exploitation

AppWizard
July 23, 2026
GitHub will reject command-line support bundle uploads from outdated versions of GitHub Enterprise Server lacking security patches starting August 18, 2026. The npm package @copilot-mcp/apex has been identified as a post-install dropper that installs a macOS infostealer, phishing for sensitive information and maintaining a connection to an attacker's server. A rogue extension on the Microsoft Visual Studio Code marketplace, "Markdown All Pro," impersonates a legitimate tool and opens a backdoor after installation. A phishing campaign targeting Portuguese users delivers the Lampion banking malware, which has been active since 2019. DoubleVerify reports a rise in "AfterCall" apps that exploit user permissions for ad fraud. The GhostCommit attack method hides malicious instructions within PNG images in pull requests. The U.S. government has updated its advisory on Iranian-affiliated cyber activity targeting operational technology devices. An Android app posing as a civil defense alert system has been found to contain malware for data harvesting. An Iranian threat actor is distributing MarkiRAT malware through fake applications. An analysis of 28 AI-coded applications revealed 434 vulnerabilities, prompting Cisco to introduce Antares to identify vulnerabilities in codebases. A Russian-speaking threat actor is dismantling guardrails on AI models to create offensive tools.
Winsage
July 23, 2026
Windows 11 is installed on 78.8% of Windows computers, while 16.9% of users remain on Windows 10. Microsoft ended support for Windows 10 in October 2025, with an extension until 2027. Windows 10 has 1,903 active Common Vulnerabilities and Exposures (CVEs), 2.9 times more than Windows 11, which has 652 CVEs. Of the active CVEs on Windows 10, 66.6% are classified as high or critical risk, with 2.4% actively exploited. Small businesses show the most significant lag in upgrading, with 21.4% still using Windows 10, while two-thirds of large enterprises have moved to Windows 11. The cost of upgrading is a primary barrier for smaller companies.
Winsage
July 22, 2026
Approximately 17% of all Windows client devices are still running Windows 10, equating to about one in six machines. Windows 11 accounts for 78% of Windows devices, with third-party trackers indicating it surpassed 70% of desktop share as of February 2026. Official support for Windows 10 ended in October 2025, but Microsoft’s Extended Security Updates (ESU) program will provide patches until October 2027 for eligible devices. A typical Windows 10 device has an average of 1,903 active security vulnerabilities, nearly three times the 652 CVE-tracked flaws found on a Windows 11 machine. 66% of Windows 10 vulnerabilities are classified as "high" or "critical." Small and medium enterprises have 21.4% of their Windows devices still on Windows 10, while larger enterprises have 16.6%. The healthcare and pharmaceuticals sectors have 23% of devices on Windows 10, followed by consumer and retail at 22%, and manufacturing at 18%. Lansweeper is urging organizations to enroll in the ESU program and address reasons for remaining on Windows 10 as 2026 approaches.
Winsage
July 18, 2026
Approximately 16.9% of Windows client devices are still using Windows 10, which has three times more active Common Vulnerabilities and Exposures (CVEs) than Windows 11, totaling 1,903 compared to 652. Two-thirds of the vulnerabilities in Windows 10 are classified as high or critical, with an exploitable rate 1.7 times greater than in Windows 11. Migration to Windows 11 is not primarily hindered by technical limitations, as only a small fraction of Windows 10 devices do not meet the hardware requirements. Additionally, nearly 20% of monitored Windows devices are running end-of-life operating systems, including Windows 7, 8.1, and XP.
Winsage
July 16, 2026
Microsoft has released its July 2026 Patch Tuesday updates, addressing 570 new security vulnerabilities, bringing the total for the month to over 620. The cumulative count of vulnerabilities patched this year has reached 1,380, exceeding the total of 1,250 for the entire year of 2020. Over 400 vulnerabilities are related to various versions of Windows, and the Windows 10 Extended Security Update program has been extended until October 12, 2027. Notable vulnerabilities include CVE-2026-56155 in Active Directory Federation Services, which allows attackers to gain administrator rights, and several critical Remote Code Execution vulnerabilities, including CVE-2026-57092 in Hyper-V and CVE-2026-56190 in Remote Desktop Protocol. Microsoft has also patched 97 vulnerabilities in Office products, with 17 classified as critical RCE vulnerabilities, and four vulnerabilities in Exchange Server, including CVE-2026-55008. The latest Microsoft Edge update addresses 27 vulnerabilities related to Chromium, and a vulnerability in Minecraft Bedrock servers has been patched.
AppWizard
July 16, 2026
In October 2024, a judge ordered Google to allow third-party app stores on the Android platform. Google has now decided to comply with this ruling, retracting its motion to amend the injunction. Changes are set to be implemented starting July 22, 2026, allowing third-party app stores to operate within the Play Store in the U.S. Developers' app listings will automatically be available to these stores unless they opt out. Third-party stores can offer apps from the Play Catalog if they pay an annual fee and meet certain criteria. However, questions remain regarding the integration of Play Protect security features and the assessment of third-party store security.
Winsage
July 14, 2026
Microsoft's July 2026 security update addresses 622 vulnerabilities, with 57 classified as "critical." Two critical vulnerabilities, CVE-2026-56155 (Active Directory Federation Services) and CVE-2026-56164 (Microsoft SharePoint Server), have been exploited in the wild. The critical vulnerabilities include 48 remote code execution (RCE) vulnerabilities, seven elevation of privilege (EoP) vulnerabilities, one spoofing vulnerability, and one security feature bypass vulnerability. RCE vulnerabilities affect various Microsoft services, including Windows Media, Microsoft Office, and SQL Server, with eleven rated as "more likely" to be exploited. Additional important vulnerabilities include CVE-2026-49170, CVE-2026-49795, and CVE-2026-50325. Talos is releasing a new Snort ruleset to detect these vulnerabilities, and Cisco Security Firewall customers are advised to update their ruleset.
Search