Microsoft, Splunk, Fortinet, TP-Link, Dell and AWS: Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories

Microsoft, Splunk, Fortinet, TP-Link, Dell and AWS: Weekly Cyber Security Newsletter Bulletin – EY Breach, Wpzshell Exploit, Notepad++ Flaws +20 Stories

Cybersecurity Roundup: Zero-Days, AI Threats, and Massive Exploits Dominate July 2026

This week’s cybersecurity landscape underscored the relentless expansion of attack surfaces, with high-impact vulnerabilities, active exploits, and emerging threats targeting everything from enterprise identity systems to AI-driven workflows.

Microsoft’s Patch Tuesday Highlights Critical Exploits
Microsoft’s July 2026 Patch Tuesday addressed 570 vulnerabilities, including two actively exploited zero-days:

  • CVE-2026-56164 (SharePoint Server): Allows remote code execution (RCE) via crafted requests.
  • CVE-2026-56155 (Active Directory Federation Services): Enables privilege escalation, posing risks to enterprise identity infrastructure.
    A BitLocker bypass bug (publicly disclosed) and a Windows User Profile Service exploit (LegacyHive PoC) further exposed post-patch risks, allowing standard users to hijack registry hives.

WordPress Under Siege: 500M Sites at Risk
A pre-authentication RCE flaw (wp2shell, CVE-2026-60137/CVE-2026-63030) in WordPress’s REST API batch-route functionality threatens over 500 million sites, enabling unauthenticated takeovers via SQL injection. The vulnerability remains unpatched for many deployments.

Big Four Breach: EY Confirms Client Data Exposure
Ernst & Young disclosed a breach between March 28 and April 12, 2026, where an unauthorized third party accessed its IT support ticket platform, exfiltrating client tax and investment documents. Detection lagged nearly three weeks, raising concerns about incident response in professional services firms.

AI Systems Emerge as New Attack Vectors
Adversaries are increasingly targeting AI integrations:

  • Claude for Chrome: A flaw in the browser extension exposed users to potential data theft.
  • GhostCommit: A novel technique hides malicious AI prompts within code commits, manipulating coding assistants undetected.
  • GPT-5/6 Exploit Chain: Researchers demonstrated an attack pairing AI models ("Sol") with Chrome vulnerabilities, signaling a shift toward AI-assisted cyberattacks.

Malicious Extensions and Supply Chain Risks

  • ModHeader: A popular Chrome/Edge extension (1.6M installs) was removed after dormant code was found exfiltrating browsing history to an external server.
  • 7-Zip: A critical flaw enables code execution via crafted archives, impacting widespread file-handling workflows.
  • Notepad++ v8.9.7: Patched multiple high-risk bugs, including PowerShell command injection and Zip Slip path traversal.

Enterprise and Cloud Threats Persist

  • Dell: Two separate issues emerged BIOS firmware flaws exposing admin passwords and a July 2026 update causing unexpected laptop shutdowns.
  • Fortinet/F5/Splunk: Vendors released patches for 10+ vulnerabilities, including Nginx-related flaws (F5) and data-integrity risks (Splunk).
  • AWS Cost Explorer: A bug introduced security and data-exposure risks for cloud billing monitoring.
  • TP-Link Cameras: A flaw could allow attackers to compromise device functionality or access video feeds.

The week’s disclosures reflect a broadening threat landscape, where legacy systems, AI tools, and third-party integrations remain prime targets for exploitation.

Source: https://cybersecuritynews.com/weekly-cyber-security-newsletter-bulletin/

Dell Technologies cybersecurity rating report: https://www.rankiteo.com/company/delltechnologies

Microsoft Security Response Center cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security-response-center

Amazon Web Services (AWS) cybersecurity rating report: https://www.rankiteo.com/company/amazon-web-services

Fortinet cybersecurity rating report: https://www.rankiteo.com/company/fortinet

Splunk cybersecurity rating report: https://www.rankiteo.com/company/splunk

TP-Link Systems Inc. cybersecurity rating report: https://www.rankiteo.com/company/tp-link

"id": "DELMICAMAFORSPLTP-1784478360",
"linkid": "delltechnologies, microsoft-security-response-center, amazon-web-services, fortinet, splunk, tp-link",
"type": "Vulnerability",
"date": "3/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Software',
                        'name': 'Microsoft',
                        'type': 'Technology'},
                       {'customers_affected': '500M sites',
                        'industry': 'CMS',
                        'name': 'WordPress',
                        'type': 'Technology'},
                       {'industry': 'Accounting/Consulting',
                        'name': 'Ernst & Young (EY)',
                        'type': 'Professional Services'},
                       {'industry': 'Hardware',
                        'name': 'Dell',
                        'type': 'Technology'},
                       {'industry': 'Cybersecurity',
                        'name': 'Fortinet',
                        'type': 'Technology'},
                       {'industry': 'Networking',
                        'name': 'F5',
                        'type': 'Technology'},
                       {'industry': 'Data Analytics',
                        'name': 'Splunk',
                        'type': 'Technology'},
                       {'industry': 'Cloud Services',
                        'name': 'AWS',
                        'type': 'Technology'},
                       {'industry': 'Networking/IoT',
                        'name': 'TP-Link',
                        'type': 'Technology'}],
 'attack_vector': ['Crafted requests',
                   'REST API batch-route functionality',
                   'Malicious extensions',
                   'AI prompts in code commits',
                   'Firmware flaws',
                   'Third-party platform access'],
 'data_breach': {'data_exfiltration': True,
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Client tax and investment '
                                              'documents',
                                              'Browsing history',
                                              'Admin passwords']},
 'date_publicly_disclosed': '2026-07',
 'description': 'This week’s cybersecurity landscape underscored the '
                'relentless expansion of attack surfaces, with high-impact '
                'vulnerabilities, active exploits, and emerging threats '
                'targeting everything from enterprise identity systems to '
                'AI-driven workflows.',
 'impact': {'data_compromised': ['Client tax and investment documents',
                                 'Browsing history',
                                 'Admin passwords',
                                 'Video feeds'],
            'operational_impact': ['Unexpected laptop shutdowns',
                                   'Device functionality compromise'],
            'systems_affected': ['SharePoint Server',
                                 'Active Directory Federation Services',
                                 'WordPress sites',
                                 'EY IT support ticket platform',
                                 'Claude for Chrome',
                                 'Chrome/Edge (ModHeader extension)',
                                 '7-Zip',
                                 'Notepad++',
                                 'Dell laptops',
                                 'Fortinet/F5/Splunk systems',
                                 'AWS Cost Explorer',
                                 'TP-Link cameras']},
 'references': [{'source': 'Microsoft Patch Tuesday'},
                {'source': 'WordPress REST API vulnerability disclosure'},
                {'source': 'EY breach disclosure'},
                {'source': 'AI system exploit research'}],
 'response': {'remediation_measures': ['Patches released by Microsoft, '
                                       'WordPress, Notepad++, Dell, Fortinet, '
                                       'F5, Splunk']},
 'title': 'Cybersecurity Roundup: Zero-Days, AI Threats, and Massive Exploits '
          'Dominate July 2026',
 'type': ['Zero-day exploit',
          'Data breach',
          'RCE',
          'Privilege escalation',
          'AI-assisted attack',
          'Supply chain attack'],
 'vulnerability_exploited': ['CVE-2026-56164',
                             'CVE-2026-56155',
                             'CVE-2026-60137',
                             'CVE-2026-63030',
                             'BitLocker bypass bug',
                             'Windows User Profile Service exploit (LegacyHive '
                             'PoC)',
                             '7-Zip archive flaw',
                             'Notepad++ PowerShell command injection',
                             'Notepad++ Zip Slip path traversal',
                             'Dell BIOS firmware flaws',
                             'TP-Link camera flaw']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.