These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
Buried in Microsoft’s record-breaking July Patch Tuesday is CVE-2026-57092, a critical use-after-free in Windows VMSwitch that lets an attacker who already has code execution inside a guest VM send crafted network requests to the Hyper-V virtual switch and escalate to full control of the host, breaking the isolation boundary every multi-tenant hosting setup depends on. With a CVSS score of 9.9 and no user interaction required, any organisation running Hyper-V, including hosting providers, MSPs and businesses with on-premises virtualization, should treat this as a same-week patch.
A connectivity failure in AWS’s US-West-2 region on July 24 took down Reddit, Hulu, Apple Pay, DoorDash and PlayStation Network for roughly 80 minutes. AWS traced it to networking devices routing traffic between the region and the Seattle metro area, the third notable AWS reliability incident in about three months after a Northern Virginia thermal event in May and a network disruption in June. None of the three were application bugs, they were physical and network infrastructure failures, which is exactly the category of risk single-region architecture does not protect against.
Anthropic’s Claude models reached general availability on Microsoft Foundry with Azure-native billing and governance, but the EU Data Zone that would guarantee in-region processing was not part of the launch. Deployments run through Global Standard or US Data Zone routing, so prompts and responses can leave Europe even when the endpoint address reads Sweden. For any regulated organisation planning to buy Claude the way it buys the rest of its Azure estate, that gap turns a procurement decision into a compliance review.
A routine network change in Azure’s West US region on July 23 cascaded into a four-hour outage that disrupted more than twenty services, including AKS, Azure Virtual Desktop, ExpressRoute and Microsoft Sentinel, plus Microsoft 365, Teams and Outlook. Microsoft resolved it with a rollback, but the incident is the second major Azure region outage in barely a month and a reminder that your security monitoring platform can go down at exactly the moment you would most want it running.
CVE-2026-16232, a critical authentication bypass in Check Point SmartConsole, let an unauthenticated attacker obtain a login token and take full administrative control of the management server behind thousands of firewalls. Check Point shipped a hotfix on July 22 and confirmed active exploitation before the patch was public, and CISA has given US federal agencies until July 25 to fix it. European organisations running Check Point Security Management should treat this as a same-day task, not a maintenance-window one.
The European Commission is pressing member states to deploy a privacy-preserving age verification app, built on zero-knowledge proofs and tied to the EU Digital Identity Wallet, by the end of 2026. Denmark, France, Greece, Italy, Spain, Cyprus and Ireland are already integrating it into national digital wallets. Any platform serving EU users that shows age-restricted content or has obligations under the Digital Services Act should be planning integration now, not after the first enforcement notice.
From 27 July, GitHub is cutting its public bug bounty rewards by roughly half at every severity level, moving the largest payouts behind a permanent, invite-only VIP tier instead. GitHub frames it as reducing noise and rewarding proven researchers faster, but the practical effect is fewer independent eyes economically motivated to find critical flaws in widely used developer infrastructure before attackers do.
Guardio Labs disclosed HermeticReader on 22 July, a vulnerability in the Adobe Acrobat PDF extension for Chrome that let any malicious website silently pull WhatsApp Web chats, contacts and profile data from a visitor’s browser with no click and no download required. Adobe shipped a fix within days, but the flaw sat in one of the most widely installed browser extensions in the world, and it is a reminder that business communication tools are only as safe as the unrelated software siting next to them in the browser.
A public proof of concept for CVE-2026-50522, a maximum-severity SharePoint deserialization flaw Microsoft patched on 14 July, triggered active exploitation within hours of going live on 20 July. Researchers at watchTowr found attackers using it to steal SharePoint machine keys, credentials that let them forge valid authentication tokens and keep access to a server long after the underlying vulnerability has been patched, making this the fourth SharePoint flaw exploited in a single month.
A hacker broke into Romania’s National Agency for Cadastre and Real Estate Advertising using valid credentials, stole citizen data and source code, then wiped the production land registry database after an extortion demand went unpaid, freezing property sales and mortgages nationwide. ANCPI is recovering only because it kept backups at multiple offline locations the attacker could not reach, a detail that should make every organisation ask whether its own backups would survive the same scenario.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.