Cyber threat intelligence · CISO Advisory product run

Daily CISO Threat Sweep — 2026-07-17

Board-ready daily situational awareness · Verified facts only · Action-forced

Overall posture: Severe
Run date
2026-07-17
Generated
15:55 UTC-class
Window
24–48h critical · 7–14d blast
Classification
Portfolio sample · public
Full PDF (13 pp) Agent repository

1 · Executive summary

The enterprise threat picture on 2026-07-17 is Severe. The last 72 hours compressed multiple confirmed in-the-wild exploitation events: a dense KEV delta (critical batches 14–16 July), dual Microsoft zero-days in SharePoint and AD FS, unauthenticated RCE paths on FortiSandbox and SonicWall SMA1000, and a critical unauthenticated Oracle Payments takeover under active exploitation. Concurrently, the Miasma / Shai-Hulud npm worm lineage delivered a canary wave (miasma-train-p1) that abused trusted CI/CD publishing and valid SLSA provenance—bypassing many “provenance-only” supply-chain defenses.

Ransomware-as-a-Service remains industrially active (The Gentlemen, Qilin, Akira). Multi-agency joint advisory AA26-194A re-confirmed long-running FSB Center 16 (Berserk Bear / Energetic Bear / Ghost Blizzard / Static Tundra) exploitation of weak SNMP and edge routers across critical infrastructure.

Top decisions required today

  1. Emergency patch / isolate internet-facing SharePoint, SonicWall SMA1000, FortiSandbox, and Oracle EBS Payments; treat unpatched internet exposure as presumed compromise until forensically cleared.
  2. Force AD FS DKM ACL audit + remediation and identity session/token review for any federated estate still on AD FS.
  3. Lockfile / SBOM sweep for malicious @asyncapi/* versions and Miasma drop paths; rotate developer, CI, cloud, and registry credentials on any hit.
  4. Router hygiene sprint per AA26-194A: kill SNMPv1/v2c defaults, Smart Install, and internet-exposed management planes.
  5. Ransomware readiness: immutable backup integrity + restore drill; edge VPN/RDP exposure inventory.

Explicit silence (last 48h)

2 · Top threats

# Name Risk Business impact Why today
1 Miasma / Shai-Hulud · miasma-train-p1 (AsyncAPI npm) 10 Dev + CI secrets → cloud/identity takeover at worm scale Valid provenance + on-import RAT; 130+ secret types
2 CVE-2026-58644 SharePoint deserialization RCE 9 Full on-prem collab compromise; ransomware staging KEV 16 Jul; CVSS 9.8; due 19 Jul; multi-CVE cluster
3 CVE-2026-15409/15410 SonicWall SMA1000 9 Remote access foothold → TOTP theft → lateral Zero-day pre-disclosure; KEV due 17 Jul; CVSS 10.0 SSRF
4 CVE-2026-25089/39808 FortiSandbox unauth OS inj. 9 Security appliance RCE; pivot into security stack KEV 16 Jul; CVSS 9.8; public PoC history
5 CVE-2026-46817 Oracle EBS Payments takeover 9 Unauth HTTP compromise of payment processing KEV 15 Jul; CVSS 9.8; due 18 Jul; active since late June
6 SharePoint auth/deserialization cluster 8 EoP / RCE chain on enterprise portals Internet-facing farms highest risk
7 CVE-2026-56155 AD FS DKM ACL EoP 8 Token-signing key risk → federated impersonation Identity control-plane blast radius
8 The Gentlemen / Qilin / Akira RaaS 8 Revenue stop, data leak, regulatory exposure Continuous mid-July leak-site claims
9 FSB Center 16 — AA26-194A 7 Router config theft; long-dwell critical-infra Joint multi-nation advisory 13 Jul
10 IAB remote-access brokerage 7 Purchased access short-circuits perimeter Feeds ransomware affiliates

Items 1–5 and 8 are bold-priority for ransomware enablement and/or high propagation.

3 · First-principles (top 3 condensed)

Miasma / Shai-Hulud — miasma-train-p1

Supply chain · T1195 · atomic risk 10

Compromised release branches + OIDC trusted publish produced packages with valid SLSA provenance. Payload runs on import, not only install lifecycle. Control gap: provenance-as-sole-trust, long-lived PATs, no install-time behavioral block.

SharePoint deserialization cluster

CWE-502 · KEV · atomic risk 9

Confirmed active exploitation; SSVC active/automatable/total. Internet-facing farms: emergency CU, de-expose, AMSI, hunt webshells and machine keys.

SonicWall SMA1000 SSRF + code injection

CVSS 10.0 · due 2026-07-17 · atomic risk 9

Zero-day exploitation before public advisory. Unpatched internet SMA1000 = emergency. IOC path → re-image, rotate admin + TOTP seeds.

4 · Prioritized action plan (excerpt)

P Action Owner Deadline Success metric
1 SharePoint cluster emergency patch & exposure kill IT Ops + AppSec T+4h / T+24h / T+72h 100% internet-facing patched or offline
2 SMA1000 hotfix + compromise-assumption workflow Network + SOC T+4h All fixed or removed; IOC review signed
3 Miasma lockfile/SBOM sweep + secret rotation AppSec + Eng + IAM T+4h / T+24h Zero malicious versions; rotation attestation
4 FortiSandbox firmware emergency SecEng + Network T+24h Patched or isolated; no public mgmt
5 Oracle EBS Payments CPU + network restrict ERP + IT Ops T+24h Patched + access-restricted
6 AD FS July update + DKM ACL remediation IAM + Windows T+24h / T+72h No 1132 warnings; 100% patch compliance
7 Router hygiene sprint (AA26-194A) Network Eng T+72h Internet SNMP/SMI exposure = 0
8 Immutable backup verify + restore drill IT Ops + CISO T+72h Successful restore evidence on ticket

5 · Strategic continuity

6 · Limitations

Grounded in tool-verified primary catalogs (KEV CSV), NVD CVSS/SSVC, and multi-source technical reporting collected 2026-07-17. No dark-web access; no fabricated marketplace listings. Exploit code intentionally omitted. Victim counts and leak-site claims are claims, not independent breach confirmation. Actions are time-bound decision support — verify against your environment before execution.