
Hosted by Johannes Ullrich · EN

German Federal Information Security Office Analyzes Windows Hello for Businesshttps://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.htmlhttps://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7 NGINX Vulnerabilityhttps://my.f5.com/manage/s/article/K000162097 7-Zip XZ Decompression CVE-2026-14266https://www.zerodayinitiative.com/advisories/ZDI-26-444/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

DShield SIEM Updatehttps://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156 Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivershttps://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875 Zoom Account Takeover Patchhttps://www.zoom.com/en/trust/security-bulletin/zsb-26014/ Forgotten UEFI shims undermining Secure Boothttps://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Herehttps://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154 LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerabilityhttps://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive Progress confirms ShareFile zero-day flaw behind Storage Zone shutdownhttps://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/ xAI/Grok Exfiltrating Data and Secretshttps://cereblab.com My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Someone Is Scanning for Your MCP Servers and AI Assistant Credentialshttps://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150 Improve Router Hygiene to Protect Against Russian State-Sponsored Targetinghttps://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a OAuth Client ID Spoofinghttps://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854https://www.veeam.com/kb4869 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Progress Sharefile Emergency Shutdown Noticehttps://status.sharefile.comhttps://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/ U-Boot Vulnerabilitieshttps://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification Nightmare Eclipse Releases Next Microsoft Defender Exploithttps://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/ Cisco Increases Patch Cadencehttps://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130 Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28https://support.apple.com/en-us/125615 Google Chrome Updatehttps://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/ My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

My Stack Simulator https://isc.sans.edu/diary/My%20Stack%20Simulator/33138 RootAsRolehttps://github.com/LeChatP/RootAsRole Hoymiles Inverter Vulnerabilityhttps://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf Git Hash Chain Malleabilityhttps://arxiv.org/abs/2607.02820 My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

More Odd DNS Records: NIMLOChttps://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128 From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/ Tenda firmware (multiple versions) contains hidden authentication backdoorhttps://kb.cert.org/vuls/id/213560 GitLost: GitHub AI Agent Leakhttps://noma.security/wp-content/uploads/GitLostWorkflow_2.gif My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

RCS and DNS: The NAPTR Recordhttps://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124 OpenSSH 10.4 releasedhttps://seclists.org/oss-sec/2026/q3/62 Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139https://www.beyondtrust.com/trust-center/security-advisories/bt26-03 PolinRider: North Korea-Linked Supply Chain Campaignhttps://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich

Apple Updated Patch Policyhttps://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/ T3MP3ST multi-agent offensive-security frameworkhttps://github.com/elder-plinius/T3MP3ST Seven FatFs bugs, one very large blast radiushttps://www.runzero.com/blog/fatfs-bugs/ OpenWRT Releases v25.12.5https://github.com/openwrt/openwrt/releases My Upcoming Classeshttps://www.sans.org/profiles/dr-johannes-ullrich