker-secured machine physically bypass its protections; Microsoft recommends installing all the patches as soon as possible.
🚕 Cyberattack downs Japan's biggest taxi operator LINK
  • Nihon Kotsu, Japan's largest taxi and chauffeur operator, was hit by a cyberattack over the weekend that forced it to shut down parts of its infrastructure, with its taxi dispatch system still offline today.
  • The company confirmed a malware infection gave attackers unauthorized external access to internal systems, and it responded by disconnecting systems to prevent further damage, knocking out car hire, web booking, reservation management, and the telephone dispatch service.
  • The firm has engaged external cybersecurity experts and is investigating whether data was leaked, though no leak has been confirmed and no ransomware group has claimed the attack; it warns customers to avoid suspicious attachments and links claiming to come from the company.
📌 Secure Boot broken for a decade unnoticed LINK
  • Researchers at ESET found that Secure Boot, the Microsoft-invented standard protecting Windows and Linux devices from firmware infections, has been trivial to bypass for 13 of its 14 years because of old signed boot components.
  • The issue stems from 11 firmware images called shims, at least one dating to 2013, that were known to be defective yet Microsoft, which oversees shim signing, never revoked them, letting even novice hackers reuse them to bypass the protection built into the UEFI.
  • Affecting both Windows and Linux users since a shim runs on either OS, an attacker can subvert the chain of signed firmware to install malicious firmware that loads early in boot and persists after an OS reinstall or hard drive replacement.
🔓 SonicWall VPN flaws let hackers run code LINK
  • SonicWall is warning that hackers are exploiting two flaws in its SMA1000 VPN appliances as zero-days, and has released hotfixes that customers are urged to install immediately.
  • The main flaw is a maximum severity server-side request forgery bug in the Appliance Work Place interface that lets a remote, unauthenticated attacker force the appliance to make requests to unintended locations.
  • SonicWall confirmed active exploitation in multiple incidents, says there are no workarounds other than the hotfixes, and shared log-based indicators of compromise like unexpected requests to /__api__/login and /wsproxy.

Your employees are connecting AI to everything. Now what?

ChatGPT and Claude aren't just answering questions. Employees are connecting them directly to Notion, Linear, Jira, and the rest of your stack — with no security visibility into what data moves or what actions they take.

Harmonic Security gives your team the visibility to control it.

💡 Strategies & Tactics

> ClickFix's Mushrooming Ecosystem Demands New Defense Tactics: Detect ClickFix scams by scanning the fake lure webpage's structure rather than the ever-changing malware, catching attacks that antivirus tools miss.
> A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed: Cloudflare's 1.1.1.1 now adds an error code telling clients when it bypassed DNSSEC security checks to keep a broken domain reachable, making a previously invisible tradeoff transparent.
> 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload: Eleven fake NuGet game-cheat packages secretly download Windows spyware that captures screenshots and tracks hardware, showing developers must vet dependencies before installing them.
> Cursor IDE Auto-Executes Malicious Code in Poisoned Repos: Cursor's AI coding tool runs a disguised program hidden in any opened project without warning, letting attackers execute malicious code on developers' machines.

Other news & articles you might like

  • China-Linked Hackers Weaponize Claude Code and DeepSeek in Government Intrusion Campaign LINK
  • LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems LINK
  • New Qilin Ransomware Attack Uses DCSync Technique to Abuse AD Replication Protocol LINK
  • Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says LINK
  • Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates LINK
  • Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow LINK
  • 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer LINK

🛠️ Trending tools

FireTail: monitors and secures API usage across an organization's stack, detecting vulnerabilities and misconfigurations before attackers exploit them in production. LINK
BestDefense.io: automatically pentests and patches vulnerabilities in every deployment using AI, helping developers catch security flaws before they reach production. LINK
Sequirly: scans prompts and file uploads in your browser to catch API keys, credentials, and personal data before they reach ChatGPT, Claude, or Gemini. LINK
LaunchSafe: runs continuous, AI-driven pentesting that chains real exploits and auto-remediates vulnerabilities, letting engineering teams ship quickly without weakening security. LINK
NeuralNetSQL: implements a full neural network's forward and backward pass using only SQL queries, treating matrix multiplication as joins and aggregations. LINK
ai-trains-ai: an RL-trained agent that autonomously designs and trains other models using reinforcement learning, built for approximately $1,300 in compute costs. LINK

📚 Trending research papers

Code review workloads can partly predict which pull requests get accepted just from info available when they're submitted, with top models scoring above 0.95 F1, but estimating how much review effort they'll need is much harder. LINK
Tracing security bugs to their exact triggering line of code, even across distant functions, works 75.0% of the time, beating prior best methods on the same test set. LINK
AI-written software tests catch more edge cases than human-written ones, with almost double the variety (0.62 vs 0.32) and more null-safety checks (13.40% vs 8.3%), though humans write slightly stronger assertions (88.1% vs 85.37%). LINK
API testing tools perform much worse when the software blueprints they rely on contain errors, and just measuring code coverage hides how badly, researchers find. LINK
Kernel trace data can be safely synthesized, matching real system logs within 2.6 points of accuracy while cutting costs, since longer context boosts quality by 104%. LINK

Not subscribed to ☕️ Cyberpresso yet? Subscribe for free