EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJULY 15, 20263 min read

Security Briefing | July 15, 2026 - Microsoft Patches Record 622 Flaws Including Two Exploited Zero-Days, SonicWall SMA 1000 Zero-Days Actively Exploited, AsyncAPI npm Packages Deliver Botnet Malware

Microsoft's July 2026 Patch Tuesday is the largest on record, addressing 622 vulnerabilities including two actively exploited zero-days in Active Directory and SharePoint Server. SonicWall warned of active exploitation of two SMA 1000 zero-days including CVE-2026-15409 (CVSS 10.0), an SSRF flaw potentially enabling remote code execution. Four compromised npm packages in the AsyncAPI namespace were found distributing a multi-stage botnet loader.

By EACA Summit Content Team

Security Briefing | July 15, 2026 - Microsoft Patches Record 622 Flaws Including Two Exploited Zero-Days, SonicWall SMA 1000 Zero-Days Actively Exploited, AsyncAPI npm Packages Deliver Botnet Malware

1. Microsoft Patches Record 622 Flaws, Including Two Exploited Zero-Days

Microsoft shipped its largest Patch Tuesday on record, fixing 622 vulnerabilities according to The Hacker News and SecurityWeek, with Krebs on Security reporting a slightly different figure of 570. Two zero-days are being actively exploited: one in Active Directory and one in SharePoint Server. The update also addresses a publicly disclosed BitLocker vulnerability.

Verified Facts

  • Microsoft released its largest ever Patch Tuesday update in July 2026
  • Two zero-day vulnerabilities are under active attack: one in Active Directory and one in SharePoint Server
  • A BitLocker vulnerability was publicly disclosed prior to the patch

Evidence

  • Microsoft Security Update Guide
  • Multiple source confirmation from The Hacker News, SecurityWeek, and Krebs on Security

Impact

Defenders must prioritize patching the two exploited zero-days and the BitLocker flaw to prevent active exploitation and potential data exposure.

Confidence Level: High

Sources The Hacker News | SecurityWeek | Krebs on Security

2. SonicWall SMA 1000 Zero-Days Exploited in the Wild

Illustration of an enterprise VPN and firewall appliance displaying a critical security warning, representing an actively exploited zero-day vulnerability affecting network perimeter defenses.

SonicWall warned of active exploitation of two zero-day vulnerabilities in SMA 1000 series appliances. CVE-2026-15409 (CVSS 10.0) is an SSRF flaw that could allow remote code execution, and CVE-2026-15410 enables arbitrary command execution. Patches are urgently recommended.

Verified Facts

  • CVE-2026-15409 is a server-side request forgery vulnerability with CVSS score 10.0
  • CVE-2026-15410 allows arbitrary command execution
  • Both vulnerabilities are being actively exploited

Evidence

  • CVE-2026-15409
  • CVE-2026-15410
  • SonicWall advisory

Impact

Organizations using SonicWall SMA 1000 appliances should apply patches immediately to prevent remote takeover.

Confidence Level: High

Sources The Hacker News | SecurityWeek

3. Compromised AsyncAPI npm Packages Deliver Botnet Malware

Four compromised npm packages in the @asyncapi namespace were found distributing a multi-stage botnet loader. The affected packages are @asyncapi/generator-helpers (1.1.1), @asyncapi/generator-components (0.7.1), @asyncapi/generator (3.3.1), and @asyncapi/specs (v6.11.2 and v6.11.2-alpha.1).

Verified Facts

Evidence

  • OX Security, SafeDep, Socket, and StepSecurity reports

Impact

Developers using these packages should check for compromise and rotate any exposed credentials immediately.

Confidence Level: High

Sources The Hacker News

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings