This Week in Security: AI-Fueled Patch Records, SharePoint Under Siege, and Surveillance’s Long Shadow

A packed week across the security landscape, with a striking through-line: artificial intelligence is now reshaping both offense and defense—from a record-breaking Patch Tuesday to essays warning about where AI-driven surveillance and infrastructure are taking us. Below, our take on the items worth your attention, from active exploitation alerts to industrial control advisories and a few thought-provoking reads. This is a curated draft; sources are linked throughout.

Optics that watch back. ETH Zurich researchers have built a “Fourier pixel” that can both display and sense light simultaneously—a genuinely impressive feat of physics. But the security implications are hard to ignore: a screen that is also a camera collapses the assumption that a display is a one-way device. It’s a reminder that hardware capabilities often outrun our threat models. (Schneier on Security)

570 patches, and AI gets the credit. Microsoft’s latest Patch Tuesday nearly tripled last month’s already-record haul, and the company points to AI-assisted vulnerability discovery as the driver. That’s a double-edged story: better tooling finds more bugs before attackers do, but it also signals an accelerating patch treadmill that stretched IT teams will struggle to keep up with. Prioritization by risk matters more than ever. (KrebsOnSecurity)

SharePoint remains a prime target. CISA is warning of active exploitation across all supported on-premises SharePoint Server versions, adding fresh CVEs to its KEV catalog. On-prem SharePoint has become a recurring soft spot for unauthorized access; if you still run it, hardening isn’t optional. (CISA)

Four more known-exploited flaws. CISA’s mid-July KEV additions span SonicWall SMA1000 appliances, Active Directory Federation Services, and SharePoint—a cluster of edge and identity infrastructure that attackers clearly favor. The overlap with the SharePoint alert underscores that these aren’t theoretical bugs. (CISA)

An 18-year-old bug, still exploited. The addition of a 2008-era Cisco IOS CSRF flaw to the KEV catalog is a quiet gut-check on patch lifespans. Vulnerabilities don’t expire just because they’re old—unpatched legacy gear keeps them alive. (CISA)

File-upload flaws in the wild. Two more KEV entries—affecting iCagenda and Balbooa Forms—show how unrestricted file uploads remain a durable, low-effort attack vector, especially in third-party web components. Smaller plugins deserve the same scrutiny as flagship products. (CISA)

Russia’s router campaign continues. A joint advisory details FSB Center 16 actors opportunistically compromising poorly configured networking devices across critical sectors. The takeaway is unglamorous but vital: basic router hygiene—patching, secure configuration, disabling legacy protocols—remains a frontline defense against state-sponsored targeting. (CISA)

Industrial control advisories pile up. A batch of ICS advisories landed this week, several with alarming severity. Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter carries a maximum CVSS 10, allowing attackers to alter I/O states and memory. (CISA) ABB’s T-MAC Plus sits at 9.9 with multiple CVEs, (CISA) while ABB Ability Edgenius inherits a Linux kernel privilege-escalation bug, (CISA) and ABB’s Advant Master Online Builder was shipped with an incorrect, vulnerable

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *