Jul 16 · Industry News

The Attackers Moved to the Crown Jewels

The exposure frontier moved off the endpoint and onto crown-jewel business apps. Progress confirmed a zero-day behind last week’s emergency ShareFile shutdown while CISA flagged an Oracle E-Business Suite Payments flaw under active attack — two business-critical enterprise apps exploited in one cycle. Plus a 292-repo GitHub malware campaign, a €140M fraud takedown, and a disputed extortion claim.

★ Top Read

Progress confirmed that last week’s emergency shutdown of ShareFile Storage Zone Controllers was driven by a real, high-severity zero-day — a path-traversal vulnerability affecting all 5.x and 6.x versions of the Storage Zone Controller. An authenticated administrative user can read arbitrary files accessible to the service account, write attacker-controlled content to arbitrary directories, or map the server filesystem. Progress shipped emergency versions 5.12.5 and 6.0.2 and temporarily disabled affected accounts as a precaution; it reserved a CVE it says it will publish in about two weeks, so any CVE number circulating now is unofficial.

This is the same vendor and the same managed-file-transfer category that produced the MOVEit mass-exploitation event. File-transfer appliances stay a high-blast-radius exposure class because they concentrate sensitive data at the network edge. The takeaway: your riskiest exposure isn’t the raw CVE count from Patch Tuesday — it’s the handful of business-critical, data-concentrating systems an attacker can actually reach, and you triage those from telemetry of what’s exposed and whether the fix is deployed, not from a spreadsheet.

Sources: BleepingComputer · SecurityWeek · The Hacker News

Vulnerabilities & Exposure

Progress confirms ShareFile Storage Zone Controller zero-day; emergency patches shipped. High-severity path traversal in all 5.x/6.x Storage Zone Controllers lets an authenticated admin read, write, or map arbitrary files via the service account. Progress released 5.12.5 and 6.0.2, disabled affected accounts as a precaution, and is withholding the CVE for about two weeks so customers can patch before details are public.

CISA adds Oracle E-Business Suite Payments RCE (CVE-2026-46817) to its Known Exploited Vulnerabilities catalog. CISA confirmed active exploitation of a critical, unauthenticated, remotely exploitable flaw in Oracle Payments (EBS 12.2.3–12.2.15, CVSS 9.8) that allows full takeover of the Payments module. Oracle patched it in its May 2026 update; exploitation was first observed June 27, and researchers report hundreds of instances still internet-exposed. Federal agencies are on the remediation clock.

SonicWall SMA1000 zero-days remain the open KEV item from July 14. CVE-2026-15409 (CVSS 10.0 pre-auth SSRF) and CVE-2026-15410 (code injection) are both confirmed exploited as zero-days; SonicWall urges customers to patch or discontinue the appliance.

So what: Two crown-jewel enterprise apps — file transfer and ERP/payments — plus an edge appliance are all under active exploitation this cycle. Attackers are targeting where data and money concentrate; prioritize exposure telemetry on file-transfer, ERP, and edge-access systems over raw CVE backlog.

AI Impact on Security

Agentic AI security shifts from theory to “Agent Zero Trust.” July analysis marks a turn from theoretical agent flaws to structural defenses that treat every agent action as untrusted by default. Recent research includes prompt-injection payloads hidden in fake error reports that AI coding agents execute, and shell-injection tricks that bypass modern agent safeguards.

GhostApproval remains the anchor case for agent oversight. Wiz’s disclosure that several AI coding assistants can hide an agent’s real action from the approval prompt (via symlink-following) still stands as the cleanest agent-observability case: a human-in-the-loop is only a control if you can independently verify what the agent actually did.

So what: The exposure story and the agent-oversight thread share one spine — you defend both by seeing what’s actually happening, not by trusting a count or a prompt.

Cyberattacks & Breaches

292 fake GitHub repos push a BoryptGrab-lineage infostealer. A threat actor stood up around 292 repositories impersonating legitimate security tools, fintech apps, crypto wallets, and developer utilities — even spoofing security-vendor brands — using fake READMEs and landing pages to deliver a trojanized libcurl.dll that sideloads an infostealer harvesting browsers, crypto wallets, messaging apps, and Windows Credential Manager. The campaign began June 26 and is ongoing; GitHub removed many repos but some redirectors stayed live.

Spanish-led operation dismantles a €140M investment-fraud and BEC ring. Police across Spain, Portugal, and Panama arrested four running an industrial-scale fraud and laundering network — roughly 800 bank accounts and dozens of money mules — with about €61M tied to 2024 business-email-compromise activity. A reminder that BEC still out-earns most ransomware.

A new group, “D1R,” claims a Synopsys/Bosch breach — Synopsys denies it. D1R claimed it exploited a Synopsys web flaw to reach a 40,000-entry database and Bosch intellectual property, threatening a leak. Synopsys says it found no evidence of a breach, and the group’s “proof” screenshot appears to come from a public user manual. Treat it as an unverified extortion claim, not a confirmed breach.

LastPass warns of active phishing using fake “security notice” lures. LastPass flagged an ongoing campaign directing users to fraudulent sites via fake security-alert emails — the latest in a 2026 pattern of password-manager impersonation. Worth an awareness note to users.

So what: The fresh, corroborated breach signal this cycle is the GitHub supply-chain campaign and the BEC takedown — not the D1R claim. Lead with what’s sourced.

Sources & further reading (13)

← All Industry News