Unauthorized news on hackers, data breaches, zero-day exploits, ransomware and AI. Original reporting and analysis for people who actually read the source.

News

Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack

Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack

On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed.

The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers at Mandiant and Google Cloud reported it. Until the update is installed, Microsoft recommends enabling AMSI (Antimalware Scan Interface) and switching request body scanning to Full mode.

The second exploited zero-day, CVE-2026-56155, sits in Active Directory Federation Services (ADFS). Insufficient granularity in its access controls lets an already authenticated user escalate to administrative privileges locally. Microsoft's DART team found it.

The third flaw, CVE-2026-50661, was disclosed publicly before the patch, though no exploitation has been seen yet. It bypasses BitLocker encryption: an attacker with physical access to a device can reach the encrypted data. Its finder stayed anonymous.

The remaining fixes break down as 254 elevation of privilege, 145 remote code execution (RCE), 102 information disclosure, 35 denial of service, 17 security feature bypass, and 16 spoofing. Fifty-nine are rated Critical, 48 of them RCE. Affected products include Office, Exchange Server, SQL Server, Windows Media Foundation, the Remote Desktop client, Microsoft Defender, and Hyper-V.

The priority for administrators is clear: patch the two exploited zero-days in SharePoint and ADFS first, and apply the AMSI workaround for SharePoint until the update is deployed.

Based on reporting by BleepingComputer.

Share this article
Share

Written by

Martin
Martin
Editor of Russian Hackers. Unauthorized news on hackers, breaches, exploits and AI.

Read next

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
By Martin

Crypto Theft Fell to $972M in H1 2026, but North Korea's Share Climbed to Two-Thirds

In the first half of 2026, attackers stole about $972 million from the cryptocurrency industry across 207 incidents, according to a mid-year report from analytics firm TRM Labs. The figure is down by more than half from the same period in 2025, when losses were put at $2.3 billion. Despite the overall decline, the share tied to North Korea has actually grown. Analysts attribute roughly $643 million, about 66% of the half-year total, to the Lazarus Group and its TraderTraitor subunit. Almost all
Comic-poster cover: North Korea's Lazarus siphoning crypto as a 2026 chart falls

$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out

In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Cover: Pyongyang skyline in crimson with a formation of fighter jets and the caption Lazarus Group

LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday

Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl
Comic-poster cover: a hacker prying open a Windows registry hive, the LegacyHive zero-day

Ill Bloom: A Weak Seed-Phrase Generator Drained Over $5M From Crypto Wallets

Researchers at Coinspect have disclosed Ill Bloom, a vulnerability in how several cryptocurrency wallets generate their mnemonic recovery phrases (seed phrases). Exploiting it, attackers emptied hundreds of wallets in a single pass and made off with more than $5.1 million. The problem is not one specific wallet but the phrase-generation method used by a handful of lesser known apps, mobile and browser extensions, some dating back to 2018. These wallets relied on a weak random number generator,
Comic-poster cover: a crypto wallet emptied through a broken seed-phrase chain