TL;DR
Microsoft patched a record 570 vulnerabilities in this month's Patch Tuesday; two new CVEs (Check Point SmartConsole, SharePoint) added to CISA's exploited vulnerabilities catalog; BlueNoroff phishing campaigns now profile cryptocurrency wallets before malware delivery.
Executive Summary
- Microsoft released patches for a record 570 security flaws across Windows and enterprise products, nearly triple the volume of last month's already-high Patch Tuesday release.
- Two CVEs—Check Point SmartConsole (CVE-2026-16232) and Microsoft SharePoint (CVE-2026-50522)—were added to CISA's Known Exploited Vulnerabilities catalog with federal remediation deadlines of July 25, 2026.
- BlueNoroff, a North Korean threat actor, operates an active phishing kit impersonating Zoom and Microsoft Teams to profile cryptocurrency wallets before delivering malware.
- New vulnerabilities disclosed in Active Directory (Certighost), ChatGPT Workspace Agents (AgentForger), and Microsoft's Bing image processing expose privilege escalation and AI agent deployment risks.
- FBI seized NetNut residential proxy platform and Popa botnet; LG announced plans to ban apps that turn smart TVs into residential proxy nodes, following discovery that 42% of LG TV apps were abusing this capability.
Top Threats Today
1. Microsoft Patch Tuesday Record: 570 Vulnerabilities Patched
Severity: HIGH Affected: Technology
Microsoft Corp. released software updates to patch at least 570 security holes in Windows operating systems and other software [1]. This represents nearly triple the number of vulnerabilities Microsoft fixed in its record-setting Patch Tuesday release last month ⚠[1]. Microsoft attributed the increase in vulnerability volume to its expanded security research efforts [1].
Sources:[1] Krebs on Security
Recommended Action
- Prioritize testing and deployment of Microsoft patches across all Windows and enterprise infrastructure within 48–72 hours of release.
- Focus initial deployments on systems running Exchange, SharePoint, Azure services, and Remote Desktop services.
- Establish patch management workflow to handle the increased monthly vulnerability volume going forward.
2. Check Point SmartConsole & SharePoint RCE Added to CISA KEV
Severity: HIGH Affected: Government
CISA added CVE-2026-16232 (Check Point SmartConsole) to its Known Exploited Vulnerabilities catalog on July 22, 2026, describing an improper authentication vulnerability that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges [1]. CVE-2026-50522 (Microsoft SharePoint) was also added to the KEV catalog on the same date; this deserialization of untrusted data vulnerability could allow an unauthorized attacker to execute code over a network [2]. Federal agencies must remediate both vulnerabilities by July 25, 2026 [1][2].
Sources:[1] CISA KEV[2] CISA KEV
Recommended Action
- For federal and critical infrastructure operators: apply patches for Check Point SmartConsole CVE-2026-16232 and SharePoint CVE-2026-50522 immediately (remediation due July 25).
- For all organizations: audit access logs on Check Point SmartConsole and SharePoint servers for unauthorized administrative authentication since July 1.
- Implement network segmentation to restrict administrative access to Check Point and SharePoint systems to authorized management workstations.
3. BlueNoroff Phishing Kit Profiles Cryptocurrency Wallets
Severity: HIGH Affected: Finance
The North Korean threat actor BlueNoroff operates an active phishing kit designed to impersonate videoconferencing platforms (Zoom and Microsoft Teams) in social engineering campaigns [1]. The kit employs typosquatted domain names and is part of ClickFix-style attack chains [1]. Notably, the phishing kit profiles cryptocurrency wallets before delivering malware ⚠[1].
Sources:[1] The Hacker News
Recommended Action
- Deploy email and web gateway protections to detect and block typosquatted Zoom and Microsoft Teams domains.
- Educate users to verify domain names in the browser address bar before entering credentials; provide examples of common typosquats.
- For cryptocurrency operations and high-net-worth individuals: enable hardware security keys and MFA on all financial accounts; do not rely on SMS-based 2FA.
4. Certighost: Active Directory Privilege Escalation Exploit Published
Severity: HIGH Affected: Government
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 for a vulnerability they codenamed Certighost that allows a low-privileged Active Directory user to obtain a certificate for a Domain Controller and authenticate as that machine [1]. Domain Controller accounts carry directory replication privileges, creating a pathway for lateral movement and domain compromise [1].
Sources:[1] The Hacker News
Recommended Action
- Review and restrict the issuance of Domain Controller certificates via your certificate authority; enforce approval workflows for administrative certificates.
- Audit all recently-issued certificates for Domain Controller objects in your environment.
- Monitor for suspicious certificate requests and unusual authentication from low-privileged accounts impersonating Domain Controllers.
5. ChatGPT Workspace Agents Vulnerability (AgentForger) Patched
Severity: HIGH Affected: Technology
Cybersecurity researchers disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous AI agent inside a victim's organization [1]. The vulnerability, codenamed AgentForger, could have been exploited to create, insert, and remotely control an invisible autonomous AI agent within a victim organization [2]. OpenAI has since fixed the vulnerability [2].
Sources:[1] The Hacker News[2] SecurityWeek
Recommended Action
- Update to the latest version of ChatGPT Workspace to receive the security patch.
- Review your organization's ChatGPT Workspace agent deployment permissions; enforce principle of least privilege for agent creation and modification.
- Educate users not to click links in unsolicited messages purporting to configure or manage AI agents.
Today’s Action Checklist
- ☐ URGENT: Check Point and SharePoint admins: confirm patch deployment status for CVE-2026-16232 and CVE-2026-50522; federal deadline is July 25.
- ☐ HIGH: Schedule Microsoft Patch Tuesday deployment across your environment; prioritize the 570 updates in your change management queue.
- ☐ HIGH: Audit Active Directory for suspicious certificate issuance and low-privileged-to-Domain-Controller impersonation activity following Certighost disclosure.
- ☐ HIGH: Issue user awareness communication warning against Zoom and Teams phishing links with typosquatted domains; include examples and verification guidance.
- ☐ MEDIUM: Review ChatGPT Workspace deployment; verify that AI agent creation is restricted to authorized users and that agent permissions are audited.