{"id":106666,"date":"2026-07-15T10:53:20","date_gmt":"2026-07-15T10:53:20","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/106666\/"},"modified":"2026-07-15T10:53:20","modified_gmt":"2026-07-15T10:53:20","slug":"ai-driven-bug-hunting-fuels-record-microsoft-patch-tuesday","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/106666\/","title":{"rendered":"AI-driven bug hunting fuels record Microsoft Patch Tuesday"},"content":{"rendered":"<p>Microsoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). <\/p>\n<p>The release was once again followed by Nightmare Eclipse <a href=\"https:\/\/git.projectnightcrawler.dev\/NightmareEclipse\/LegacyHive\" target=\"_blank\" rel=\"nofollow noopener\">publishing<\/a> a stripped down proof-of-concept exploit for an unpatched Windows elevation of privilege (EoP) vulnerability, which the researcher dubbed LegacyHive.<\/p>\n<p>Vulnerabilities of note<\/p>\n<p>CVE-2026-56155 is an EoP flaw affecting Active Directory Federation Services (ADFS), and has been spotted being exploited in the wild by Microsoft\u2019s incident responders. <\/p>\n<p>Fixes for it <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-56155\" target=\"_blank\" rel=\"nofollow noopener\">have been bundled<\/a> into Windows and Windows servers updates, and Microsoft also <a href=\"https:\/\/support.microsoft.com\/en-us\/servicing\/os\/windows\/docs\/2026\/07\/kb5121391-cve-2026-56155-ad-fs-dkm-container-acl-hardening\" target=\"_blank\" rel=\"nofollow noopener\">announced<\/a> it\u2019s started hardening the Access Control List (ACL) on the AD FS Distributed Key Manager container.<\/p>\n<p>\u201c[This vulnerability] stems from insufficient access-control granularity and does require local access and low privileges to start, but AD FS is exactly the kind of identity infrastructure attackers love to pivot through once they\u2019re in. It can also be paired with an RCE as we often see in ransomware. Test and deploy this patch quickly,\u201d <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2026\/7\/14\/the-july-2026-security-update-review\" target=\"_blank\" rel=\"nofollow noopener\">commented<\/a> Dustin Childs, head of threat awareness at TrendAI\u2019s Zero Day Initiative.<\/p>\n<p>CVE-2026-56164 is an EoP flaw found in Microsoft SharePoint Server that has been reported by Google\u2019s incident responders and an anonymous researcher. It\u2019s remotely exploitable in low-complexity attacks, and attackers are already taking advantage of it.<\/p>\n<p>While enabling the Antimalware Scan Interface (AMSI) feature on SharePoint servers is <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2026-56164\" target=\"_blank\" rel=\"nofollow noopener\">noted<\/a> as a possible mitigation, implementing security updates is the better option, especially because they fix additional SharePoint remote code execution vulnerabilities (CVE-2026-50522 and CVE-2026-58644) and a critical security feature bypass flaw (CVE-2026-55040). <\/p>\n<p>\u201cDiscovered by Rapid7 Senior Principal Security Researcher Stephen Fewer, and published (\u2026) in coordination with Microsoft, [CVE-2026-55040] is the first in a pair of exploits which, when chained together, can lead to unauthenticated remote code execution against a vulnerable SharePoint server,\u201d commented Adam Barnett, Principal Software Engineer at Rapid7.<\/p>\n<p>The second vulnerability in the full RCE chain remains embargoed for now, and Microsoft is expected to publish patches for it in August 2026, he <a href=\"https:\/\/www.rapid7.com\/blog\/post\/em-patch-tuesday-july-2026\/\" target=\"_blank\" rel=\"nofollow noopener\">added<\/a>.<\/p>\n<p>In other developments, the US Cybersecurity and Infrastructure Security Agency (CISA) has <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/14\/cisa-urges-sharepoint-hardening-after-new-exploitations\" target=\"_blank\" rel=\"nofollow noopener\">urged<\/a> organizations running SharePoint servers to apply additional hardening measures, in light of the fact that attackers are also exploiting two recently patched vulnerabilities (CVE-2026-32201 and <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/05\/26\/sharepoint-vulnerability-cve-2026-45659\/\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-45659<\/a>).<\/p>\n<p>CVE-2026-50661 is a Windows BitLocker security feature bypass vulnerability that has been disclosed but not (yet) actively exploited.  <\/p>\n<p>\u201cWhile not confirmed at this time, this CVE may be the patch for GreatXML, a BitLocker bypass exploit released by the Nightmare-Eclipse persona,\u201d Crowdstrike <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/patch-tuesday-analysis-july-2026\/\" target=\"_blank\" rel=\"nofollow noopener\">noted<\/a>.<\/p>\n<p>Security patching in the age of AI-assisted vulnerability discovery<\/p>\n<p>The flood of new vulnerabilities was expected and <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/10\/microsoft-windows-update-deployment-timelines\/\" rel=\"nofollow noopener\" target=\"_blank\">pre-announced<\/a>, as Microsoft recently confirmed it\u2019s been using AI to speed up internal discovery of software vulnerabilities. <\/p>\n<p>The company also noted that other security researchers and attackers have been doing the same.<\/p>\n<p>\u201cIf you\u2019re not delivering critical quality updates with security fixes until a couple of weeks after they\u2019ve been issued, that\u2019s ample time for attackers using AI to find and exploit known security gaps,\u201d Microsoft said. <\/p>\n<p>\u201cTo address this, we\u2019ve updated our recommendations for deploying Windows updates to less than three days as the deferral period for quality updates, setting deadlines for those updates to zero or one day, and the update grace period to a maximum of two days.\u201d<\/p>\n<p>Satnam Narang, senior staff research engineer at Tenable, also pointed out that the state of the Exploitability Index (how likely a vulnerability is to be exploited) must shift with the machine speed of discovery. <\/p>\n<p>\u201cFor example, Microsoft originally tagged CVE-2026-45659, a SharePoint vulnerability, as exploitation less likely. However, the vulnerability was added to the CISA KEV on July 1,\u201d he noted. <\/p>\n<p>\u201cAnthropic\u2019s Red Team\u2019s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated \u2018Exploitation Less Likely\u2019 or \u2018Exploitation Unlikely.\u2019 What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.\u201d<\/p>\n<p>Cybersecurity agencies of Five Eyes countries have recently <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/five-eyes-cyber-security-agencies-statement\" target=\"_blank\" rel=\"nofollow noopener\">advised<\/a> organizations to integrate AI tools into their security operations so they can \u201cdetect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents.\u201d<\/p>\n<p>They\u2019ve also urged them to:<\/p>\n<p>Reduce their attack surface by limiting access to them<br \/>\nAccelerated the patching process and prioritise security updates according to risk<br \/>\nAddress legacy systems (i.e., decommission themm if possible)<br \/>\nStrengthen identity and access controls<br \/>\nPrepare for incidents before they happen.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n<p>Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. <a href=\"https:\/\/www.helpnetsecurity.com\/newsletter\/\" rel=\"nofollow noopener\" target=\"_blank\">Subscribe here!<\/a><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/devider.webp\"\/><\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged&hellip;\n","protected":false},"author":2,"featured_media":106667,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[24,420,7829,6455,330,320,7828,23294,8917,17506,11188,28106,55233],"class_list":["post-106666","post","type-post","status-publish","format-standard","has-post-thumbnail","category-microsoft","tag-ai","tag-azure","tag-azure-ai","tag-cisa","tag-crowdstrike","tag-microsoft","tag-microsoft-ai","tag-patch-tuesday","tag-patching","tag-security-update","tag-sharepoint","tag-tenable","tag-trend-micro"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/106666","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=106666"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/106666\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/106667"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=106666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=106666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=106666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}