Storm-2603 is using the SharePoint deserialization flaw (CVE-2026-45659) to deploy Warlock ransomware, and Microsoft says it caught two unrelated attackers operating inside the same network. The vulnerability, which federal agencies were ordered to patch by July 4, needs only Site Member permissions for initial access.
The Known Exploited Vulnerabilities listing stops being an abstract deadline and becomes a live ransomware campaign against on-premises SharePoint farms. For a security-conscious audience, the lesson is the seam again: the exposure isn’t the patch’s availability — it shipped in May — but the dwell time and lateral movement that follow a low-privilege foothold.
Sources: The Hacker News, CISA Known Exploited Vulnerabilities Catalog
Cyberattacks & Breaches
SharePoint CVE-2026-45659 → Storm-2603 / Warlock ransomware. The CVSS 8.8 deserialization remote-code-execution flaw was patched by Microsoft in May 2026 across SharePoint Subscription Edition, 2019 and Enterprise 2016; an authenticated attacker with only Site Member rights can trigger it. CISA added it to its Known Exploited Vulnerabilities catalog with a July 4 federal deadline; Microsoft attributes exploitation to Storm-2603, a Warlock ransomware operator active against on-premises SharePoint since mid-2025, and describes a case where two unrelated intruders were in the same environment simultaneously.
So what: Two of today’s lead stories share one shape — a low-friction initial foothold, whether a low-privilege SharePoint bug or a cloned government filename, that only becomes a breach because of what happens after, unseen. The durable control is behavioral, cross-domain visibility that catches lateral movement and post-access activity, not the front-door signature.
Operation DragonReturn — China-nexus DcRAT campaign against India’s tax infrastructure. Seqrite Labs detailed a multi-stage campaign that clones the legitimate 2026-27 tax-filing utility’s filename to spear-phish taxpayers, chartered accountants and corporate finance teams, then deploys the DcRAT remote-access trojan via image-concealed payloads, process injection, AMSI bypass and fileless execution — a recent variant went undetected by every scanner on VirusTotal. Researchers link the campaign to Chinese-nexus infrastructure with tactical overlap to the Silver Fox threat actor; the nation-state attribution is suspected, not confirmed.
So what: Two of today’s lead stories share one shape — a low-friction initial foothold, whether a low-privilege SharePoint bug or a cloned government filename, that only becomes a breach because of what happens after, unseen. The durable control is behavioral, cross-domain visibility that catches lateral movement and post-access activity, not the front-door signature.
Vulnerabilities & Exposure
FatFs — seven bugs, and physical access leads to a jailbreak. runZero disclosed seven flaws, none critical but several high-severity, in FatFs, the FAT/exFAT library bundled into millions of embedded devices. The worst allow memory corruption and code execution from a booby-trapped USB stick, SD card or over-the-air update image. Affected platforms include Espressif’s ESP-IDF, ST’s STM32Cube, Zephyr, MicroPython, ArduPilot, RT-Thread, Mbed, Samsung’s TizenRT and SWUpdate. There is no upstream fix for the memory-corruption bugs, no security mailing list, and no clean way for downstream products to learn they are affected; as of the July 1 disclosure, no in-the-wild exploitation had been observed.
So what: FatFs is the more strategic of this week’s vulnerabilities — it’s a supply-chain visibility problem, not a patch problem. When a library ships silently inside firmware with no advisory path, asset owners can’t even enumerate their exposure. That’s an inventory-and-visibility question long before it’s a remediation one.
TrojPix — new air-gap exfiltration via video-cable emissions. Researchers showed that malware can nudge the least-significant bits of on-screen pixels to shape the electromagnetic radiation off an HDMI cable into a controllable signal, reaching a peak of roughly 1 megabyte per second and a range of up to 208 meters, with no administrator rights or hardware tampering required. It is exfiltration-only — the malware must already be on the machine — making it an egress channel for high-assurance and air-gapped environments rather than an intrusion vector.
So what: FatFs is the more strategic of this week’s vulnerabilities — it’s a supply-chain visibility problem, not a patch problem. When a library ships silently inside firmware with no advisory path, asset owners can’t even enumerate their exposure. That’s an inventory-and-visibility question long before it’s a remediation one.
AI Impact on Security
AI is now on both sides of the vulnerability lifecycle. runZero found the FatFs bugs by re-approaching the codebase in March 2026 with an AI coding assistant in “auto” mode, with no custom fuzzing harness — a concrete data point that AI-assisted discovery is compressing the research cycle for defenders, and symmetrically, for attackers. It slots into the week’s broader AI-attacker arc: AI-generated browser ransomware, an LLM running an intrusion end-to-end, and an AI-assisted malware framework tuned to evade endpoint detection.
So what: The AI story this week isn’t a single incident, it’s a pattern — the barrier to both finding and weaponizing flaws is dropping on both sides at once. That’s arguable now as one thesis without waiting on the next headline.
Regulatory & Policy
HSIN oversight thread hardens. Closed-door congressional briefings now look all but certain, per federal reporting, extending Senator Mark Warner’s earlier demand into a durable accountability question: who owns monitoring of the unclassified legacy tier, and what visibility obligations attach to information-sharing infrastructure.
So what: The HSIN oversight angle stays the more board-legible federal story — it reframes “was classified data taken?” into “why did it take weeks to see anyone was inside?”
EU AI Act obligations still take effect August 2, 2026. Unchanged; the compliance clock runs into a month where AI sits on both sides of the attack surface.
So what: The HSIN oversight angle stays the more board-legible federal story — it reframes “was classified data taken?” into “why did it take weeks to see anyone was inside?”
Sources & further reading (6)
- The Hacker News — “SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation”
- CISA — “Known Exploited Vulnerabilities Catalog”
- Seqrite — “Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India Tax Infrastructure via Multi-Stage DcRAT Deployment”
- runZero — “Seven FatFs bugs, one very large blast radius”
- The Hacker News — “New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions”
- Nextgov/FCW — “Hackers breached DHS information-sharing network, people familiar say”