July 20, 2026 Emerging Threats Weekly
This week’s briefing covers:
00:00 – Intro
00:48 [VULNERABILITY] Microsoft July Patch Cycle Expands Exposure Across Identity, SharePoint and Endpoint Security
Microsoft’s July 2026 security update cycle was unusually large with 570 flaws fixed in the Patch Tuesday release, including two actively exploited zero-days and one publicly disclosed zero-day.
03:07 [THREAT ACTOR] Russian APTs Target Critical Infrastructure Routers
The United States and allied agencies warned that Russian state-sponsored APT actors are targeting networking devices, particularly routers, to compromise critical infrastructure networks worldwide. The activity focuses on poorly secured devices and uses a combination of scanning, misconfiguration abuse and exploitation of known vulnerabilities.
06:19 [VULNERABILITY] SonicWall SMA1000 Zero-Days Expose Remote Access Infrastructure
SonicWall has warned that attackers are actively exploiting two SMA1000 vulnerabilities in zero-day attacks targeting remote access infrastructure. The affected appliances are frequently exposed to the internet and often sit close to authentication services and privileged network access paths, making them attractive targets for initial access operations.
08:56 [CAMPAIGN] Fake GitHub Repositories Distribute Infostealer Malware at Scale
Researchers have identified a campaign involving nearly 300 fake GitHub repositories impersonating legitimate software vendors, security companies, cryptocurrency services, developer tools, financial applications, secure email providers, macOS utilities and gaming software.
11:27 [SOCIAL ENGINEERING] New Microsoft 365 Phishing Kits Bypass MFA Controls
Two newly identified phishing kits, Jalisco and OmegaLord, were reported targeting Microsoft 365 accounts. The techniques designed to defeat or bypass multifactor authentication represent a shift from password theft to cloud manipulation.
13:22 [MALWARE] CrashStealer Targets macOS Credentials and Crypto Wallets
Two newly identified phishing kits, Jalisco and OmegaLord, were reported targeting Microsoft 365 accounts. The techniques designed to defeat or bypass multifactor authentication represent a shift from password theft to cloud manipulation.
Dive deeper:
Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report
Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing
Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto
Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist
Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber
Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports
Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber
#krollcyber #threatintelligence #cyberthreats