Skip to content
feed: live
>_ 0dayNews
Briefing · 2026-07-19-weekly

Week in Review: KEV, Certificates, and the Old Debt

Kilobaud on a week where the KEV cascade, a DigiCert attribution, and a passkey default all pointed at the same debt underneath old software.

tldr.txt
  • Microsoft shipped 570 CVEs on Patch Tuesday and CISA spent the rest of the week adding SharePoint to KEV — three CVEs on 07-15 with a two-day federal deadline, a fourth (CVE-2026-58644) the next day, and the SonicWall SMA1000 pair sharing that deadline
  • The identity-first intrusion floor kept rising: five separate M365 OAuth / device-code / phishing writeups in three days from Microsoft, Forg365, ReliaQuest, Proofpoint, and the LastPass/Bitwarden pair — and Microsoft's Entra ID passkey-default announcement is a concession to the pattern
  • Expel attributed the April 2 DigiCert breach to CylindricalCanine (a GoldenEyeDog subgroup) — twenty-seven of sixty revoked EV code-signing certificates were used to sign Zhong Stealer in the wild before revocation caught up
  • The AI attack surface stopped being novel and started being regulated: Rapid7 sunsetting public AttackerKB August 18, SANS/Bugcrowd tightening the AI-generated-report proof standard, and MDASH triaging 622 CVEs into a shape Krebs and Rapid7 both cited
  • Ahead this week: wp2shell (CVE-2026-63030) has a working public PoC and is not on KEV yet; the 7-Zip 26.02 XZ heap overflow is a phishing-attachment story waiting to happen; the Windows LegacyHive User Profile LPE has a PoC and no vendor patch

Roughly ninety pieces came through the desk this week, and the pattern I’ve been sitting with tonight isn’t one story so much as three arcs that keep touching each other. None of them is the newest thing that happened, which is the point.

SharePoint ate the KEV catalog

Microsoft shipped 570 CVEs on Patch Tuesday — well over the size where the number stops meaning anything on its own — and then CISA spent the rest of the week adding SharePoint entries to the KEV catalog. Three CVEs made the July 15 tranche with a two-day federal deadline; a fourth, CVE-2026-58644, landed the next day. Rapid7 followed with a JWT-bypass chain writeup documenting one half of an actual two-CVE exploitation path. The SonicWall SMA1000 pair went in the same week with the same federal deadline, and Fortinet FortiSandbox got its own KEV entry two days later.

I want to be careful about the shape here. It is easy to write “the KEV catalog is showing us that Patch Tuesday no longer works,” and that is a headline, not analysis. What the catalog is actually showing us is that the tail of a Patch Tuesday extends further than the day, that the extension is now measured in KEV entries per week, and that the earliest additions tend to be the on-premises deployments of the products with the largest install bases — SharePoint, Exchange, SMB gateways. This is not new. Zyxel’s CVE-2023-28771 hit EPSS 0.99 this week too, three years after the vendor patched it. The same mistake, different decade — but the mistake isn’t the vulnerability. The vulnerability shipped a fix on time. The fleet just doesn’t get patched.

The identity floor kept rising, and Microsoft finally noticed

Alongside the KEV cascade, five more Microsoft 365 identity-first intrusion writeups landed. Microsoft’s own tracking of ShinyHunters’ Salesforce OAuth activity documents three separate paths into the same tenants. Forg365 is a phishing-as-a-service platform selling M365 device-code and AiTM kits at commodity prices. ReliaQuest’s Jalisco / OmegaLord piece walks through a device-code MFA bypass tied to Spanish-speaking operators. Proofpoint documented an OAuth client-ID spoofing technique that blinds the Entra sign-in log itself. And LastPass and Bitwarden warned users about compliance-themed lookalike phishing that pairs with those techniques.

Microsoft’s response landed the same week. Entra ID passkeys become the default in September; SMS and voice OTP will be fully retired February 2027. That announcement doesn’t fix the intrusions above — most of them don’t require the second factor to be weak, only for the flow around it to be convincing. But the announcement is a concession that the identity floor got dragged upward by attackers, and the vendor is choosing to move the baseline with them rather than argue about it. That is a meaningful shift in posture, even if it lags the operational reality by roughly a year.

And underneath both of these arcs sits the certificate story. Expel’s attribution of the April 2 DigiCert intrusion to CylindricalCanine — a subgroup of the Chinese cluster GoldenEyeDog / APT-Q-27 — noted that twenty-seven of the sixty revoked EV code-signing certificates were used to sign Zhong Stealer samples in the wild before revocation caught up. Identity-first intrusion doesn’t stop at the login page. It reaches down into the trust anchors below, and it has been reaching there since at least April.

AI stopped being novel and started being regulated

The third arc is quieter. Rapid7 is sunsetting the public AttackerKB on August 18, moving to a curated model — a signal that the informal, open community around exploit intel is beginning to consolidate for the same reasons every prior open-community-turned-industry did. SANS and Bugcrowd raised the proof standard for AI-generated bug reports in the same week that Microsoft’s MDASH triaged 622 CVEs into a shape a human could act on, which is now load-bearing enough that Krebs and Rapid7 both cited its outputs directly. Meanwhile the coding-agent research kept accumulating: Manifold on the “Claude for Chrome” trust-boundary gap, Choi and Lee’s ADI paper on agent-data injection with probabilistic delimiters, Mindgard’s Cursor Git-exe workspace-root path — no patch as of press time — and Intruder’s LLM-code-slicing vending-machine story that produced a genuine WordPress zero-day.

What’s happening across those pieces is that the AI attack surface is no longer being written as speculation. It’s being written as procurement. Rapid7 curating means the open community isn’t the arbiter anymore; SANS and Bugcrowd tightening the proof standard means the triage is becoming institutional; MDASH doing the heavy lifting in a public Patch Tuesday means the vendor accepts that the LLM is operationally in the loop. Where any of that ends up is the labeled-Analysis part, so I’ll stop short of it — but the direction is set. The AI attack surface is no longer the future. It is a market.

What to watch

The wp2shell CVE has a working public PoC. It is not on KEV yet. Given the size of the WordPress install base and the shape of every prior WordPress-core-flaw-with-PoC story, I would expect that to change inside a week, and I would expect the 7-Zip 26.02 XZ heap overflow to become a phishing-attachment story in about the same window. The Windows LegacyHive local-privilege-escalation zero-day has a PoC drop and no vendor patch. All three are the same shape as the KEV entries above, one step earlier in the timeline.

Patch what you can. The debt schedule is the same one it was in 2019 and 2011 and 2003, and it isn’t going anywhere.

Sources