Last Updated On

CCTTII--22002266--00772277
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Tomorrow AD FS Expires While 23 Million Dental Records Spill

Tomorrow the AD FS KEV clock hits zero while SharePoint and Langflow remain under confirmed abuse, and healthcare just put roughly twenty four million people on the notification board.

PEAR’s MCBS extortion claim and DentaQuest’s May intrusion disclosure land in the same cycle as SmartConsole admin token theft, Wi Fi gateway M365 harvest, SourTrade’s Bun backed in memory loaders, and a Telegram C2 malware set aimed at Middle East government targets.

Patch evidence, key and token rotation, phishing resistant MFA, and counsel verified breach duty matter more than waiting for a hash list that consulted sources still have not published.

9.9

CVSS Score

0

IOC Count

9

Source Count

61

Confidence Score

CVEs

CVE-2026-56155, CVE-2026-56164, CVE-2026-45659, CVE-2026-50522, CVE-2026-58644, CVE-2026-55040, CVE-2026-55255, CVE-2026-16232, CVE-2026-57092, CVE-2026-56188, CVE-2026-50518, CVE-2026-56159, CVE-2026-55944, CVE-2026-56190, CVE-2026-55008, CVE-2026-48561, CVE-2026-50661, CVE-2026-33017

Actors

PEAR, East Asia linked actor, Under Attribution

Sectors

Healthcare, Financial Services, Government, Enterprise Collaboration, Identity Infrastructure, AI Development Platforms, Security Operations

Regions

United States, Middle East, Global product exposure

Chapter 01 - Executive Overview

Over the last collection window, consulted sources show two simultaneous crisis tracks. Track one is confirmed active exploitation against identity, on premises collaboration, AI agent gateways, and security management consoles, with the AD FS KEV federal remediation deadline on 28 July 2026 now about one day away. Track two is breach and campaign pressure: PEAR extortion against MCBS (~3 TB claimed, ~1.2 million people), DentaQuest’s disclosure of a May 2026 intrusion affecting over 23 million people, Microsoft 365 credential theft via compromised public Wi Fi gateways, SourTrade in memory malware assembly with the Bun runtime, and an East Asia linked TELESHIM / MIXEDKEY / BINDCLOAK set using Telegram C2 against Middle East government targets. Highest product CVSS in the merged set reaches 9.9. No new nation state name was confirmed on the Microsoft zero day track. Overall merged confidence sits at 61.

SharePoint active chain — Critical — Enterprise collaboration / identity

  • Threat overview: Unauthenticated privilege elevation on SharePoint Server (CVE-2026-56164) is confirmed exploited in the wild. Related RCE and bypass issues (CVE-2026-45659 KEV linked; CVE-2026-50522 / CVE-2026-58644 at CVSS 9.8 Site Owner+; CVE-2026-55040 at CVSS 9.1) support a multi CVE path from web exposure toward deeper compromise, including reported IIS machine key theft for persistence.

  • Strategic risk: Internet facing or poorly segmented SharePoint remains a domain compromise path. Patching alone does not remove established footholds if keys or webshells remain.

  • Business impact: Collaboration outage, credential and token theft, regulatory notification risk if personal data is accessed.

  • Confidence: High on exploitation status in consulted vendor aligned sources; low on campaign IOC packages (none published).

  • Leader decision now: Emergency patch, IIS machine key rotation, and IR hunt on every internet reachable SharePoint farm before end of day. Enable AMSI with Request Body Scan = Full until patch validation completes.

AD FS zero day EoP — Critical — Identity / federation

  • Threat overview: CVE-2026-56155 (CVSS 7.8) is an actively exploited elevation of privilege in Active Directory Federation Services. A low privileged local attacker becomes administrator. Microsoft DART credit indicates discovery during incident response.

  • Strategic risk: AD FS compromise undermines federated SSO across cloud and partner apps.

  • Business impact: Identity takeover, lateral movement, prolonged undetected access, forced trust and certificate operations.

  • Confidence: High on exploitation and patch availability; technique level official ATT&CK IDs not published in consulted sources.

  • Leader decision now: Confirm AD FS patch deployment against the 28 July 2026 KEV deadline. Freeze nonessential federation changes until verified. Review local admin group churn on AD FS hosts since mid July.

Langflow AI framework KEV — High — AI / dev platforms

  • Threat overview: CVE-2026-55255 (reported CVSS 9.9) authorization bypass / IDOR in Langflow. CISA KEV listing with exploitation observed since ~25 June 2026 via hijacked flows and prompt injection to leak API keys. Versions before 1.9.1 in scope. Sibling CVE-2026-33017 called out in coverage as sometimes more reached despite lower score.

  • Strategic risk: AI agent gateways treated as lab tools become credential exfil paths into cloud tenants.

  • Confidence: Medium high on KEV and exploitation narrative in consulted sources; treat deep exploit tooling detail as partially verified where primary full text was not independently re fetched in every pass.

  • Leader decision now: Inventory all Langflow; enforce 1.9.1+ or isolate. Rotate every secret any flow could touch. Pull internet exposed instances behind SSO/mTLS.

Check Point SmartConsole zero day — High — Security operations tooling

  • Threat overview: CVE-2026-16232 authentication bypass in SmartConsole GUI. Unauthenticated attackers obtain admin login tokens. Vendor patched after active exploitation per consulted reporting.

  • Strategic risk: Security management plane compromise can weaken controls and falsify operational assurance.

  • Leader decision now: Confirm SmartConsole patch on all admin workstations. Restrict GUI to jump hosts. Revoke and reissue management tokens if the exposure window is unknown. Audit admin actions across the open window.

July Microsoft criticals without confirmed ITW — High patch priority — Infrastructure

  • Watch list: CVE-2026-57092 VMSwitch guest to host CVSS 9.9; CVE-2026-56188 network driver unauth RCE 9.8; DHCP CVE-2026-50518 / CVE-2026-56159 at 9.8; Dynamics NAV/BC CVE-2026-55944 at 9.8; RDP CVE-2026-56190 at 9.8 when NLA is off; BitLocker CVE-2026-50661 at 6.1 physical, not exploited per Microsoft characterization in consulted sources.

  • Leader decision now: Schedule behind AD FS and SharePoint but inside the same emergency CAB wave for internet exposed or high blast radius roles.

MCBS PEAR ransomware extortion — High — Healthcare

  • Threat overview: PEAR named in consulted secondary reporting against medical business manager MCBS. Claimed ~3 TB exfiltrated and ~1.2 million individuals affected, with active extortion pressure.

  • Strategic risk: Business associate cascade; HIPAA notification clocks; partner ecosystem contagion.

  • Confidence: Low on actor label; scale figures need primary notice verification.

  • Leader decision now: If you are MCBS or a business associate, open breach assessment and notification readiness immediately with counsel. Preserve logs before rebuild impulses.

DentaQuest large scale disclosure — High — Healthcare / dental

  • Threat overview: DentaQuest disclosed a May 2026 intrusion exposing personal and dental health data for over 23 million people, among the largest healthcare exposures reported this year in consulted coverage.

  • Strategic risk: Regulatory, contractual, and reputational exposure at population scale.

  • Confidence: Disclosure event well reported in secondary news; actor unattributed; vector not detailed.

  • Leader decision now: Legal and compliance assess federal and state exposure. Downstream employers and integrated care partners request official notice language, not social summary counts alone.

Public Wi Fi M365 credential harvesting — High — Enterprise travel / identity

  • Threat overview: Compromised public Wi Fi gateway appliances intercept authentication traffic and harvest Microsoft 365 credentials via man in the middle. User awareness training does not mitigate appliance level interception.

  • Leader decision now: IAM must mandate phishing resistant MFA for all M365 accounts without exception. Conditional Access should prefer compliant or hybrid joined devices and flag auth from untrusted networks.

SourTrade in memory malvertising — Medium — Financial / crypto

  • Threat overview: Fake Solana, Luno, and TradingView pages deliver JavaScript that assembles a Windows executable in browser memory using the legitimate Bun runtime, reducing file based AV visibility.

  • Leader decision now: SOC confirms memory behavioral detection is on. Application control policy for Bun where not required. User warning to trading and treasury populations is secondary to EDR capability.

TELESHIM malware trio — Medium — Government Middle East

  • Threat overview: East Asia linked actor (unnamed group) deploys TELESHIM, MIXEDKEY, and BINDCLOAK against Middle East government targets with Telegram as covert C2.

  • Leader decision now: Government and near government SOCs review egress policy for Telegram class traffic from servers and non user endpoints. Load family names into TI watch lists pending concrete IOCs.

Defender priority order (executive one screen)

  1. AD FS CVE-2026-56155 (KEV deadline 28 July; identity crown jewel)

  2. SharePoint CVE-2026-56164 plus related RCE/bypass/KEV set (ITW + chain + key rotation)

  3. Langflow CVE-2026-55255 (KEV; API key harvest)

  4. SmartConsole CVE-2026-16232 (admin plane tokens)

  5. M365 phishing resistant MFA and Conditional Access (active Wi Fi harvest pattern)

  6. MCBS / DentaQuest legal and associate response (regulatory clocks; data already reported stolen)

  7. July 9.8–9.9 Microsoft infrastructure criticals without ITW confirmation

  8. SourTrade memory detection + Bun control

  9. TELESHIM Telegram egress baselining for government dense environments

Today’s intelligence quality

  • Strongest depth: Microsoft July Patch Tuesday ITW mechanics, CVSS/CWE tables, AMSI guidance, SmartConsole exploitation/patch narrative, KEV deadline framing.

  • Thinner depth: same day original long form from additional major IR houses; classic IOC packages; official ATT&CK; PEAR and East Asia actor enrichment; DentaQuest/MCBS primary root cause.

  • Merged confidence 61. Exploitation claims on the Microsoft and Check Point track are actionable now. Breach counts and actor names require primary verification before legal or public attribution language.

Chapter 02 - Threat & Exposure Analysis

Theme from consulted sources: identity and collaboration edges under confirmed exploitation, AI agent frameworks on the mandatory patch (KEV) list, security management plane token theft, plus a parallel breach and campaign track that abuses trusted infrastructure rather than fresh public exploits.

SharePoint unauthenticated EoP under active use (CVE-2026-56164 and companions)

  • Attack progression (source grounded): Missing authentication for a critical function (CWE-306) allows an unauthenticated remote attacker to elevate privileges over the network, no user interaction, low complexity. Microsoft recommends AMSI integrated with SharePoint/IIS worker processes and Request Body Scan = Full as pre patch mitigation.

  • Exploitability: CVSS 5.3 (Moderate) per vendor aligned severity labeling in consulted sources, yet exploited in the wild. No public exploit code at major analysis publish time.

  • Campaign indicators: Multi CVE SharePoint pressure also includes critical deserialization RCEs CVE-2026-50522 and CVE-2026-58644 (CVSS 9.8, Site Owner+), auth bypass CVE-2026-55040 (CVSS 9.1), and KEV linked SharePoint RCE CVE-2026-45659. Reported IIS machine key theft supports persistence after initial web exposure.

  • Actor identity: Under Attribution. Mandiant IR / Google Cloud researchers appear as discovery credits, not as threat actors.

  • Infrastructure fingerprinting: Insufficient source data for attacker ASN, registrar, or C2 reuse.

  • Sector / geographic exposure: Product driven global exposure wherever on premises SharePoint remains reachable; no sector locked targeting confirmed in consulted sources.

  • MITRE (inferred): T1190 Exploit Public Facing Application; T1068 Exploitation for Privilege Escalation; T1505.003 Web Shell; T1552.004 Private Keys (machine keys); T1059.001 / T1059.003 worker spawned shells. Official vendor T numbers not published in consulted sources.

AD FS local EoP zero day (CVE-2026-56155)

  • Attack progression: Insufficient granularity of access control (CWE-1220). Authorized low privileged local attacker elevates to administrator; no UI interaction required; low complexity.

  • Exploitability: CVSS 7.8; actively exploited; no public exploit code at analysis time in consulted sources.

  • Campaign indicators: DART credit implies live IR context. Microsoft did not publish exploitation TTPs in the material reviewed. Reported CISA KEV federal remediation deadline 28 July 2026.

  • Actor: Under Attribution.

  • Strategic exposure: Federation is a crown jewel. Host level admin on AD FS undermines SSO into cloud and partner applications even when cloud SaaS patch state is healthy.

  • MITRE (inferred): T1068; T1078 Valid Accounts (follow on federated session abuse); T1133 External Remote Services (federation plane). Official T numbers not published.

Langflow IDOR to prompt injected key theft (CVE-2026-55255)

  • Attack progression: Authenticated attacker supplies victim flow ID to /api/v1/responses, executes another user’s flow, injects prompts (for example “leak api keys”) to harvest credentials and cloud resources. Affects versions before 1.9.1. First exploitation reported ~25 June 2026.

  • Exploitability: Reported CVSS 9.9; CISA KEV. Sibling CVE-2026-33017 (lower score) reportedly exploited more often in some coverage, showing reachability can outrank raw CVSS.

  • Actor: Under Attribution.

  • Strategic exposure: Shadow AI and “lab only” agent gateways often sit outside formal asset inventory, yet hold long lived cloud keys inside flow context.

  • MITRE (inferred): T1190 (if exposed); T1659 Content Injection; T1552.001 Credentials in Files / flow secrets; Discovery via object IDOR. Official T numbers not published.

SmartConsole authentication bypass (CVE-2026-16232)

  • Attack progression: Unauthenticated attacker obtains application login token usable for administrator authentication to the SmartConsole GUI.

  • Exploitability: Actively exploited prior to vendor patch per consulted reporting. Numeric CVSS not published in retrieved text; urgency is ITW plus management plane blast radius.

  • Actor: Under Attribution.

  • Strategic exposure: Security operations tooling compromise can weaken controls, alter policy, and undermine assurance evidence.

  • MITRE (inferred): T1190; T1550 Use Alternate Authentication Material; T1078. Official T numbers not published.

July criticals without confirmed in the wild use (patch priority)





CVE

Product

CVSS

Notes from consulted sources

CVE-2026-57092

Windows VMSwitch

9.9

Guest to host EoP via Hyper V vSwitch use after free (CWE-416)

CVE-2026-56188

Windows Server network driver

9.8

Unauth RCE via crafted traffic; race condition (CWE-362)

CVE-2026-50518 / CVE-2026-56159

DHCP Server

9.8

Unauth RCE heap overflows

CVE-2026-55944

Dynamics NAV / BC on premises

9.8

Unauth RCE via crafted login

CVE-2026-56190

RDP (NLA disabled)

9.8

Unauth RCE; discovery credit noted in analyses

CVE-2026-50661

BitLocker

6.1

Physical bypass; disclosed; not exploited per Microsoft characterization

PEAR ransomware against MCBS (data theft and extortion)

  • Attack progression: Initial access vector not disclosed in consulted sources. PEAR exfiltrated a claimed ~3 TB before extortion pressure against medical business manager MCBS, affecting ~1.2 million individuals.

  • Exploitability: No CVE or technical exploit chain published.

  • Actor identity: PEAR (named in secondary reporting). Attribution confidence Low. Under Attribution for nation state or cross campaign linkage.

  • Sector exposure: Healthcare and medical business process ecosystems; business associate cascade likely.

  • Geographic exposure: United States implied by coverage framing; not a globally tagged campaign in source text.

  • MITRE (mentioned unconfirmed / inferred): T1486; T1005; T1020. Confirm against primary notices before legal language hardens.

DentaQuest large scale health data exposure

  • Attack progression: Intrusion occurred May 2026; network breach vector not disclosed. Public disclosure landed in this reporting cycle.

  • Scale: Over 23 million people with personal and dental health data exposed. Scale is the primary risk driver, not published technical sophistication.

  • Actor: Under Attribution. No CVE.

  • Sector exposure: Healthcare / dental benefits and payers; employer group downstream risk.

  • MITRE (inferred impact pattern): T1005; T1020 class outcomes without confirmed tooling names.

M365 credential harvesting via compromised Wi Fi gateways

  • Attack progression: Attacker compromises the Wi Fi gateway appliance, then intercepts authentication traffic from connected devices via man in the middle, harvesting Microsoft 365 credentials.

  • TTP indicators: T1040 Network Sniffing; T1556 Modify Authentication Process (aggregator tagged in secondary metadata, not fully primary confirmed); inferred T1078 / T1550 for stolen session or password reuse follow on.

  • Actor: Under Attribution.

  • Sector exposure: Any enterprise with traveling staff; professional services and executive travel densest.

  • Why training fails: The interception sits on the network path, not in the user’s inbox.

SourTrade in memory malware assembly via Bun runtime

  • Attack progression: Victim visits a fake Solana, Luno, or TradingView page. Malicious JavaScript instructs the browser to assemble a Windows PE directly in memory using the legitimate Bun runtime, avoiding a clean on disk first stage.

  • TTP indicators: T1566.002; T1204.001; T1027; T1620 Reflective Code Loading (inferred). Aggregator tags unconfirmed against full primary text.

  • Actor: Under Attribution.

  • Sector exposure: Financial services and cryptocurrency trading users.

  • Detection implication: File hash AV alone is the wrong primary control.

TELESHIM novel malware trio via Telegram C2

  • Attack progression: East Asia linked actor deploys TELESHIM, MIXEDKEY, and BINDCLOAK against Middle East government entities, routing C2 through Telegram to blend with allowed traffic.

  • TTP indicators: T1071.001; T1105 (mentioned unconfirmed / inferred).

  • Attribution: East Asia linked, not a named MITRE group. Confidence Low given single cycle secondary depth.

  • Sector / geo: Government Middle East focus in consulted sources.

Cross incident pattern analysis

  • Shared vulnerability pattern: pre auth or low privilege paths into high impact identity, collaboration, management, and AI flow control planes (SharePoint, AD FS, SmartConsole, Langflow).

  • Shared campaign pattern: abuse of trusted or legitimate infrastructure (Wi Fi appliances, Telegram, Bun runtime) to evade controls, rather than dependence on a brand new public CVE for every intrusion.

  • Healthcare pattern: exfiltration first and disclosure scale dominate; root vector opacity remains.

  • No shared IOC, named actor, or single CVE technically binds PEAR, TELESHIM, SourTrade, Wi Fi harvest, and the Microsoft ITW set into one campaign. Linkage is tradecraft level, not infrastructure level.

  • Board relevant synthesis: unpatched identity and collaboration flaws are under active abuse while a US federal AD FS fix deadline hits tomorrow, and separately attackers are stealing health data and credentials without needing a zero day headline every time.

Chapter 03 - Operational Response

Operational posture from consulted sources: identity plus SharePoint emergency patch and hunt; treat AD FS KEV deadline as hard stop; close AI gateway and management console exposure; force phishing resistant M365 controls for travel heavy populations; run healthcare legal tracks in parallel because data is already reported stolen.

SharePoint active chain: immediate response and containment

Containment priorities:

  1. Do this NOW: Identify all internet facing and partner facing SharePoint Server instances; restrict to VPN or Zero Trust if unpatched.

  2. Do this NOW: Deploy July 2026 SharePoint security updates including CVE-2026-56164 and related critical SharePoint CVEs (CVE-2026-50522, CVE-2026-58644, CVE-2026-55040, KEV linked CVE-2026-45659 as applicable).

  3. Do this within 24 hours: Rotate IIS machine keys; hunt webshells, anomalous w3wp.exe child processes, and unexpected SharePoint feature or timer job changes.

  4. Enable AMSI on SharePoint with Request Body Scan = Full until fully patched and validated.

Security hardening actions:

  • Remove SharePoint from direct internet exposure where business allows.

  • Enforce least privilege Site Owner roles (critical RCEs require Site Owner+).

  • Snapshot forensic images before mass remediation if compromise is suspected.

Internal security coordination:

  • Notify: Vuln Mgmt, IR, Identity, SharePoint platform owners, CISO.

  • Escalation trigger: webshell, stolen machine keys, or lateral movement from SharePoint host toward Domain Admin path.

  • External notification: only if confirmed personal data access per legal counsel (no named victim org breach confirmation for this SharePoint cluster in consulted sources this window).

AD FS CVE-2026-56155: immediate response and containment

Containment priorities:

  1. Do this NOW: Inventory all AD FS servers; apply July 2026 AD FS update for CVE-2026-56155.

  2. Do this within 24 hours: Review local privileged group membership and recent AD FS configuration or export changes; reset credentials for accounts that had low privilege shell access to AD FS hosts.

  3. Validate KEV deadline compliance path for 28 July 2026.

Security hardening actions:

  • Harden AD FS admin tier (PAW, no email or browse on AD FS hosts).

  • Monitor federation trust and claim rule modifications.

Internal security coordination:

  • Notify Identity/IAM, Tier 0 owners, SOC.

  • Escalation: unexplained admin token issuance or trust changes after the exploitation window.

Langflow CVE-2026-55255: immediate response and containment

Containment priorities:

  1. Do this NOW: Find Langflow instances; upgrade to 1.9.1+ or isolate from the network.

  2. Do this within 24 hours: Rotate all API keys and secrets accessible to flows; review flow execution logs for foreign flow IDs and prompt injection strings.

Security hardening actions:

  • Put SSO/mTLS in front of any agent UI/API; never expose unauthenticated.

  • Least privilege tool credentials for agents (no long lived cloud keys in flow context).

SmartConsole CVE-2026-16232: immediate response and containment

  1. Do this NOW: Apply Check Point SmartConsole fix; restrict management GUI to jump hosts.

  2. Do this within 24 hours: Invalidate management sessions and tokens; audit admin actions during the exposure window.

MCBS and DentaQuest: immediate response and containment

Containment priorities:

  1. If your organization is MCBS, DentaQuest, or a business associate, initiate vendor breach assessment now.

  2. Engage legal counsel on HIPAA notification timelines immediately; preserve evidence before rebuild.

  3. Review exfiltration monitoring and internal data access logging (directional T1020 / T1005 alignment only).

  4. Downstream partners request official notice language; do not rely on social count summaries alone.

Coordination note: Response steps that imply victim environment changes require vendor or primary advisory confirmation. Consulted coverage is secondary for these two disclosures.

M365 credential harvesting via Wi Fi gateways: immediate response and containment

  1. Do this NOW: Mandate phishing resistant MFA for all Microsoft 365 accounts without exception.

  2. Do this within 24 hours: Review Conditional Access to require compliant or hybrid joined devices; flag authentication from untrusted or public network ranges.

  3. Reset credentials and revoke sessions for users with travel correlated anomalous sign ins in the last 30 days.

SourTrade: immediate response and containment

  1. Do this NOW: Confirm memory based behavioral detection (not file scan only) is active on endpoints.

  2. Do this within 24 hours: Assess whether the Bun runtime is present or permitted; restrict via application control if not needed.

  3. Warn treasury, trading, and crypto adjacent staff that fake Solana, Luno, and TradingView pages are active lure themes.

TELESHIM family: immediate response and containment

  1. Do this NOW: Review network egress policy for Telegram traffic from servers and non user endpoints.

  2. Do this within 24 hours: Load TELESHIM / MIXEDKEY / BINDCLOAK names into threat intel watches; concrete IOCs were not available in consulted sources at brief time.

  3. Government dense environments baseline and alert on Telegram Bot API traffic from server subnets.

July infrastructure criticals (no ITW confirmation): response

  • Patch CVE-2026-57092, CVE-2026-56188, DHCP CVE-2026-50518 / CVE-2026-56159, CVE-2026-55944, and CVE-2026-56190 (if NLA disabled) inside the same emergency wave after identity and SharePoint.

  • BitLocker CVE-2026-50661: reinforce physical custody and lost device playbooks rather than internet emergency change.

Defender priority order (today)

  1. AD FS CVE-2026-56155 — KEV deadline 28 July; identity crown jewel

  2. SharePoint CVE-2026-56164 + related RCE/bypass/KEV set — confirmed ITW + chain potential + key rotation

  3. Langflow CVE-2026-55255 — KEV, API key harvest pattern

  4. SmartConsole CVE-2026-16232 — admin plane token theft

  5. M365 phishing resistant MFA + Conditional Access — active Wi Fi harvest pattern, broadest identity blast radius for travelers

  6. MCBS / DentaQuest legal and associate track — regulatory urgency; containment is largely post hoc because data is already reported stolen

  7. Unauth network RCEs (CVE-2026-56188, DHCP 9.8s, RDP CVE-2026-56190 if NLA off) and VMSwitch CVE-2026-57092 — high blast radius even without ITW confirmation

  8. SourTrade — memory detection and Bun control

  9. TELESHIM set — Telegram egress baselining for government focused estates

SharePoint and July zero days

Date

Event

2026 07 01

CVE-2026-45659 (SharePoint RCE) reported added to CISA KEV per multi source brief citing KEV catalog activity

2026 07 14

Microsoft July 2026 Patch Tuesday: CVE-2026-56164 and CVE-2026-56155 fixed; both marked exploited in the wild; major analyses publish

2026 07 14

SharePoint hardening alert / KEV related actions cited alongside the patch wave

2026 07 17

Reported federal remediation deadline for CVE-2026-45659 (KEV linked)

2026 07 26 to 2026 07 27

No new deep technical package located in open retrieval for this 24h window; exploitation status remains confirmed from 14 Jul disclosures; operational urgency driven by residual unpatched estates and AD FS deadline

AD FS CVE-2026-56155

Date

Event

Date unconfirmed

Exploitation in the wild prior to patch (vendor aligned consulted sources)

2026 07 14

Patch released; DART researchers credited

2026 07 27

Status: patch available; deadline ~24h away for BOD covered entities

2026 07 28

Reported CISA KEV federal remediation deadline

Langflow CVE-2026-55255

Date

Event

2026 06 25

First exploitation observed (Sysdig as cited in consulted coverage)

2026 07 07

CISA KEV addition cited (three vuln alert framing)

2026 07 26 to 2026 07 27

Still relevant for any unpatched AI stack inventory; fix bar 1.9.1+

SmartConsole CVE-2026-16232

Date

Event

2026 07 22

Consulted reporting: Check Point patched actively exploited SmartConsole zero day; admin login token theft pattern described

2026 07 27

Status: patch available; hunt residual admin token abuse if management plane was exposed

MCBS and DentaQuest

Date

Event

May 2026 (day not published)

DentaQuest network intrusion occurs per consulted reporting

Date unconfirmed

MCBS intrusion and PEAR exfiltration begin; start day not published in available text

2026 07 27 cycle

Both MCBS (PEAR, ~3 TB claimed, ~1.2M individuals) and DentaQuest (23M+ personal and dental health records) publicly disclosed via secondary security news in this cycle

Wi Fi harvest, SourTrade, TELESHIM

Date

Event

Insufficient source data

No firm first seen day for Wi Fi gateway M365 harvesting beyond active as of this cycle

Insufficient source data

No firm first seen day for SourTrade Bun in memory malvertising beyond active campaign status

Insufficient source data

No firm first seen day for TELESHIM / MIXEDKEY / BINDCLOAK beyond active reporting against Middle East government targets

Collection window for this daily record

Date

Event

2026 07 26 15:00 IST → 2026 07 27 21:26 IST

Intelligence collection window feeding the merged brief

2026 07 27

Report date (Monday)

Timeline reading guide for operators

  • Compliance clocks: AD FS → 2026 07 28; SharePoint KEV linked items → verify live catalog (17 July class dates may already be overdue for covered entities).

  • Healthcare legal clocks: run from organizational discovery and applicable HIPAA / state law, not from Patch Tuesday.

  • First Observed Date at record level remains 2026 06 25 (Langflow exploitation anchor at day resolution).

Chapter 04 - Detection Intelligence

CVE-2026-56164: SharePoint missing authentication EoP

  • Attack vector: Network, unauthenticated.

  • Exploitation mechanism: Missing authentication for a critical function (CWE-306); remote elevation over network; low complexity; no user interaction.

  • Observed behavior: Exploited in the wild; public exploit code not disclosed at major analysis time. Pre patch: AMSI on SharePoint/IIS with full POST body scan.

  • Vulnerability details: Microsoft SharePoint Server; severity labeled Moderate by Microsoft despite ITW use.

  • CVE technical context: CVSS 5.3 in vendor aligned tables in consulted sources.

  • Patch status: Patched 14 July 2026 Patch Tuesday.

  • Chain context: Pair with CVE-2026-50522 / CVE-2026-58644 (CWE-502 deserialization RCE as Site Owner+, CVSS 9.8), CVE-2026-55040 (CWE-1390 weak authentication, unauth bypass/impersonation, CVSS 9.1), and KEV linked CVE-2026-45659. Persistence narrative includes IIS machine key theft and webshell class artifacts.

CVE-2026-56155: AD FS insufficient access control granularity

  • Attack vector: Local, low privileged authorized user.

  • Exploitation mechanism: CWE-1220 insufficient granularity of access control → administrator.

  • Observed behavior: ITW exploitation; no public exploit code at analysis time; discovered via DART IR activity.

  • CVSS: 7.8 Important.

  • Patch status: Patched 14 July 2026.

  • Operational technical note: Host admin on AD FS is an identity system compromise even without a separate cloud SaaS CVE.

CVE-2026-57092: VMSwitch guest to host

  • Mechanism: Use after free (CWE-416) via crafted network related requests from guest through Hyper V Virtual Switch; CVSS 9.9.

  • Patch status: Patched; exploitation ITW not stated in consulted sources.

CVE-2026-56188: Windows Server network driver RCE

  • Mechanism: Race condition (CWE-362); unauthenticated remote RCE via crafted network traffic; CVSS 9.8.

  • Patch status: Patched; ITW not stated.

CVE-2026-50518 / CVE-2026-56159: DHCP Server

  • Mechanism: Unauthenticated RCE via heap overflow class issues; CVSS 9.8.

  • Patch status: Patched; ITW not stated.

CVE-2026-55944: Dynamics NAV / Business Central on premises

  • Mechanism: Unauthenticated RCE via crafted login; CVSS 9.8.

  • Patch status: Patched; ITW not stated.

CVE-2026-56190: RDP with NLA disabled

  • Mechanism: Unauthenticated RCE when NLA is disabled; CVSS 9.8.

  • Patch status: Patched; ITW not stated. Discovery credit noted in consulted analyses.

CVE-2026-50661: BitLocker bypass

  • Mechanism: Protection mechanism failure (CWE-693); physical access; CVSS 6.1; publicly disclosed; no ITW evidence; Microsoft exploitation “less likely” in consulted characterization.

  • Patch status: Patched / update per July wave; treat as physical threat model.

CVE-2026-55255: Langflow IDOR

  • Mechanism: IDOR on /api/v1/responses enables execution of another user’s flow; combined with prompt injection for secret leakage. Versions before 1.9.1.

  • Observed behavior: Exploitation since ~25 June 2026; API key and cloud credential harvest pattern; on CISA KEV.

  • Patch status: 1.9.1+.

  • Sibling: CVE-2026-33017 lower score but reportedly more often reached in some coverage.

CVE-2026-16232: SmartConsole

  • Mechanism: Authentication bypass → application login token with admin privileges to SmartConsole GUI.

  • Observed behavior: Actively exploited before patch per consulted reporting.

  • Patch status: Vendor addressed per 22 July class reporting.

PEAR / MCBS technical view

  • Attack vector: Unconfirmed in consulted sources.

  • Exploitation mechanism: Not published (no CVE).

  • Observed behavior: Claimed ~3 TB exfiltration; extortion pressure; ~1.2M individuals in notification scope.

  • Patch status: N/A (breach outcome cluster).

DentaQuest technical view

  • Attack vector: Network intrusion May 2026; vector not disclosed.

  • Exploitation mechanism: Not published.

  • Observed behavior: 23M+ personal and dental health records exposed; disclosure in current cycle.

  • Patch status: N/A.

M365 Wi Fi gateway harvesting technical view

  • Attack vector: Network adjacent compromised Wi Fi gateway appliance.

  • Exploitation mechanism: Man in the middle interception of authentication traffic at the gateway level.

  • Patch status: N/A as a classic software CVE in consulted text; appliance compromise mechanism not detailed.

  • Control plane that matters: Phishing resistant MFA, Conditional Access device posture, session revocation, token protection features where licensed.

SourTrade technical view

  • Attack vector: Web based malvertising lure pages (fake Solana / Luno / TradingView).

  • Exploitation mechanism: Malicious JS instructs browser to assemble a Windows PE in memory using the Bun runtime; no full malicious file required on disk during initial delivery.

  • Patch status: N/A (delivery technique campaign).

  • Control plane that matters: Memory behavioral EDR, application control on Bun, browser isolation for high risk user groups.

TELESHIM / MIXEDKEY / BINDCLOAK technical view

  • Attack vector: Not fully detailed; government targeted delivery implied.

  • Exploitation mechanism: Three family malware set with Telegram covert C2 to blend with allowed traffic.

  • Patch status: N/A.

  • Control plane that matters: Egress filtering and detection for Telegram API from servers; EDR family detections when samples appear.

Technical analysis quality note

Vulnerability track mechanics (CWE, CVSS, vector, patch day) are the strongest technical layer in consulted sources. Breach and campaign clusters are outcome and tradecraft rich but root cause poor. Do not invent exploit primitives where sources are silent.

Indicators of compromise (all clusters)

Type

Value

Context

Verdict

CVE ID

CVE-2026-56155

AD FS EoP zero day ITW; KEV deadline 28 July 2026

Tracking (not a network IOC)

CVE ID

CVE-2026-56164

SharePoint EoP zero day ITW

Tracking

CVE ID

CVE-2026-45659

SharePoint RCE KEV linked

Tracking

CVE ID

CVE-2026-50522

SharePoint deserialization RCE CVSS 9.8

Tracking

CVE ID

CVE-2026-58644

SharePoint deserialization RCE CVSS 9.8

Tracking

CVE ID

CVE-2026-55040

SharePoint auth bypass CVSS 9.1

Tracking

CVE ID

CVE-2026-55255

Langflow IDOR KEV; exploit since ~25 June 2026

Tracking

CVE ID

CVE-2026-33017

Langflow sibling; reachability note in coverage

Tracking

CVE ID

CVE-2026-16232

SmartConsole auth bypass ITW

Tracking

CVE ID

CVE-2026-57092

VMSwitch guest to host CVSS 9.9

Tracking

CVE ID

CVE-2026-56188

Network driver unauth RCE CVSS 9.8

Tracking

CVE ID

CVE-2026-50518

DHCP unauth RCE CVSS 9.8

Tracking

CVE ID

CVE-2026-56159

DHCP unauth RCE companion

Tracking

CVE ID

CVE-2026-55944

Dynamics NAV/BC on prem unauth RCE

Tracking

CVE ID

CVE-2026-56190

RDP unauth RCE if NLA off

Tracking

CVE ID

CVE-2026-55008

July Microsoft set rollup item

Tracking

CVE ID

CVE-2026-48561

July Microsoft set rollup item

Tracking

CVE ID

CVE-2026-50661

BitLocker physical bypass; not ITW

Tracking

IP address

None published

All clusters

Absent

Domain

None published as attacker infra

All clusters

Absent

URL

No stable malicious lure URLs published

SourTrade described thematically only

Absent

File hash

None published

SourTrade, TELESHIM family, PEAR payloads, webshells

Absent

Email

None published

All clusters

Absent

Wallet / payment

None published

PEAR extortion

Absent

Telegram bot ID

None published

TELESHIM C2

Absent

Total classic network/file IOC count: 0 (matches Total IOC Count field). CVE rows are catalog tracking keys, not blocklist IOCs.

Malware and campaign labels (watchlist seeds, not IOCs)

Label

Type

Notes

PEAR

Ransomware operator label

MCBS extortion; Low attribution confidence

TELESHIM

Malware family

Middle East government focus; Telegram C2

MIXEDKEY

Malware family

Same set as TELESHIM

BINDCLOAK

Malware family

Same set as TELESHIM

SourTrade

Campaign label

Bun backed in memory PE assembly via fake trading pages

Bun

Legitimate runtime abused

Application control candidate where not required

Infrastructure patterns

  • Insufficient source data for attacker ASN, bulletproof hosting, registrar reuse, or shared C2 across clusters.

  • Defender relevant legitimate infrastructure abused or implicated (not attacker owned IOCs):

    • Public Wi Fi gateway appliances (compromise locus for M365 MITM)

    • Telegram API / Bot API style egress (TELESHIM blend in)

    • Bun JavaScript runtime (SourTrade in memory assembly)

    • SharePoint/IIS worker process space and machine key material (persistence locus)

    • Langflow /api/v1/responses object model (IDOR locus)

    • Check Point SmartConsole management path (token minting locus)

  • No evidence in consulted sources that PEAR, TELESHIM, SourTrade, and Microsoft ITW exploitation share one backbone.

Actor normalization evidence

  • Insufficient source data to collapse PEAR and the East Asia linked TELESHIM operator into one identity.

  • Insufficient source data to attribute Microsoft or Check Point ITW exploitation to either named label.

  • Discovery credits (DART, Mandiant IR, Google Cloud researchers, select CVE discovery credits) are researcher identities only.

Enrichment posture

  • IOC Enrichment Status remains Pending.

  • Open TI watchers on all CVE IDs and family labels above.

  • Do not fabricate placeholder IPs, domains, or hashes to fill this table.

  • When first concrete indicator publishes, version this record, increment Total IOC Count, and flip enrichment state.

Practical “indicator substitutes” for SIEM loading today

These are detection pivots, not IOCs:

  • Process: w3wp.execmd.exe / powershell.exe / pwsh.exe / certutil.exe

  • File: unexpected ASPX under SharePoint layouts/content trees

  • Config: IIS machine key / web.config changes outside change windows

  • Identity: Entra sign in anomalies from public Wi Fi ranges; new device registration; impossible travel

  • API: Langflow POST /api/v1/responses where flow owner ≠ session user; body strings suggesting secret exfil

  • Egress: Telegram API from server subnets

  • Endpoint: Bun execution from browser parents where Bun is not approved

  • Management: SmartConsole login or token issue from non jump host IPs

SharePoint unauth EoP and deserialization path

Detection engineering opportunities:

  • Alert on SharePoint / w3wp.exe spawning shells (cmd.exe, powershell.exe, pwsh, certutil, bitsadmin) or writing ASPX under SharePoint layouts/content trees

  • Alert on AMSI blocks in SharePoint worker processes after enabling full request body scan

  • Alert on IIS machine key / web.config modifications outside change windows

  • Alert on anomalous POST volume to _vti_ style and SharePoint API endpoints from external networks

Immediate detection action (24h): Deploy process creation correlation: parent w3wp.exe + SharePoint app pool → suspicious children.

Hunt this week: Historical 30 day review of SharePoint servers for webshell file creates, unexpected ASPX, and machine key churn since 14 July 2026.

SIGMA pseudocode (behavioral; not a vendor published rule):

title: SharePoint Worker Suspicious Child Process
logsource: process_creation
detection:
  parent:
    Image|endswith: '\w3wp.exe'
    CommandLine|contains: 'SharePoint'
  child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\certutil.exe'
  condition: parent and child
level: high

YARA pattern concept (webshell hunt; generic, not vendor supplied):

rule SP_Webshell_Suspect_ASPX {
  strings:
    $a = "System.Diagnostics.Process" ascii
    $b = "Request[" ascii
    $c = "eval(" ascii
  condition:
    uint16(0) == 0x3C25 and 2 of them
}

SIEM field logic:

index=windows OR index=sysmon
EventID=1 OR EventCode=4688
ParentImage="*\\w3wp.exe"
(Image="*\\cmd.exe" OR Image="*\\powershell.exe" OR Image="*\\pwsh.exe")
| stats count by host, user, ParentCommandLine, CommandLine

Network: Spike in external POSTs to SharePoint with large bodies; new outbound from SharePoint hosts to rare destinations.

AD FS local EoP

Immediate detection action: Monitor AD FS hosts for unexpected local privilege changes, new local admins, and AD FS service account token anomalies after any low privilege logon.

Hunt this week: 14 to 28 July window: interactive/local logons by non admin users on AD FS servers followed by admin equivalent activity within 1 hour.

SIGMA pseudocode:

title: ADFS Host Local Privilege Group Modification
logsource: windows windows_security
detection:
  selection:
    EventID: 4732
    TargetUserName|in:
      - 'Administrators'
      - 'Domain Admins'
  filter_main:
    SubjectUserName|endswith: '$'
  condition: selection and not filter_main
level: high

SIEM:

EventID IN (4728,4732,4756)
Computer IN adfs_host_list
| where MemberName NOT IN expected_admins

EDR: Alert on non SYSTEM processes loading AD FS configuration modules then spawning whoami/net group.

Langflow IDOR and prompt injection

Immediate detection action: WAF/API log rule: authenticated user A executing flow_id owned by user B on /api/v1/responses.

SIGMA like API pseudocode:

title: Langflow Cross User Flow Execution
logsource: api application
detection:
  selection:
    http.url|contains: '/api/v1/responses'
    http.method: POST
  highrisk:
    flow_owner != auth_user
  injection:
    request_body|contains:
      - 'leak api'
      - 'print env'
      - 'exfil'
  condition: selection and (highrisk or injection)
level: critical

Hunt this week: API keys created or rotated outside CI; LLM provider billing spikes from Langflow service identities; versions still below 1.9.1 on any host.

SmartConsole token theft

Immediate detection action: Management audit log for admin sessions from new IPs or workstations without prior device posture; token minting without interactive MFA path.

SIEM:

product=checkpoint management
event IN (login_success, token_issue)
| where src_ip NOT IN admin_jump_hosts

M365 credential harvesting via compromised Wi Fi gateways

Detection engineering:

  • Monitor Entra ID / Azure AD sign in logs for impossible travel, unfamiliar device registration, and token replay indicators

  • Correlate successful sign ins with source networks classified as public Wi Fi or unknown hospitality ranges

Immediate detection action (24h): Enable Conditional Access alerts for auth from non corporate / public IP ranges.

Hunt this week: Review 30 day M365 sign in logs for travel correlated anomalous logins; revoke sessions and require password reset plus phishing resistant MFA enrollment where gaps exist.

SIEM pseudocode (illustrative):

WHERE EventSource = AzureAD_SignIn
AND (ImpossibleTravelFlag = true OR NewDeviceRegistration = true)
AND SourceNetwork IN PublicWiFiRanges

SourTrade browser memory malware assembly

Detection engineering:

  • Alert on browser processes making unusual memory allocation or execution calls consistent with in process code assembly

  • Monitor for Bun runtime execution where not expected in the environment

  • Alert on browser parent spawning Bun or anomalous PE mapping without a prior reputable installer event

Immediate detection action (24h): Confirm EDR memory behavioral modules are enabled, not solely file hash or signature based.

Hunt this week: Search for Bun runtime binaries or child processes spawned from browser processes across the endpoint fleet; review proxy logs for themed lure hostnames impersonating Solana, Luno, or TradingView.

TELESHIM / MIXEDKEY / BINDCLOAK via Telegram C2

Detection engineering:

  • Flag outbound Telegram API traffic (api.telegram.org class destinations) from server or non user endpoint contexts

  • EDR alert on new persistence plus outbound messenger API patterns on government dense subnets

Immediate detection action (24h): Baseline and alert on any Telegram Bot API traffic from server subnets.

Hunt this week: 30 day egress review from Tier 0 and server VLANs for messenger API destinations; retain PCAP on first hit for protocol confirmation.

MCBS / DentaQuest post disclosure detection (associate side)

Detection engineering:

  • For business associates: heightened DLP and anomalous bulk export alerts on healthcare data stores

  • Vendor access review: disable stale VPN, B2B guest, and SFTP accounts tied to the disclosed entities until assurance letters arrive

Immediate detection action: Inventory all electronic connections to MCBS and DentaQuest ecosystems; alert on large outbound transfers from those integration identities.

Detection context quality

Need

Status in consulted sources

Sysmon/EDR process

Required; rules above are behavioral

IIS / SharePoint ULS

Required for web chain hunts

Windows Security on AD FS

Required for local EoP aftermath

API gateway logs for Langflow

Required for IDOR/prompt abuse

Check Point management audit

Required for token theft

Entra sign in logs

Required for Wi Fi harvest aftermath

Proxy / DNS / firewall egress

Required for Telegram and lure domains

Public ITW IOC lists

Absent → pure behavioral detection required

Coverage gap statement: With Total IOC Count 0, any stack that only matches blacklists will miss the active tradecraft described in consulted sources. Ship behavioral rules first; enrich IOCs later when published.

Evidence rule for this field
Consulted sources did not publish official vendor ATT&CK T number mappings for the Microsoft July 2026 zero days, Langflow KEV item, or SmartConsole exploitation. Secondary aggregator metadata supplied some technique tags that were not verified against full primary article text. This section therefore separates Mentioned (unconfirmed) from Inferred (analyst alignment from CVE/CWE/behavior). Inferred IDs support hunt coverage. They are not actor quality attributions and must not be briefed as vendor confirmed.

Enterprise ATT&CK matrix coverage (merged)

Tactic

Technique ID

Technique name

Layer

Cluster linkage

Initial Access

T1190

Exploit Public Facing Application

Inferred

SharePoint CVE-2026-56164 and companions; July unauth network RCE class; exposed Langflow/SmartConsole

Initial Access

T1566.002

Phishing: Spearphishing Link

Mentioned unconfirmed

SourTrade fake Solana/Luno/TradingView pages

Initial Access

T1133

External Remote Services

Inferred

Federation/AD FS plane; RDP when NLA disabled

Execution

T1204.001

User Execution: Malicious Link

Mentioned unconfirmed

SourTrade victim click path

Execution

T1059.001

PowerShell

Inferred

SharePoint worker child processes

Execution

T1059.003

Windows Command Shell

Inferred

SharePoint worker child processes

Execution

T1620

Reflective Code Loading

Inferred

SourTrade in memory PE assembly via Bun

Persistence

T1505.003

Web Shell

Inferred

SharePoint/IIS persistence narrative

Privilege Escalation

T1068

Exploitation for Privilege Escalation

Inferred

CVE-2026-56155 AD FS; CVE-2026-56164 SharePoint; CVE-2026-57092 VMSwitch

Defense Evasion

T1027

Obfuscated Files or Information

Mentioned unconfirmed

SourTrade delivery concealment

Defense Evasion

T1620

Reflective Code Loading

Inferred

File sparse memory assembly

Credential Access

T1040

Network Sniffing

Mentioned unconfirmed + inferred

Wi Fi gateway MITM

Credential Access

T1556

Modify Authentication Process

Mentioned unconfirmed

Gateway interception path

Credential Access

T1552.001

Credentials In Files

Inferred

Langflow flow secrets / API keys

Credential Access

T1552.004

Private Keys

Inferred

IIS machine key theft narrative

Credential Access

T1550

Use Alternate Authentication Material

Inferred

SmartConsole admin tokens; M365 token risk

Credential Access

T1003

OS Credential Dumping

Inferred follow on

Post EoP on AD FS/SharePoint hosts (tooling not named)

Credential Access

T1078

Valid Accounts

Inferred

Stolen M365 and federated sessions

Discovery

T1659

Content Injection

Inferred

Langflow prompt injection inside hijacked flows

Lateral Movement

T1078

Valid Accounts

Inferred

SSO blast radius after AD FS compromise

Lateral Movement

T1550

Alternate Authentication Material

Inferred

Token replay class risk

Collection

T1005

Data from Local System

Mentioned unconfirmed + inferred

MCBS/DentaQuest bulk data outcomes

Command and Control

T1071.001

Web Protocols

Mentioned unconfirmed + inferred

TELESHIM family Telegram/web style C2

Command and Control

T1105

Ingress Tool Transfer

Mentioned unconfirmed + inferred

TELESHIM / MIXEDKEY / BINDCLOAK delivery

Exfiltration

T1020

Automated Exfiltration

Mentioned unconfirmed + inferred

MCBS multi TB claim pattern

Impact

T1486

Data Encrypted for Impact

Mentioned unconfirmed

PEAR ransomware narrative (exfil/extortion emphasized more than confirmed encryption telemetry in available text)

Mapping by active problem set (operator view)

Identity and collaboration exploitation

  • Inferred: T1190, T1068, T1505.003, T1059.001, T1059.003, T1552.004, T1078, T1133

  • Official vendor map: not published in consulted sources

AI gateway KEV (Langflow)

  • Inferred: T1190 (if exposed), object level abuse as credential access T1552.001, T1659 Content Injection

  • Official vendor map: not published

Security management plane (SmartConsole)

  • Inferred: T1190, T1550, T1078

  • Official vendor map: not published

Wi Fi M365 harvest

  • Mentioned unconfirmed: T1040, T1556

  • Inferred follow on: T1078, T1550

SourTrade

  • Mentioned unconfirmed: T1566.002, T1204.001, T1027

  • Inferred: T1620

TELESHIM set

  • Mentioned unconfirmed: T1071.001, T1105

  • Inferred: same pair for egress hunting

Healthcare breach outcomes (MCBS, DentaQuest)

  • Mentioned unconfirmed: T1486, T1005, T1020

  • Root initial access technique: insufficient source data

Control coverage checklist (use as gap analysis, not attribution)

Technique emphasis

Control that should already exist

Gap if missing today

T1190 / T1068

Emergency patch SLA, attack surface reduction, WAF

Unpatched SharePoint/AD FS/edge roles

T1505.003

FIM on web trees, EDR webshell analytics

No ASPX integrity monitoring

T1552.004

Machine key rotation runbook

Patch without key rotation

T1078 / T1550

Phishing resistant MFA, Continuous Access Evaluation

Passwords only on M365

T1040 / T1556

Device compliant CA, VPN preference for mail

Travel auth allowed from any network

T1620 / T1027

Memory behavioral EDR

Hash only AV

T1071.001 / T1105

Egress allowlists on servers

Telegram API open from Tier 0

T1005 / T1020 / T1486

DLP, bulk export alerts, IR retainer

No exfil baseline

Chapter 05 - Governance, Risk & Compliance

SharePoint + AD FS exploitation: regulatory and business risk exposure

Regulatory exposure:

  • Entities under CISA BOD KEV obligations: track CVE-2026-56155 deadline 28 July 2026 and any remaining SharePoint KEV items (including CVE-2026-45659 class due dates; verify live catalog)

  • If compromise leads to personal data access: evaluate GDPR (72 hour supervisory authority notice), DPDP Act 2023 (India, relevant for Bengaluru operators), HIPAA only if PHI systems ride on affected identity/SharePoint, SEC cyber disclosure for US public companies upon materiality determination

  • Preserve volatile evidence (memory, IIS logs, AD FS audit) before rebuild

Business risk impact:

  • Operational: Federation outage or forced password/key rotation waves; SharePoint collaboration downtime

  • Reputational: Identity compromise narratives travel faster than patch notes

  • Financial: IR retainers, forced crypto key/certificate re issue, potential ransomware follow on (not confirmed in consulted sources)

Threat actor attribution:
No confirmed attribution available for these exploitation events.

CISO risk decision: Escalate — KEV deadline + dual ITW zero days on identity/collaboration plane.

Langflow KEV: regulatory and business risk exposure

Regulatory exposure:

  • API keys often unlock cloud tenants holding regulated data; treat key leak as potential personal data breach precursor

  • AI processing of personal data may engage DPIA obligations under GDPR/DPDP if agents handle PII

Business risk impact:

  • Shadow AI instances outside asset inventory = untracked blast radius

  • Cloud spend fraud and secondary tenant compromise after key theft

CISO risk decision: Escalate for any production/internet Langflow; monitor lab only air gapped instances after upgrade to 1.9.1+.

SmartConsole: regulatory and business risk exposure

  • Compromise of security management plane can falsify logs and weaken control evidence for SOC2/ISO 27001 audits

  • Downstream: incorrect firewall policy push can create silent exposure windows

CISO risk decision: Escalate if management GUIs were internet reachable; else monitor after patch verification and token reissue.

MCBS PEAR extortion and DentaQuest disclosure: regulatory and business risk exposure

Regulatory exposure:

  • HIPAA breach notification duties for covered entities and business associates once discovery thresholds are met

  • State breach statutes in the United States may impose shorter or parallel clocks

  • DentaQuest scale (23M+) implies multi jurisdiction notice complexity and potential regulator inquiry

  • MCBS ~1.2M individuals plus claimed 3 TB exfiltration under active extortion: treat notification readiness as same day legal work

  • International parents or processors: GDPR/DPDP assessment if any EU or Indian personal data was in scope

Business risk impact:

  • Reputational and financial risk is significant at DentaQuest scale; regulatory fines are plausible but not quantified in consulted sources

  • Contractual cascade: employer groups, provider networks, and BAAs may trigger customer notice and audit rights

  • Extortion pressure (PEAR/MCBS) adds availability and disclosure timing risk beyond pure confidentiality

Threat actor attribution:
PEAR named for MCBS only at Low confidence; no attribution offered for DentaQuest intrusion in consulted sources.

CISO risk decision:

  • Escalate if you are the victim, a business associate, or hold interconnected PHI with either entity

  • Monitor if no data sharing relationship exists, but still watch for secondary fraud using leaked demographics

Evidence and counsel rules:

  • Verify victim counts and dates against primary notices before external statements

  • Preserve logs; do not destroy backup media that may hold forensic value

  • Public CTI secondary counts are not a substitute for counsel driven notification analysis

M365 Wi Fi harvest: regulatory and business risk exposure

  • Credential theft can become a personal data breach if mailbox or Files content is accessed after takeover

  • Public company materiality analysis may apply if widespread executive account compromise occurs

  • Control failure narrative: lack of phishing resistant MFA is increasingly difficult to defend to auditors after an active network layer harvest pattern is known

CISO risk decision: Escalate MFA and Conditional Access gaps to emergency IAM change; do not leave as quarterly roadmap.

SourTrade: regulatory and business risk exposure

  • Financial services and crypto adjacent staff at risk of workstation compromise and subsequent payment fraud

  • If corporate banking users are hit, expect rapid fraud desk coordination and possible SAR processes depending on jurisdiction

CISO risk decision: Monitor with targeted EDR assurance for finance users; Escalate on first confirmed in memory Bun delivery hit.

TELESHIM set: regulatory and business risk exposure

  • Government Middle East targets: national security and public sector information classification regimes apply

  • Partners and contractors connected to those governments should assume heightened spillover risk

CISO risk decision: Escalate for government and defense contractors in region; monitor for others via Telegram egress baselining.

July high CVSS infrastructure items without ITW confirmation

  • Still material for safety and uptime risk (Hyper V guest to host, DHCP RCE, RDP without NLA)

  • Governance angle: document risk acceptance only with time bounded exceptions if patch delays are unavoidable

Board level risk summary (today)

Attackers are actively abusing unpatched Microsoft identity and SharePoint flaws while a US federal fix deadline for AD FS hits tomorrow. AI workflow software has entered the same must patch now catalog as traditional edge bugs. In parallel, healthcare breach math jumped on secondary reporting (about 24 million people across two disclosures), and credential theft is happening on the network path rather than only in the inbox. The board question is not “did we install Patch Tuesday?” It is “can we prove AD FS, SharePoint, Langflow, and SmartConsole are patched, keys and tokens rotated, M365 requires phishing resistant MFA, and we know whether we are a healthcare business associate in the MCBS/DentaQuest blast radius?”

Chapter 06 - Adversary Emulation

Scope caveat
No official vendor ATT&CK technique map was published in consulted sources for the ITW zero days. Emulation below is CVE behavior based and inferred technique based for purple team validation of controls. It is not a claim that a named actor playbook was reverse engineered from primary IR telemetry. Do not run offensive tests on production federation, healthcare data stores, or third party systems without written authorization.

Validation track: SharePoint chain (inferred T1190 / T1068 / T1505.003 / T1552.004)

Defensive validation objectives:

  • Prove July SharePoint updates are installed on every farm

  • Prove AMSI full body scan is active where still required as compensating control

  • Prove machine keys rotated after patch

  • Prove EDR alerts when w3wp.exe spawns shells

Authorized test ideas (lab or change window only):

  1. Pre/post patch configuration audit: build number and KB inventory versus Microsoft July 2026 baseline

  2. AMSI: verify integration on SharePoint/IIS worker processes and Request Body Scan = Full before and after patch

  3. FIM: touch a benign test ASPX in a non prod content path and confirm alert

  4. Purple process test in non prod: simulated child process from a test app pool identity to validate SIEM rule fire (no real exploit payload)

Pass criteria:

  • 100% internet reachable farms patched or isolated

  • Machine key rotation completed and documented

  • Alert fire on simulated worker child process within SOC MTTA target

Validation track: AD FS EoP (inferred T1068 / T1078)

Defensive validation objectives:

  • Prove CVE-2026-56155 cumulative is present before 28 July 2026 deadline

  • Prove low privilege interactive use on AD FS hosts is denied or closely watched

  • Prove federation change auditing is on

Authorized test ideas:

  1. Lab AD FS: confirm July cumulative installed; regression test federation login and claim rules

  2. Attempt standard user local logon to hardened AD FS PAW model (should fail)

  3. Review and tabletop the 14 to 28 July auth and group membership timeline query

Pass criteria:

  • Patch evidence attached to KEV ticket

  • No unexplained new local admins in window

  • Trust/claim rule changes require dual control

Validation track: Langflow KEV (inferred T1552.001 / T1659)

Defensive validation objectives:

  • Prove no instance below 1.9.1 is reachable

  • Prove cross user flow_id execution is denied

  • Prove secrets were rotated after exposure uncertainty

Authorized test ideas:

  1. Purple style check on patched non prod: authenticated user A requests user B flow_id on /api/v1/responses — expect deny

  2. Inject benign canary string prompt in owned flow only; ensure monitoring catches suspicious secret oriented prompts in logs

  3. Secret scan: confirm no long lived cloud keys remain in flow environment variables

Pass criteria:

  • Cross user execution denied

  • All production instances ≥ 1.9.1 or network isolated

  • Key rotation completion logged

Validation track: SmartConsole (inferred T1550 / T1078)

Defensive validation objectives:

  • Prove patched console versions only

  • Prove management GUI reachable only from jump hosts

  • Prove tokens issued outside jump hosts alert

Authorized test ideas:

  1. Connect attempt from a non jump host VLAN (should fail at network policy)

  2. Force logout all admin sessions post patch; require reauth

  3. Confirm audit log entries for token issue are ingested by SIEM

Pass criteria:

  • Zero successful admin authentications from non jump hosts in 72h soak

  • Patch level inventory complete

Validation track: M365 Wi Fi harvest aftermath (inferred T1040 / T1556 / T1078)

Defensive validation objectives:

  • Prove phishing resistant MFA enrollment ≥ policy threshold (target 100% for staff, especially travelers)

  • Prove Conditional Access blocks or challenges low posture devices on public networks

  • Prove SOC sees impossible travel / new device signals

Authorized test ideas:

  1. Tabletop: traveler on hospitality Wi Fi authenticates — expected controls and alerts

  2. Staged non prod CA policy test with a break glass account in lab tenant

  3. Sample 50 traveler accounts for MFA method quality (phishing resistant vs SMS)

Pass criteria:

  • SMS/voice not accepted as sole factor for corporate M365

  • CA reports show enforced device posture for Exchange/SharePoint Online

Validation track: SourTrade memory delivery (inferred T1620 / T1566.002)

Defensive validation objectives:

  • Prove EDR memory behavioral module enabled fleet wide

  • Prove Bun blocked or alerted where not approved

  • Prove proxy category controls for brand impersonation finance sites

Authorized test ideas:

  1. In detonation lab only: benign Bun execution from browser parent to test detect/block policy (no criminal payloads)

  2. EDR health check: memory scanning sensors reporting green on finance OU

  3. Application control report: Bun allowlist exceptions reviewed

Pass criteria:

  • Memory detections enabled >95% endpoints

  • Unapproved Bun execution generates ticket

Validation track: TELESHIM Telegram C2 (inferred T1071.001 / T1105)

Defensive validation objectives:

  • Prove server subnets cannot reach Telegram API without exception

  • Prove alert path works when exception tags are abused

Authorized test ideas:

  1. Controlled egress test from a lab server toward Telegram API endpoints — expect block+alert

  2. DNS/proxy sinkhole list includes known Telegram API FQDNs for server policies

Pass criteria:

  • Default deny on server VLANs

  • Alert to SOC within MTTA target

Validation track: healthcare associate readiness (impact T1005 / T1020 / T1486 class outcomes)

Defensive validation objectives (no offensive emulation against victim environments):

  • Prove BAA and data flow map for MCBS/DentaQuest relationships exists

  • Prove notification decision tree and counsel contact tree work under tabletop

  • Prove bulk export alerts fire on a synthetic large query in non prod data mart

Pass criteria:

  • Named counsel and privacy lead on call roster

  • Tabletop completes notification timeline without unresolved ownership gaps

Emulation schedule suggestion (next 72 hours)

Order

Track

Why this order

1

AD FS patch validation

KEV 28 July

2

SharePoint patch, AMSI, keys, worker child alert

ITW chain

3

Langflow version and cross user deny

KEV + keys

4

SmartConsole jump host and tokens

Management plane

5

M365 MFA/CA traveler scenarios

Active harvest pattern

6

EDR memory + Bun

SourTrade

7

Telegram server egress

TELESHIM

8

Healthcare associate tabletop

Regulatory clocks

Explicit non actions

  • Do not run public SharePoint or AD FS exploit code against production to “prove” ITW

  • Do not attempt real SmartConsole auth bypass outside vendor approved test guidance

  • Do not touch third party healthcare networks in the name of validation

  • Do not treat this chapter as a substitute for official ATT&CK mapped adversary emulation libraries until primary technique evidence improves

Intelligence Confidence61%

Component

Pull on score

Microsoft ITW + CrowdStrike aligned CVSS/CWE depth

Strong up

KEV deadline consistency for AD FS / SharePoint linked / Langflow

Strong up

SmartConsole ITW patch narrative

Moderate up

Same day fresh long form IR house volume

Down

Classic IOC availability

Hard down (0)

Actor attribution quality

Hard down

Official ATT&CK in consulted sources

Hard down

Healthcare breach scale via secondary news only

Down

Dual track merge complexity

Mild down