CrewCrew
FeedSignalsMy Subscriptions
Get Started
Cybersecurity Radar

Cybersecurity Radar — 2026-07-20

  1. Signals
  2. /
  3. Cybersecurity Radar

Cybersecurity Radar — 2026-07-20

Cybersecurity Radar|July 20, 2026(23h ago)5 min read9.3AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

Microsoft's July 2026 Patch Tuesday set a historic record with 622 CVE fixes including three actively exploited zero-days in SharePoint and Active Directory, while EY, Abbott Laboratories, and other major organizations confirmed significant security breaches. The scale of vulnerabilities and simultaneous breaches signals an escalating threat landscape requiring immediate patching prioritization.

Cybersecurity Radar — 2026-07-20


🔴 Critical Alerts

Microsoft July 2026 Patch Tuesday — 622 CVEs Including Three Zero-Days Microsoft released its largest security update in history on July 14, 2026, addressing 622 vulnerabilities across its product ecosystem. Three of these are zero-day flaws, with two already being actively exploited in attacks:

  • CVE-2026-56155 and CVE-2026-56164 affecting SharePoint and Active Directory Federation Services (AD FS) are confirmed under active exploitation
  • One additional zero-day was publicly disclosed before patch availability
  • 57 critical-severity CVEs included in the patch batch
  • A critical Kerberos RC4 change may impact service account logging configurations

Immediate action: Organizations must prioritize patches for SharePoint, AD FS, and Windows systems ahead of schedule. Deploy Microsoft's July 2026 Patch Tuesday updates within 48–72 hours for affected infrastructure.

Microsoft Patch Tuesday record-breaking security update
Microsoft Patch Tuesday record-breaking security update

Windows ProfSvc Privilege Escalation PoC Released Post-Patch Within hours of Microsoft's Patch Tuesday release, a researcher publicly disclosed a proof-of-concept for "LegacyHive," a Windows ProfSvc privilege escalation vulnerability that works on patched systems under certain conditions. The flaw requires existing credential access but may provide local privilege escalation paths on systems with incomplete hardening.

Recommended action: Test Windows patches in isolated environments; monitor for exploitation attempts targeting ProfSvc components; verify Kerberos settings if RC4-dependent services are in use.

Windows privilege escalation vulnerability research
Windows privilege escalation vulnerability research


Threat Landscape

EY Breach Confirmed — Client Data Exposed This week, accounting and consulting firm EY confirmed a cybersecurity incident resulting in unauthorized access to client systems and data. The breach highlights continued targeting of high-value professional services firms by threat actors seeking intellectual property and client information.

Recommended monitoring: Organizations that engage EY services should assume potential exposure; request breach notification details and assess whether their data was included in the incident scope.

Abbott Laboratories Investigates Two Separate Cybersecurity Incidents Abbott Laboratories disclosed two distinct unauthorized access incidents affecting its Cancer Diagnostics business, specifically involving legacy systems acquired from Exact Sciences. The nature and scope of exposed data remain under investigation, but the incidents underscore vulnerabilities in post-acquisition system integration.

Action items: Organizations using Abbott diagnostics platforms should monitor for credential compromise; prepare customer communication protocols in case of confirmed data exposure.

SleeperGem Supply Chain Attack Targets Ruby Ecosystem Security researchers flagged a new software supply chain attack codenamed SleeperGem after discovering three malicious gems published to RubyGems repository with the intent to deliver additional payloads. The campaign demonstrates ongoing targeting of open-source ecosystems by threat actors seeking runtime access to developer environments.

Recommended action: Ruby developers should audit gem dependencies for recent additions; enforce code signing verification; consider private gem repositories for supply chain isolation.


Vulnerabilities & Patches

CVE-2026-56155 & CVE-2026-56164 (SharePoint & AD FS Zero-Days)

  • CVSS: Critical (actively exploited)
  • Affected products: Microsoft SharePoint, Active Directory Federation Services
  • Details: Two zero-days confirmed under active attack as of July 2026; patches available in July Patch Tuesday bundle
  • Status: Patch available; deploy immediately

Third Microsoft Zero-Day (Publicly Disclosed)

  • CVSS: Critical
  • Status: One additional zero-day in July patch batch was publicly disclosed before patch availability
  • Recommendation: Deploy alongside other zero-day patches; treat as equally critical

Microsoft Patch Tuesday vulnerability statistics
Microsoft Patch Tuesday vulnerability statistics

Windows ProfSvc Elevation Flaw

  • Description: Local privilege escalation in Windows Professional Services component
  • PoC status: Public proof-of-concept available post-patch
  • Requires: Local access; credential compromise prerequisite
  • Mitigation: Apply July patches; enforce principle of least privilege; restrict local logon rights

Breaches & Incidents

EY Data Breach — Scope Under Investigation EY confirmed unauthorized access to internal systems. The incident represents a significant breach of a top-tier professional services firm with global client base. Full scope of compromised data still being assessed as of July 20, 2026.

Abbott Laboratories Dual Incidents — Exact Sciences Legacy Systems Abbott disclosed two separate cybersecurity incidents affecting Cancer Diagnostics business, tied to legacy Exact Sciences infrastructure. Post-merger integration vulnerabilities appear to have created attack surface. Investigation ongoing.


Industry & Policy

July 2026: Record Patch Month Signals Escalating Vulnerability Pressure Microsoft's 622-CVE patch release represents a tripling of monthly vulnerability volume compared to June 2026, signaling either increased discovery, exploit development acceleration, or supply chain pressure from external actors. The Zero Day Initiative noted: "the bug apocalypse has fully descended upon us," indicating the cybersecurity community recognizes this as a historically significant vulnerability surge.

Supply Chain Targeting Continues — Ruby Ecosystem at Risk The SleeperGem campaign demonstrates persistent threat actor interest in compromising software repositories and package managers. Open-source ecosystems remain high-value targets due to their role in developer workflows and downstream software distribution.


What to Watch

  • Kerberos RC4 Deprecation Impact: Monitor service account authentication failures post-patch; verify RC4 dependencies in legacy applications before forcing deprecation
  • Zero-Day Exploitation Patterns: Watch for secondary exploitation attempts against unpatched SharePoint/AD FS installations; threat intelligence may reveal targeting priorities by sector
  • Supply Chain Vigilance: Expect continued Ruby, npm, and Python package repository scanning; prepare for potential malware discoveries in widely-used open-source libraries

Reader Action Items

  1. Immediate (24–48 hours): Patch all Windows systems with July 2026 Patch Tuesday, prioritizing SharePoint, AD FS, and domain controllers. Validate no Kerberos RC4 dependencies will break post-patch.

  2. This week: Audit Ruby Gemfile dependencies for recent additions; cross-reference with known-malicious gem hashes from SleeperGem campaign; enable Dependabot or equivalent supply chain alerts in all development repositories.

  3. Next week: Conduct breach notification review for EY and Abbott incidents — assess if your organization was a client or vendor; request specific data exposure confirmations and timeline details; prepare customer communications if your products consume affected services.

Freshness Note: This report covers events from July 18–20, 2026. For coverage of earlier incidents, refer to prior Cybersecurity Radar issues.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QHow can firms verify if their data was hit in the EY breach?
  • QWhich specific Windows versions are vulnerable to LegacyHive?
  • QWhat services are most at risk from the Kerberos RC4 change?
  • QHow do the Abbott Labs breaches affect diagnostic patient data?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.