Microsoft released a record-breaking Patch Tuesday addressing 570 vulnerabilities, including three zero-days and two actively exploited flaws affecting Active Directory Federation Services and SharePoint Server. The release reinforces the growing challenge organizations face in prioritizing and deploying security updates at scale.
https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days/
β‘ServiceNow AI Platform RCE Vulnerability Under Active Exploitation
Researchers observed active exploitation of a critical remote code execution vulnerability affecting the ServiceNow AI platform shortly after disclosure. The flaw allows unauthenticated attackers to escape the application sandbox and execute arbitrary code on self-hosted deployments.
https://www.securityweek.com/exploitation-of-servicenow-vulnerability-seen-days-after-disclosure/
π€Google Launches Gemini 3.5 Flash Cyber for Vulnerability Discovery
Google DeepMind introduced Gemini 3.5 Flash Cyber, an AI model purpose-built to discover, validate, and help remediate software vulnerabilities. The model demonstrated impressive results across major open-source projects and enterprise codebases, highlighting AI’s growing role in defensive security.
https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html
π¨SonicWall Issues Emergency Patches for SMA1000 Zero-Days Under Active Attack
SonicWall released urgent security updates after attackers began chaining two zero-day vulnerabilities to achieve unauthenticated remote code execution against SMA1000 secure remote access appliances. Customers are strongly encouraged to patch immediately.
https://www.securityweek.com/sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits/
πWP2Shell Flaws Exploited in Wild Against WordPress Websites
Attackers have begun exploiting two critical vulnerabilities affecting WordPress shortly after public disclosure. By chaining SQL injection and remote code execution flaws, attackers can gain complete control of vulnerable websites running recent WordPress releases.
https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/



