CrewCrew
FeedSignalsMy Subscriptions
Get Started
Cybersecurity Radar

Cybersecurity Radar — 2026-07-25

  1. Signals
  2. /
  3. Cybersecurity Radar

Cybersecurity Radar — 2026-07-25

Cybersecurity Radar|July 25, 2026(1h ago)5 min read9.3AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

Ransomware activity surged in the past week with fresh reports of supply chain targeting and AI-enhanced tactics, while Microsoft's record-breaking July Patch Tuesday addressed 622 vulnerabilities including three zero-days already under active exploitation. Critical infrastructure remains in the crosshairs as Iranian-affiliated threat actors maintain pressure on operational technology systems.

Cybersecurity Radar — 2026-07-25


🔴 Critical Alerts

Microsoft July 2026 Patch Tuesday: 622 CVEs, 3 Zero-Days Under Active Attack Microsoft released a record-breaking security update addressing 622 vulnerabilities, including three zero-day exploits already exploited in the wild. Two zero-days affect SharePoint and Active Directory Federation Services (AD FS), both critical for enterprise authentication. CISA has set a federal remediation deadline of July 28 for critical vulnerabilities. Organizations must prioritize these patches immediately to prevent credential compromise and lateral movement.

Screenshot of Microsoft Patch Tuesday July 2026 update dashboard
Screenshot of Microsoft Patch Tuesday July 2026 update dashboard

Check Point Zero-Day Exploit Used in Active Attacks Israeli cybersecurity firm Check Point Software disclosed a critical zero-day vulnerability in its SmartConsole graphical user interface (GUI) admin panel that is currently being exploited in the wild. The flaw allows attackers to compromise the administrative interface of enterprise security solutions. Organizations running affected Check Point products should apply patches immediately and review access logs for unauthorized administrative activity.

malwarebytes.com

malwarebytes.com


Threat Landscape

Ransomware Groups Intensifying Supply Chain Targeting; More Victims Expected Ransomware threat activity escalated sharply in the past week, with reports indicating a significant rise in attacks targeting supply chain partners and third-party vendors. Multiple ransomware groups are competing intensely, driving increased operational frequency and sophistication. Supply chain compromises are particularly dangerous as they allow attackers to gain access to multiple downstream victims through a single breach. Organizations should strengthen vendor risk management, implement zero-trust principles, and monitor for indicators of compromise from third-party service providers.

Ransomware threat trends visualization
Ransomware threat trends visualization

Iranian Cyber Operations Continue Pressure on Operational Technology Systems The U.S. government issued an updated advisory warning of ongoing Iranian-affiliated cyber activity targeting internet-connected operational technology (OT) devices. CISA added new guidance to detect malicious code injected into Rockwell Automation PLC programs, expanding earlier April 2026 warnings. State-backed threat actors are increasingly blurring the line between espionage and destructive capabilities, with ransomware-style operations used alongside nation-state objectives. Critical infrastructure operators must prioritize segmentation of OT networks and implement enhanced monitoring for unauthorized code modifications.

Funky Mantis RaaS Operation Offering Centralized Affiliate Management Swiss cybersecurity firm PRODAFT is tracking a centrally administered ransomware-as-a-service (RaaS) operation called Funky Mantis. DevMan operators are maintaining a dedicated web platform that allows affiliates to build custom payloads, manage victim communications, and track earnings—resembling a mature criminal franchise. This operational maturity suggests the group will remain active in targeting mid-market and enterprise organizations.

helpnetsecurity.com

helpnetsecurity.com


Vulnerabilities & Patches

Windows ProfSvc Privilege Escalation PoC Released After Patch Security researcher LegacyHive released a public proof-of-concept for a Windows ProfSvc privilege escalation flaw that functions despite July 2026 patches. While the PoC requires elevated credentials to exploit, its public availability accelerates the timeline for attackers to develop fully weaponized exploits. Organizations should prioritize testing and validating patches in non-production environments before broad deployment.

Windows vulnerability alert notification
Windows vulnerability alert notification

Microsoft SharePoint and AD FS Zero-Days Demand Immediate Attention Among the three zero-days fixed in July's Patch Tuesday, SharePoint and Active Directory Federation Services vulnerabilities pose the highest risk to enterprises. Both services are extensively used for authentication and information sharing, making them prime targets for lateral movement and privilege escalation. Threat intelligence indicates these flaws are being actively weaponized by advanced threat actors. CVSS scores place these among the most critical Microsoft vulnerabilities this year.


Breaches & Incidents

Data Breaches Return "With a Vengeance" After Week of Quiet Following a brief lull, confirmed data breaches returned in force during the July 17-23 period. Organizations across multiple sectors experienced significant compromises, with incident response teams stretched thin managing the surge. The increase correlates with heightened ransomware group activity and improved attack sophistication documented in weekly threat reports.

Data breach statistics visualization
Data breach statistics visualization

Cybersecurity Threats Escalate Across Government, Business, and Consumer Sectors The threat landscape continues to expand with simultaneous increases in ransomware, data breaches, and online fraud targeting all organizational tiers. Governments, enterprises, and individual consumers face escalating risks as threat actors deploy more agile tactics and coordinate attacks across multiple vectors. The convergence of state-backed and criminal activity creates a complex defensive challenge.

images.unsplash.com

images.unsplash.com


Industry & Policy

NSA and CISA Issue Joint Advisory on Critical Infrastructure Defense The National Security Agency published an advisory alongside CISA addressing rising threats to critical infrastructure, particularly operational technology systems. The guidance reinforces the need for mandatory segmentation, enhanced monitoring, and supplier risk management. Federal agencies are increasing scrutiny of contractor cybersecurity postures as nation-state activity intensifies.

SMB Targeting Accelerates as Ransomware Competition Intensifies Threat landscape analysis indicates increased targeting of small and medium-sized businesses alongside continued hits against larger enterprises. Competition among top-tier ransomware groups is driving higher operational frequency and more aggressive affiliate recruitment. SMBs often lack mature incident response capabilities, making them attractive targets despite lower individual payouts.


What to Watch

  • CISA Federal Deadline July 28: Critical Microsoft vulnerabilities must be patched across federal agency networks within days; widespread exploitation is certain if patches are delayed beyond this date
  • Check Point Admin Interface Attacks: Additional zero-days in security vendor products may be disclosed; review administrative access logs and consider temporary restrictions on remote admin access
  • Ransomware Supply Chain Cascades: Expect secondary waves of breaches as attackers move laterally from compromised vendors into customer networks; prepare for multi-party incident response scenarios

Reader Action Items

  1. Apply Microsoft patches immediately — Prioritize SharePoint and AD FS zero-days before July 28 federal deadline; test in non-production first but do not delay production deployment beyond end of week
  2. Audit vendor access and credentials — Review all third-party administrative credentials and service account permissions; rotate passwords for any accounts with elevated privileges to critical systems
  3. Activate incident response monitoring — Enable enhanced logging for authentication events, lateral movement indicators, and code modifications on operational technology and business systems; coordinate with security operations center to review for breach indicators

Data Sources: Privacy Guides, Malwarebytes, The Hacker News, SecurityWeek, Help Net Security, Hornetsecurity, SWK Technologies, SC Media

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QWhich sectors are most at risk from these attacks?
  • QHow can companies verify their vendors' security?
  • QWhat indicators show a Check Point compromise?
  • QAre there specific patches for the Iranian threats?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.