Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire
This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire
Read Time:3 Minute, 46 Second

If there was a single theme running through this week’s cybersecurity news, it’s that no layer of the stack is off limits anymore, from decades-old identity infrastructure to the AI copilots developers now rely on daily. Between a record-setting Microsoft patch cycle, a critical WordPress vulnerability, and a string of findings on AI systems becoming attack surfaces in their own right, defenders had little room to breathe this week.

Microsoft’s Patch Tuesday Delivers 570 Fixes, Two of Them Already Under Attack

Microsoft’s July 2026 Patch Tuesday addressed approximately 570 vulnerabilities, an unusually large batch even by recent standards. Two of those, however, stood out because they weren’t theoretical: CVE-2026-56164, affecting SharePoint Server, and CVE-2026-56155, affecting Active Directory Federation Services, were both confirmed as actively exploited zero-days at the time of disclosure. A publicly disclosed BitLocker bypass rounded out the more notable entries in the release.

The fact that attackers were already exploiting these flaws before or around the time patches shipped underscores a pattern security teams have grown used to: the gap between disclosure and weaponization keeps shrinking. Organizations running SharePoint or ADFS in production should treat these two CVEs as immediate priorities rather than folding them into a routine patch cycle.

A WordPress Bug With an Enormous Blast Radius

Separately, researchers disclosed “wp2shell,” a pre-authentication remote code execution chain in WordPress Core stemming from a REST API batch-route flaw that cascades into SQL injection and full server compromise. No plugin, login, or special configuration is required, and the affected install base is estimated in the hundreds of millions. WordPress shipped version 7.0.2 to address it, with auto-updates reportedly rolling out to vulnerable sites automatically. Given the scale of exposure, this is likely to remain a live target for opportunistic scanning well after this week’s news cycle fades.

Identity Infrastructure Keeps Taking Hits

Beyond the Patch Tuesday zero-day, Active Directory-adjacent infrastructure had a rough week more broadly. Reports of active exploitation against AD-related services piled on top of a separately disclosed proof-of-concept called “LegacyHive,” which exploits the Windows User Profile Service to let a standard user load another account’s registry hive, reportedly working even against systems patched as of July 2026. Identity systems remain one of the highest-value targets in enterprise environments, and this week is a reminder that even “boring,” long-standing components can still surface new attack paths.

AI Tools Are Becoming Their Own Attack Surface

Perhaps the most forward-looking thread this week was the growing body of research treating AI-integrated tools as a genuine, exploitable attack surface rather than a hypothetical concern. Disclosures included a vulnerability in the Claude for Chrome browser integration, a technique dubbed “GhostCommit” that hides malicious prompts inside code commits to manipulate AI coding assistants without a developer’s awareness, and an exploit chain pairing GPT-5/6-era models with Chrome browser vulnerabilities. None of these are theoretical academic exercises; they represent real, demonstrated pathways for manipulating AI systems that increasingly sit inside developer and browsing workflows with elevated trust and access.

Rounding Out the Week

Several other items are worth a defender’s attention:

  • Notepad++ patched five issues in version 8.9.7, including a high-risk installer-time PowerShell command injection bug, a stack buffer overflow, a Zip Slip path traversal flaw, a session-validation bypass, and a macro integrity bypass.
  • The ModHeader Chrome extension, with roughly 1.6 million installs, was pulled from the Chrome and Edge stores after researchers discovered dormant code capable of encrypting and exfiltrating users’ browsing history to an external server.
  • A new macOS information-stealer campaign was found disguising its payload as legitimate Apple crash-report dialogs to trick users into handing over credentials or access.
  • Fortinet, F5, Splunk, and Dell all issued patches this week, spanning issues from nginx-related flaws to BIOS-level password exposure on Dell hardware.

The Takeaway for Defenders

Taken together, this week’s stories reinforce two trends worth building into planning: patch velocity needs to keep pace with a shrinking window between disclosure and active exploitation, and the attack surface itself is expanding into places, like AI browser extensions and coding assistants, that many security programs haven’t yet formalized into their threat models. Teams that haven’t already should prioritize the two actively exploited Patch Tuesday zero-days and the WordPress RCE bug this week, while starting to ask harder questions about how AI-integrated tools are vetted, monitored, and scoped inside their environments.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on This Week’s Threat Landscape: Patch Tuesday’s 570 Fixes, an Active Directory Zero-Day, and AI Tools Under Fire, use the discussion on Forum.

>> forum community

Comments

Leave a Reply