Progress confirmed that last week’s emergency shutdown of ShareFile Storage Zone Controllers was driven by a real, high-severity zero-day — a path-traversal vulnerability affecting all 5.x and 6.x versions of the Storage Zone Controller. An authenticated administrative user can read arbitrary files accessible to the service account, write attacker-controlled content to arbitrary directories, or map the server filesystem. Progress shipped emergency versions 5.12.5 and 6.0.2 and temporarily disabled affected accounts as a precaution; it reserved a CVE it says it will publish in about two weeks, so any CVE number circulating now is unofficial.
This is the same vendor and the same managed-file-transfer category that produced the MOVEit mass-exploitation event. File-transfer appliances stay a high-blast-radius exposure class because they concentrate sensitive data at the network edge. The takeaway: your riskiest exposure isn’t the raw CVE count from Patch Tuesday — it’s the handful of business-critical, data-concentrating systems an attacker can actually reach, and you triage those from telemetry of what’s exposed and whether the fix is deployed, not from a spreadsheet.
Sources: BleepingComputer · SecurityWeek · The Hacker News
Vulnerabilities & Exposure
Progress confirms ShareFile Storage Zone Controller zero-day; emergency patches shipped. High-severity path traversal in all 5.x/6.x Storage Zone Controllers lets an authenticated admin read, write, or map arbitrary files via the service account. Progress released 5.12.5 and 6.0.2, disabled affected accounts as a precaution, and is withholding the CVE for about two weeks so customers can patch before details are public.
CISA adds Oracle E-Business Suite Payments RCE (CVE-2026-46817) to its Known Exploited Vulnerabilities catalog. CISA confirmed active exploitation of a critical, unauthenticated, remotely exploitable flaw in Oracle Payments (EBS 12.2.3–12.2.15, CVSS 9.8) that allows full takeover of the Payments module. Oracle patched it in its May 2026 update; exploitation was first observed June 27, and researchers report hundreds of instances still internet-exposed. Federal agencies are on the remediation clock.
SonicWall SMA1000 zero-days remain the open KEV item from July 14. CVE-2026-15409 (CVSS 10.0 pre-auth SSRF) and CVE-2026-15410 (code injection) are both confirmed exploited as zero-days; SonicWall urges customers to patch or discontinue the appliance.
So what: Two crown-jewel enterprise apps — file transfer and ERP/payments — plus an edge appliance are all under active exploitation this cycle. Attackers are targeting where data and money concentrate; prioritize exposure telemetry on file-transfer, ERP, and edge-access systems over raw CVE backlog.
AI Impact on Security
Agentic AI security shifts from theory to “Agent Zero Trust.” July analysis marks a turn from theoretical agent flaws to structural defenses that treat every agent action as untrusted by default. Recent research includes prompt-injection payloads hidden in fake error reports that AI coding agents execute, and shell-injection tricks that bypass modern agent safeguards.
GhostApproval remains the anchor case for agent oversight. Wiz’s disclosure that several AI coding assistants can hide an agent’s real action from the approval prompt (via symlink-following) still stands as the cleanest agent-observability case: a human-in-the-loop is only a control if you can independently verify what the agent actually did.
So what: The exposure story and the agent-oversight thread share one spine — you defend both by seeing what’s actually happening, not by trusting a count or a prompt.
Cyberattacks & Breaches
292 fake GitHub repos push a BoryptGrab-lineage infostealer. A threat actor stood up around 292 repositories impersonating legitimate security tools, fintech apps, crypto wallets, and developer utilities — even spoofing security-vendor brands — using fake READMEs and landing pages to deliver a trojanized libcurl.dll that sideloads an infostealer harvesting browsers, crypto wallets, messaging apps, and Windows Credential Manager. The campaign began June 26 and is ongoing; GitHub removed many repos but some redirectors stayed live.
Spanish-led operation dismantles a €140M investment-fraud and BEC ring. Police across Spain, Portugal, and Panama arrested four running an industrial-scale fraud and laundering network — roughly 800 bank accounts and dozens of money mules — with about €61M tied to 2024 business-email-compromise activity. A reminder that BEC still out-earns most ransomware.
A new group, “D1R,” claims a Synopsys/Bosch breach — Synopsys denies it. D1R claimed it exploited a Synopsys web flaw to reach a 40,000-entry database and Bosch intellectual property, threatening a leak. Synopsys says it found no evidence of a breach, and the group’s “proof” screenshot appears to come from a public user manual. Treat it as an unverified extortion claim, not a confirmed breach.
LastPass warns of active phishing using fake “security notice” lures. LastPass flagged an ongoing campaign directing users to fraudulent sites via fake security-alert emails — the latest in a 2026 pattern of password-manager impersonation. Worth an awareness note to users.
So what: The fresh, corroborated breach signal this cycle is the GitHub supply-chain campaign and the BEC takedown — not the D1R claim. Lead with what’s sourced.
Sources & further reading (13)
- BleepingComputer — “Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown”
- SecurityWeek — “Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption”
- The Hacker News — “URGENT — Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers”
- CISA — “CISA Adds Two Known Exploited Vulnerabilities to Catalog (July 15)”
- The Hacker News — “Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild”
- BleepingComputer — “Over 900 Oracle E-Business instances exposed to ongoing attacks”
- SecurityWeek — “SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits”
- Adversa AI — “Top Agentic AI security resources — July 2026”
- Wiz — “GhostApproval: A Trust Boundary Gap in AI Coding Assistants”
- Arctic Wolf — “Fake GitHub Repositories Deliver BoryptGrab-Lineage Infostealer”
- BleepingComputer — “Spanish Police take down €140 million cyber fraud ring, arrest four”
- SecurityWeek — “Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims”
- SecurityWeek — “LastPass Warns of New Phishing Campaign”