[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fcMK9VocKjjRiVy5bhbdjBbZU4wIWvbLTlvAcModIhZY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":41},"3964101b-0c7e-4455-856e-1ec4182106bc","record-breaking-patch-tuesday-622-flaws-including-two-actively-exploited-zero-days","d6d2e863-0dc8-4768-8e9a-bdbae800f383","Record-Breaking Patch Tuesday: 622 Flaws Including Two Actively Exploited Zero-Days","Microsoft's largest-ever Patch Tuesday highlights the accelerating pace of vulnerability discovery, now turbocharged by AI-assisted research. Two of the patched flaws — in Active Directory Federation Services and SharePoint Server — were actively exploited in the wild, meaning organizations that delayed patching were exposed to real-world attacks. The publicly disclosed BitLocker bypass further underscores that encryption controls can be undermined when underlying OS vulnerabilities go unpatched. This event illustrates that patch management is not a monthly checkbox but a continuous, risk-prioritized discipline, especially for identity and collaboration infrastructure that sits at the heart of enterprise environments.","**Immediate actions:**\n- Apply July 2026 Patch Tuesday updates immediately, prioritizing the two actively exploited AD FS and SharePoint zero-days above all others.\n- Audit all BitLocker-protected devices and verify firmware\u002FOS patch levels to mitigate the disclosed bypass risk.\n- Isolate or place compensating controls (e.g., network ACLs, WAF rules) around unpatched AD FS and SharePoint instances until patches can be deployed.\n\n**Long-term improvements:**\n- Establish a tiered emergency patching SLA (e.g., critical\u002Fzero-day ≤ 24 hours, high ≤ 7 days, medium ≤ 30 days) and enforce it via policy.\n- Maintain a continuously updated asset inventory that maps software versions to CVEs, enabling rapid identification of affected systems when advisories drop.\n- Integrate AI-assisted vulnerability scanning and threat intelligence feeds to proactively detect exposures before they are exploited.\n\n**Detection measures:**\n- Deploy SIEM rules and EDR detections tuned to exploitation indicators for AD FS token forgery and SharePoint remote code execution patterns.\n- Enable detailed logging on AD FS servers and SharePoint farms and forward logs to a centralized SIEM for anomaly alerting.\n- Schedule weekly vulnerability scan runs post-Patch-Tuesday to confirm patch deployment success and identify any stragglers.",[12,13,14,15,16,17,18,19,20],"CIS Control 7 – Continuous Vulnerability Management","CIS Control 2 – Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4 – Guide to Enterprise Patch Management","NIST SI-2 – Flaw Remediation","NIST RA-5 – Vulnerability Monitoring and Scanning","NIST SC-28 – Protection of Information at Rest (BitLocker context)","ITIL Change Management – Emergency Change Process","MITRE ATT&CK T1190 – Exploit Public-Facing Application","MITRE ATT&CK T1548 – Abuse Elevation Control Mechanism (BitLocker bypass)","published","2026-07-15T12:20:39.080599+00:00","2026-07-15T12:20:39.017+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fhackread.com\u002Fmicrosoft-july-2026-patch-tuesday-fixes-zero-days\u002F","microsoft-s-july-2026-patch-tuesday-fixes-622-flaws-and-2-exploited-zero-days-9a6bc9","Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days",[29,35],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[42],{"id":43,"date":44,"edition":45,"title":46,"audio_url":47},"8e21cb45-320b-4bd6-aea9-af9442197aa8","2026-07-15","afternoon","ThreatNoir Afternoon Brief — July 15","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-15\u002Fthreatnoir-afternoon-brief-2026-07-15.mp3"]