Cyber threat intelligence · CISO Advisory product run
Board-ready daily situational awareness · Verified facts only · Action-forced
The enterprise threat picture on 2026-07-17 is Severe.
The last 72 hours compressed multiple confirmed in-the-wild exploitation
events: a dense KEV delta (critical batches 14–16 July), dual Microsoft
zero-days in SharePoint and AD FS,
unauthenticated RCE paths on FortiSandbox and
SonicWall SMA1000, and a critical unauthenticated
Oracle Payments takeover under active exploitation.
Concurrently, the Miasma / Shai-Hulud npm worm lineage
delivered a canary wave (miasma-train-p1) that abused
trusted CI/CD publishing and valid SLSA provenance—bypassing many
“provenance-only” supply-chain defenses.
Ransomware-as-a-Service remains industrially active (The Gentlemen, Qilin, Akira). Multi-agency joint advisory AA26-194A re-confirmed long-running FSB Center 16 (Berserk Bear / Energetic Bear / Ghost Blizzard / Static Tundra) exploitation of weak SNMP and edge routers across critical infrastructure.
@asyncapi/* versions and Miasma drop paths; rotate
developer, CI, cloud, and registry credentials on any hit.
| # | Name | Risk | Business impact | Why today |
|---|---|---|---|---|
| 1 | Miasma / Shai-Hulud · miasma-train-p1 (AsyncAPI npm) | 10 | Dev + CI secrets → cloud/identity takeover at worm scale | Valid provenance + on-import RAT; 130+ secret types |
| 2 | CVE-2026-58644 SharePoint deserialization RCE | 9 | Full on-prem collab compromise; ransomware staging | KEV 16 Jul; CVSS 9.8; due 19 Jul; multi-CVE cluster |
| 3 | CVE-2026-15409/15410 SonicWall SMA1000 | 9 | Remote access foothold → TOTP theft → lateral | Zero-day pre-disclosure; KEV due 17 Jul; CVSS 10.0 SSRF |
| 4 | CVE-2026-25089/39808 FortiSandbox unauth OS inj. | 9 | Security appliance RCE; pivot into security stack | KEV 16 Jul; CVSS 9.8; public PoC history |
| 5 | CVE-2026-46817 Oracle EBS Payments takeover | 9 | Unauth HTTP compromise of payment processing | KEV 15 Jul; CVSS 9.8; due 18 Jul; active since late June |
| 6 | SharePoint auth/deserialization cluster | 8 | EoP / RCE chain on enterprise portals | Internet-facing farms highest risk |
| 7 | CVE-2026-56155 AD FS DKM ACL EoP | 8 | Token-signing key risk → federated impersonation | Identity control-plane blast radius |
| 8 | The Gentlemen / Qilin / Akira RaaS | 8 | Revenue stop, data leak, regulatory exposure | Continuous mid-July leak-site claims |
| 9 | FSB Center 16 — AA26-194A | 7 | Router config theft; long-dwell critical-infra | Joint multi-nation advisory 13 Jul |
| 10 | IAB remote-access brokerage | 7 | Purchased access short-circuits perimeter | Feeds ransomware affiliates |
Items 1–5 and 8 are bold-priority for ransomware enablement and/or high propagation.
Compromised release branches + OIDC trusted publish produced packages
with valid SLSA provenance. Payload runs on
import, not only install lifecycle. Control gap:
provenance-as-sole-trust, long-lived PATs, no install-time behavioral
block.
Confirmed active exploitation; SSVC active/automatable/total. Internet-facing farms: emergency CU, de-expose, AMSI, hunt webshells and machine keys.
Zero-day exploitation before public advisory. Unpatched internet SMA1000 = emergency. IOC path → re-image, rotate admin + TOTP seeds.
| P | Action | Owner | Deadline | Success metric |
|---|---|---|---|---|
| 1 | SharePoint cluster emergency patch & exposure kill | IT Ops + AppSec | T+4h / T+24h / T+72h | 100% internet-facing patched or offline |
| 2 | SMA1000 hotfix + compromise-assumption workflow | Network + SOC | T+4h | All fixed or removed; IOC review signed |
| 3 | Miasma lockfile/SBOM sweep + secret rotation | AppSec + Eng + IAM | T+4h / T+24h | Zero malicious versions; rotation attestation |
| 4 | FortiSandbox firmware emergency | SecEng + Network | T+24h | Patched or isolated; no public mgmt |
| 5 | Oracle EBS Payments CPU + network restrict | ERP + IT Ops | T+24h | Patched + access-restricted |
| 6 | AD FS July update + DKM ACL remediation | IAM + Windows | T+24h / T+72h | No 1132 warnings; 100% patch compliance |
| 7 | Router hygiene sprint (AA26-194A) | Network Eng | T+72h | Internet SNMP/SMI exposure = 0 |
| 8 | Immutable backup verify + restore drill | IT Ops + CISO | T+72h | Successful restore evidence on ticket |
Grounded in tool-verified primary catalogs (KEV CSV), NVD CVSS/SSVC, and multi-source technical reporting collected 2026-07-17. No dark-web access; no fabricated marketplace listings. Exploit code intentionally omitted. Victim counts and leak-site claims are claims, not independent breach confirmation. Actions are time-bound decision support — verify against your environment before execution.