{
  "meta": {
    "generated": "2026-07-22T09:09:04.530Z",
    "schemaVersion": "1.0",
    "source": "https://defend.network",
    "docs": "https://defend.network/api/",
    "license": "CC BY 4.0",
    "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
    "attribution": "Data by defend.network (https://defend.network), licensed CC BY 4.0. Underlying CVE facts from NVD (NIST), the CISA KEV catalog, and FIRST.org EPSS.",
    "count": 30
  },
  "briefings": [
    {
      "date": "2026-07-22",
      "title": "SharePoint RCE, WordPress flaws, PAN-OS actively exploited in ransomware campaigns",
      "url": "https://defend.network/briefings/sharepoint-wordpress-ransomware-active-exploits-2026-07-22.html",
      "severity": "high",
      "threats": [
        "vulnerability-exploit",
        "ransomware"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-21",
      "title": "WordPress, SonicWall zero-days in active exploitation; FakeGit malware campaign hits 7,600 GitHub repos",
      "url": "https://defend.network/briefings/fakegit-wordpress-sonicwall-zero-day-exploits-2026-07-21.html",
      "severity": "critical",
      "threats": [
        "malware",
        "zero-day"
      ],
      "industries": [
        "technology",
        "finance"
      ]
    },
    {
      "date": "2026-07-20",
      "title": "NGINX, WordPress, SonicWall RCEs under active exploitation; patched versions released",
      "url": "https://defend.network/briefings/nginx-wordpress-sonicwall-rce-exploits-2026-07-20.html",
      "severity": "low",
      "threats": [
        "zero-day",
        "vulnerability-exploit"
      ],
      "industries": [
        "technology",
        "government"
      ]
    },
    {
      "date": "2026-07-19",
      "title": "WordPress, 7-Zip RCE exploited; NadMesh steals AWS keys; ACR Stealer surge",
      "url": "https://defend.network/briefings/wordpress-7zip-nadmesh-acr-stealer-rce-2026-07-19.html",
      "severity": "medium",
      "threats": [
        "vulnerability-exploit",
        "malware"
      ],
      "industries": [
        "technology",
        "healthcare"
      ]
    },
    {
      "date": "2026-07-18",
      "title": "WordPress, OpenSSL, Fortinet zero-days: patches shipped and KEV escalations",
      "url": "https://defend.network/briefings/wordpress-openssl-fortinet-exploits-patched-2026-07-18.html",
      "severity": "high",
      "threats": [
        "vulnerability-exploit",
        "supply-chain"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-17",
      "title": "Scattered Spider sentenced; Microsoft patches record 570 flaws; macOS ClickLock stealer active",
      "url": "https://defend.network/briefings/scattered-spider-sentenced-microsoft-570-patches-clickl-2026-07-17.html",
      "severity": "high",
      "threats": [
        "vulnerability-exploit",
        "malware"
      ],
      "industries": [
        "government",
        "transportation"
      ]
    },
    {
      "date": "2026-07-16",
      "title": "Microsoft SharePoint, Windows zero-days actively exploited; Zoom account takeover critical",
      "url": "https://defend.network/briefings/microsoft-sharepoint-zoom-windows-critical-exploits-2026-07-16.html",
      "severity": "high",
      "threats": [
        "zero-day",
        "vulnerability-exploit"
      ],
      "industries": [
        "government",
        "technology"
      ]
    },
    {
      "date": "2026-07-15",
      "title": "Critical zero-days in Microsoft Active Directory, SonicWall SMA1000, GitHub malware campaign",
      "url": "https://defend.network/briefings/microsoft-sonicwall-github-zero-day-exploits-2026-07-15.html",
      "severity": "critical",
      "threats": [
        "zero-day",
        "vulnerability-exploit"
      ],
      "industries": [
        "technology",
        "finance"
      ]
    },
    {
      "date": "2026-07-14",
      "title": "ModHeader, CrashStealer, Joomla RCE active exploits; npm supply-chain risk",
      "url": "https://defend.network/briefings/modheader-extension-crashstealer-joomla-rce-exploits-2026-07-14.html",
      "severity": "medium",
      "threats": [
        "supply-chain",
        "malware"
      ],
      "industries": [
        "technology",
        "retail"
      ]
    },
    {
      "date": "2026-07-13",
      "title": "npm supply-chain attacks escalate; Zimbra RCE, Android malware evolves",
      "url": "https://defend.network/briefings/npm-supply-chain-zimbra-rce-android-malware-2026-07-13.html",
      "severity": "medium",
      "threats": [
        "supply-chain",
        "malware"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-12",
      "title": "npm supply-chain attacks: jscrambler infostealer, Injective wallet theft, Zimbra RCE",
      "url": "https://defend.network/briefings/jscrambler-zimbra-injective-npm-supply-chain-2026-07-12.html",
      "severity": "medium",
      "threats": [
        "supply-chain",
        "malware"
      ],
      "industries": [
        "technology",
        "finance"
      ]
    },
    {
      "date": "2026-07-11",
      "title": "Progress ShareFile emergency shutdown; Injective GitHub breach; U-Boot firmware flaws",
      "url": "https://defend.network/briefings/progress-sharefile-injective-uboot-firmware-threats-2026-07-11.html",
      "severity": "medium",
      "threats": [
        "supply-chain",
        "vulnerability-exploit"
      ],
      "industries": [
        "technology",
        "finance"
      ]
    },
    {
      "date": "2026-07-10",
      "title": "GitHub API enumeration campaign exposed; GigaWiper Windows backdoor combines disk wipe, spyware",
      "url": "https://defend.network/briefings/github-api-enumeration-gigawiper-windows-backdoor-npm-s-2026-07-10.html",
      "severity": "medium",
      "threats": [
        "supply-chain",
        "malware"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-09",
      "title": "Ubiquiti UniFi critical patches; HalluSquatting targets AI coding assistants",
      "url": "https://defend.network/briefings/ubiquiti-unifi-hallusquatting-ai-coding-exploits-2026-07-09.html",
      "severity": "medium",
      "threats": [
        "vulnerability-exploit",
        "supply-chain"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-08",
      "title": "GitHub, Gitea, Google Dialogflow hit by active exploits; RedWing Android malware-as-service",
      "url": "https://defend.network/briefings/github-gitea-google-dialogflow-android-redwing-2026-07-08.html",
      "severity": "high",
      "threats": [
        "vulnerability-exploit",
        "mobile-malware"
      ],
      "industries": [
        "technology",
        "finance"
      ]
    },
    {
      "date": "2026-07-07",
      "title": "Adobe ColdFusion RCE, Linux KVM escape, Gitea authentication bypass under active attack",
      "url": "https://defend.network/briefings/adobe-coldfusion-linux-kvm-gitea-active-exploits-2026-07-07.html",
      "severity": "critical",
      "threats": [
        "vulnerability-exploit",
        "apt"
      ],
      "industries": [
        "technology",
        "government"
      ]
    },
    {
      "date": "2026-07-06",
      "title": "North Korea PolinRider expands to 108 packages; Avalon ransomware framework emerges",
      "url": "https://defend.network/briefings/north-korea-malware-packages-avalon-framework-ransomwar-2026-07-06.html",
      "severity": "medium",
      "threats": [
        "malware",
        "ransomware"
      ],
      "industries": [
        "technology",
        "government"
      ]
    },
    {
      "date": "2026-07-05",
      "title": "North Korea targets npm, Linux kernel RCE, AI-driven ransomware surge",
      "url": "https://defend.network/briefings/north-korea-malware-linux-kernel-ransomware-ai-2026-07-05.html",
      "severity": "medium",
      "threats": [
        "malware",
        "ransomware"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-04",
      "title": "Linux kernel RCE, FatFs firmware flaws, North Korea npm malware",
      "url": "https://defend.network/briefings/linux-kernel-fatfs-npm-supply-chain-threats-2026-07-04.html",
      "severity": "low",
      "threats": [
        "vulnerability-exploit",
        "supply-chain"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-03",
      "title": "NetNut seized; Citrix Bleed 2 exploited; ToddyCat hijacks Gmail via OAuth",
      "url": "https://defend.network/briefings/netnut-citrix-bleed-toddycat-oauth-gmail-2026-07-03.html",
      "severity": "high",
      "threats": [
        "vulnerability-exploit",
        "malware"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-07-02",
      "title": "Unpatched Argo CD RCE, ChocoPoC researcher targeting, Scattered Spider extraditions",
      "url": "https://defend.network/briefings/argo-cd-kubernetes-chocopoc-github-scattered-spider-2026-07-02.html",
      "severity": "medium",
      "threats": [
        "vulnerability-exploit",
        "supply-chain"
      ],
      "industries": [
        "technology",
        "government"
      ]
    },
    {
      "date": "2026-07-01",
      "title": "AI agent poisoning, Langflow RCE exploited: Microsoft warns data theft risks",
      "url": "https://defend.network/briefings/ai-agent-poisoning-microsoft-langflow-rce-cryptojacking-2026-07-01.html",
      "severity": "high",
      "threats": [
        "vulnerability-exploit",
        "credential-theft"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-06-30",
      "title": "Oracle PeopleSoft breaches widen; malicious Chrome extension steals searches; Mustang Panda targets India",
      "url": "https://defend.network/briefings/oracle-peoplesoft-microsoft-chrome-credential-theft-2026-06-30.html",
      "severity": "critical",
      "threats": [
        "data-breach",
        "credential-theft"
      ],
      "industries": [
        "finance",
        "government"
      ]
    },
    {
      "date": "2026-06-29",
      "title": "Russian intel evolves Signal phishing; Cisco actively exploited; KDDI breach hits 14.2M",
      "url": "https://defend.network/briefings/russian-phishing-signal-cisco-breach-2026-06-29.html",
      "severity": "medium",
      "threats": [
        "phishing",
        "apt"
      ],
      "industries": [
        "government",
        "telecom"
      ]
    },
    {
      "date": "2026-06-28",
      "title": "Russian phishing escalates; Turla malware evolves; GitHub AI agents at risk",
      "url": "https://defend.network/briefings/russian-signal-phishing-turla-malware-github-ai-2026-06-28.html",
      "severity": "medium",
      "threats": [
        "phishing",
        "apt"
      ],
      "industries": [
        "government"
      ]
    },
    {
      "date": "2026-06-27",
      "title": "Signal backup keys targeted; Linux kernel RCE; AWS Q credential theft",
      "url": "https://defend.network/briefings/signal-phishing-linux-kernel-aws-credential-theft-2026-06-27.html",
      "severity": "low",
      "threats": [
        "phishing",
        "credential-theft"
      ],
      "industries": [
        "government",
        "technology"
      ]
    },
    {
      "date": "2026-06-25",
      "title": "Critical Lantronix flaw actively exploited; Cisco SD-WAN zero-day; 27M credentials recovered",
      "url": "https://defend.network/briefings/lantronix-eds5000-cisco-sd-wan-cordyceps-github-2026-06-25.html",
      "severity": "high",
      "threats": [
        "vulnerability-exploit",
        "supply-chain"
      ],
      "industries": [
        "government",
        "technology"
      ]
    },
    {
      "date": "2026-06-24",
      "title": "FortiBleed harvests 110M credentials; Cisco SSRF actively exploited; GitHub patches CI/CD attacks",
      "url": "https://defend.network/briefings/fortibleed-cisco-github-ai-credential-theft-2026-06-24.html",
      "severity": "high",
      "threats": [
        "credential-theft",
        "vulnerability-exploit"
      ],
      "industries": [
        "technology"
      ]
    },
    {
      "date": "2026-06-23",
      "title": "WordPress, AI Platform, Proxy Supply-Chain Compromises: Backdoors and Cross-Tenant Leaks",
      "url": "https://defend.network/briefings/shapedplugin-dify-squidbleed-supply-chain-exposure-2026-06-23.html",
      "severity": "medium",
      "threats": [
        "supply-chain",
        "data-breach"
      ],
      "industries": [
        "technology",
        "finance"
      ]
    },
    {
      "date": "2026-06-22",
      "title": "AI Agent Exploitation, SocGholish Disruption, Klue Salesforce Breach",
      "url": "https://defend.network/briefings/autojack-ai-exploit-socgholish-disrupted-klue-salesforc-2026-06-22.html",
      "severity": "low",
      "threats": [
        "zero-day",
        "supply-chain"
      ],
      "industries": [
        "technology"
      ]
    }
  ]
}
