Last Updated On

Tomorrow AD FS Expires While 23 Million Dental Records Spill
Tomorrow the AD FS KEV clock hits zero while SharePoint and Langflow remain under confirmed abuse, and healthcare just put roughly twenty four million people on the notification board.
PEAR’s MCBS extortion claim and DentaQuest’s May intrusion disclosure land in the same cycle as SmartConsole admin token theft, Wi Fi gateway M365 harvest, SourTrade’s Bun backed in memory loaders, and a Telegram C2 malware set aimed at Middle East government targets.
Patch evidence, key and token rotation, phishing resistant MFA, and counsel verified breach duty matter more than waiting for a hash list that consulted sources still have not published.
9.9
CVSS Score
0
IOC Count
9
Source Count
61
Confidence Score
CVE-2026-56155, CVE-2026-56164, CVE-2026-45659, CVE-2026-50522, CVE-2026-58644, CVE-2026-55040, CVE-2026-55255, CVE-2026-16232, CVE-2026-57092, CVE-2026-56188, CVE-2026-50518, CVE-2026-56159, CVE-2026-55944, CVE-2026-56190, CVE-2026-55008, CVE-2026-48561, CVE-2026-50661, CVE-2026-33017
PEAR, East Asia linked actor, Under Attribution
Healthcare, Financial Services, Government, Enterprise Collaboration, Identity Infrastructure, AI Development Platforms, Security Operations
United States, Middle East, Global product exposure
Chapter 01 - Executive Overview
Over the last collection window, consulted sources show two simultaneous crisis tracks. Track one is confirmed active exploitation against identity, on premises collaboration, AI agent gateways, and security management consoles, with the AD FS KEV federal remediation deadline on 28 July 2026 now about one day away. Track two is breach and campaign pressure: PEAR extortion against MCBS (~3 TB claimed, ~1.2 million people), DentaQuest’s disclosure of a May 2026 intrusion affecting over 23 million people, Microsoft 365 credential theft via compromised public Wi Fi gateways, SourTrade in memory malware assembly with the Bun runtime, and an East Asia linked TELESHIM / MIXEDKEY / BINDCLOAK set using Telegram C2 against Middle East government targets. Highest product CVSS in the merged set reaches 9.9. No new nation state name was confirmed on the Microsoft zero day track. Overall merged confidence sits at 61.
SharePoint active chain — Critical — Enterprise collaboration / identity
Threat overview: Unauthenticated privilege elevation on SharePoint Server (CVE-2026-56164) is confirmed exploited in the wild. Related RCE and bypass issues (CVE-2026-45659 KEV linked; CVE-2026-50522 / CVE-2026-58644 at CVSS 9.8 Site Owner+; CVE-2026-55040 at CVSS 9.1) support a multi CVE path from web exposure toward deeper compromise, including reported IIS machine key theft for persistence.
Strategic risk: Internet facing or poorly segmented SharePoint remains a domain compromise path. Patching alone does not remove established footholds if keys or webshells remain.
Business impact: Collaboration outage, credential and token theft, regulatory notification risk if personal data is accessed.
Confidence: High on exploitation status in consulted vendor aligned sources; low on campaign IOC packages (none published).
Leader decision now: Emergency patch, IIS machine key rotation, and IR hunt on every internet reachable SharePoint farm before end of day. Enable AMSI with Request Body Scan = Full until patch validation completes.
AD FS zero day EoP — Critical — Identity / federation
Threat overview: CVE-2026-56155 (CVSS 7.8) is an actively exploited elevation of privilege in Active Directory Federation Services. A low privileged local attacker becomes administrator. Microsoft DART credit indicates discovery during incident response.
Strategic risk: AD FS compromise undermines federated SSO across cloud and partner apps.
Business impact: Identity takeover, lateral movement, prolonged undetected access, forced trust and certificate operations.
Confidence: High on exploitation and patch availability; technique level official ATT&CK IDs not published in consulted sources.
Leader decision now: Confirm AD FS patch deployment against the 28 July 2026 KEV deadline. Freeze nonessential federation changes until verified. Review local admin group churn on AD FS hosts since mid July.
Langflow AI framework KEV — High — AI / dev platforms
Threat overview: CVE-2026-55255 (reported CVSS 9.9) authorization bypass / IDOR in Langflow. CISA KEV listing with exploitation observed since ~25 June 2026 via hijacked flows and prompt injection to leak API keys. Versions before 1.9.1 in scope. Sibling CVE-2026-33017 called out in coverage as sometimes more reached despite lower score.
Strategic risk: AI agent gateways treated as lab tools become credential exfil paths into cloud tenants.
Confidence: Medium high on KEV and exploitation narrative in consulted sources; treat deep exploit tooling detail as partially verified where primary full text was not independently re fetched in every pass.
Leader decision now: Inventory all Langflow; enforce 1.9.1+ or isolate. Rotate every secret any flow could touch. Pull internet exposed instances behind SSO/mTLS.
Check Point SmartConsole zero day — High — Security operations tooling
Threat overview: CVE-2026-16232 authentication bypass in SmartConsole GUI. Unauthenticated attackers obtain admin login tokens. Vendor patched after active exploitation per consulted reporting.
Strategic risk: Security management plane compromise can weaken controls and falsify operational assurance.
Leader decision now: Confirm SmartConsole patch on all admin workstations. Restrict GUI to jump hosts. Revoke and reissue management tokens if the exposure window is unknown. Audit admin actions across the open window.
July Microsoft criticals without confirmed ITW — High patch priority — Infrastructure
Watch list: CVE-2026-57092 VMSwitch guest to host CVSS 9.9; CVE-2026-56188 network driver unauth RCE 9.8; DHCP CVE-2026-50518 / CVE-2026-56159 at 9.8; Dynamics NAV/BC CVE-2026-55944 at 9.8; RDP CVE-2026-56190 at 9.8 when NLA is off; BitLocker CVE-2026-50661 at 6.1 physical, not exploited per Microsoft characterization in consulted sources.
Leader decision now: Schedule behind AD FS and SharePoint but inside the same emergency CAB wave for internet exposed or high blast radius roles.
MCBS PEAR ransomware extortion — High — Healthcare
Threat overview: PEAR named in consulted secondary reporting against medical business manager MCBS. Claimed ~3 TB exfiltrated and ~1.2 million individuals affected, with active extortion pressure.
Strategic risk: Business associate cascade; HIPAA notification clocks; partner ecosystem contagion.
Confidence: Low on actor label; scale figures need primary notice verification.
Leader decision now: If you are MCBS or a business associate, open breach assessment and notification readiness immediately with counsel. Preserve logs before rebuild impulses.
DentaQuest large scale disclosure — High — Healthcare / dental
Threat overview: DentaQuest disclosed a May 2026 intrusion exposing personal and dental health data for over 23 million people, among the largest healthcare exposures reported this year in consulted coverage.
Strategic risk: Regulatory, contractual, and reputational exposure at population scale.
Confidence: Disclosure event well reported in secondary news; actor unattributed; vector not detailed.
Leader decision now: Legal and compliance assess federal and state exposure. Downstream employers and integrated care partners request official notice language, not social summary counts alone.
Public Wi Fi M365 credential harvesting — High — Enterprise travel / identity
Threat overview: Compromised public Wi Fi gateway appliances intercept authentication traffic and harvest Microsoft 365 credentials via man in the middle. User awareness training does not mitigate appliance level interception.
Leader decision now: IAM must mandate phishing resistant MFA for all M365 accounts without exception. Conditional Access should prefer compliant or hybrid joined devices and flag auth from untrusted networks.
SourTrade in memory malvertising — Medium — Financial / crypto
Threat overview: Fake Solana, Luno, and TradingView pages deliver JavaScript that assembles a Windows executable in browser memory using the legitimate Bun runtime, reducing file based AV visibility.
Leader decision now: SOC confirms memory behavioral detection is on. Application control policy for Bun where not required. User warning to trading and treasury populations is secondary to EDR capability.
TELESHIM malware trio — Medium — Government Middle East
Threat overview: East Asia linked actor (unnamed group) deploys TELESHIM, MIXEDKEY, and BINDCLOAK against Middle East government targets with Telegram as covert C2.
Leader decision now: Government and near government SOCs review egress policy for Telegram class traffic from servers and non user endpoints. Load family names into TI watch lists pending concrete IOCs.
Defender priority order (executive one screen)
AD FS CVE-2026-56155 (KEV deadline 28 July; identity crown jewel)
SharePoint CVE-2026-56164 plus related RCE/bypass/KEV set (ITW + chain + key rotation)
Langflow CVE-2026-55255 (KEV; API key harvest)
SmartConsole CVE-2026-16232 (admin plane tokens)
M365 phishing resistant MFA and Conditional Access (active Wi Fi harvest pattern)
MCBS / DentaQuest legal and associate response (regulatory clocks; data already reported stolen)
July 9.8–9.9 Microsoft infrastructure criticals without ITW confirmation
SourTrade memory detection + Bun control
TELESHIM Telegram egress baselining for government dense environments
Today’s intelligence quality
Strongest depth: Microsoft July Patch Tuesday ITW mechanics, CVSS/CWE tables, AMSI guidance, SmartConsole exploitation/patch narrative, KEV deadline framing.
Thinner depth: same day original long form from additional major IR houses; classic IOC packages; official ATT&CK; PEAR and East Asia actor enrichment; DentaQuest/MCBS primary root cause.
Merged confidence 61. Exploitation claims on the Microsoft and Check Point track are actionable now. Breach counts and actor names require primary verification before legal or public attribution language.
Chapter 02 - Threat & Exposure Analysis
Theme from consulted sources: identity and collaboration edges under confirmed exploitation, AI agent frameworks on the mandatory patch (KEV) list, security management plane token theft, plus a parallel breach and campaign track that abuses trusted infrastructure rather than fresh public exploits.
SharePoint unauthenticated EoP under active use (CVE-2026-56164 and companions)
Attack progression (source grounded): Missing authentication for a critical function (CWE-306) allows an unauthenticated remote attacker to elevate privileges over the network, no user interaction, low complexity. Microsoft recommends AMSI integrated with SharePoint/IIS worker processes and Request Body Scan = Full as pre patch mitigation.
Exploitability: CVSS 5.3 (Moderate) per vendor aligned severity labeling in consulted sources, yet exploited in the wild. No public exploit code at major analysis publish time.
Campaign indicators: Multi CVE SharePoint pressure also includes critical deserialization RCEs CVE-2026-50522 and CVE-2026-58644 (CVSS 9.8, Site Owner+), auth bypass CVE-2026-55040 (CVSS 9.1), and KEV linked SharePoint RCE CVE-2026-45659. Reported IIS machine key theft supports persistence after initial web exposure.
Actor identity: Under Attribution. Mandiant IR / Google Cloud researchers appear as discovery credits, not as threat actors.
Infrastructure fingerprinting: Insufficient source data for attacker ASN, registrar, or C2 reuse.
Sector / geographic exposure: Product driven global exposure wherever on premises SharePoint remains reachable; no sector locked targeting confirmed in consulted sources.
MITRE (inferred): T1190 Exploit Public Facing Application; T1068 Exploitation for Privilege Escalation; T1505.003 Web Shell; T1552.004 Private Keys (machine keys); T1059.001 / T1059.003 worker spawned shells. Official vendor T numbers not published in consulted sources.
AD FS local EoP zero day (CVE-2026-56155)
Attack progression: Insufficient granularity of access control (CWE-1220). Authorized low privileged local attacker elevates to administrator; no UI interaction required; low complexity.
Exploitability: CVSS 7.8; actively exploited; no public exploit code at analysis time in consulted sources.
Campaign indicators: DART credit implies live IR context. Microsoft did not publish exploitation TTPs in the material reviewed. Reported CISA KEV federal remediation deadline 28 July 2026.
Actor: Under Attribution.
Strategic exposure: Federation is a crown jewel. Host level admin on AD FS undermines SSO into cloud and partner applications even when cloud SaaS patch state is healthy.
MITRE (inferred): T1068; T1078 Valid Accounts (follow on federated session abuse); T1133 External Remote Services (federation plane). Official T numbers not published.
Langflow IDOR to prompt injected key theft (CVE-2026-55255)
Attack progression: Authenticated attacker supplies victim flow ID to
/api/v1/responses, executes another user’s flow, injects prompts (for example “leak api keys”) to harvest credentials and cloud resources. Affects versions before 1.9.1. First exploitation reported ~25 June 2026.Exploitability: Reported CVSS 9.9; CISA KEV. Sibling CVE-2026-33017 (lower score) reportedly exploited more often in some coverage, showing reachability can outrank raw CVSS.
Actor: Under Attribution.
Strategic exposure: Shadow AI and “lab only” agent gateways often sit outside formal asset inventory, yet hold long lived cloud keys inside flow context.
MITRE (inferred): T1190 (if exposed); T1659 Content Injection; T1552.001 Credentials in Files / flow secrets; Discovery via object IDOR. Official T numbers not published.
SmartConsole authentication bypass (CVE-2026-16232)
Attack progression: Unauthenticated attacker obtains application login token usable for administrator authentication to the SmartConsole GUI.
Exploitability: Actively exploited prior to vendor patch per consulted reporting. Numeric CVSS not published in retrieved text; urgency is ITW plus management plane blast radius.
Actor: Under Attribution.
Strategic exposure: Security operations tooling compromise can weaken controls, alter policy, and undermine assurance evidence.
MITRE (inferred): T1190; T1550 Use Alternate Authentication Material; T1078. Official T numbers not published.
July criticals without confirmed in the wild use (patch priority)
CVE | Product | CVSS | Notes from consulted sources |
|---|---|---|---|
CVE-2026-57092 | Windows VMSwitch | 9.9 | Guest to host EoP via Hyper V vSwitch use after free (CWE-416) |
CVE-2026-56188 | Windows Server network driver | 9.8 | Unauth RCE via crafted traffic; race condition (CWE-362) |
CVE-2026-50518 / CVE-2026-56159 | DHCP Server | 9.8 | Unauth RCE heap overflows |
CVE-2026-55944 | Dynamics NAV / BC on premises | 9.8 | Unauth RCE via crafted login |
CVE-2026-56190 | RDP (NLA disabled) | 9.8 | Unauth RCE; discovery credit noted in analyses |
CVE-2026-50661 | BitLocker | 6.1 | Physical bypass; disclosed; not exploited per Microsoft characterization |
PEAR ransomware against MCBS (data theft and extortion)
Attack progression: Initial access vector not disclosed in consulted sources. PEAR exfiltrated a claimed ~3 TB before extortion pressure against medical business manager MCBS, affecting ~1.2 million individuals.
Exploitability: No CVE or technical exploit chain published.
Actor identity: PEAR (named in secondary reporting). Attribution confidence Low. Under Attribution for nation state or cross campaign linkage.
Sector exposure: Healthcare and medical business process ecosystems; business associate cascade likely.
Geographic exposure: United States implied by coverage framing; not a globally tagged campaign in source text.
MITRE (mentioned unconfirmed / inferred): T1486; T1005; T1020. Confirm against primary notices before legal language hardens.
DentaQuest large scale health data exposure
Attack progression: Intrusion occurred May 2026; network breach vector not disclosed. Public disclosure landed in this reporting cycle.
Scale: Over 23 million people with personal and dental health data exposed. Scale is the primary risk driver, not published technical sophistication.
Actor: Under Attribution. No CVE.
Sector exposure: Healthcare / dental benefits and payers; employer group downstream risk.
MITRE (inferred impact pattern): T1005; T1020 class outcomes without confirmed tooling names.
M365 credential harvesting via compromised Wi Fi gateways
Attack progression: Attacker compromises the Wi Fi gateway appliance, then intercepts authentication traffic from connected devices via man in the middle, harvesting Microsoft 365 credentials.
TTP indicators: T1040 Network Sniffing; T1556 Modify Authentication Process (aggregator tagged in secondary metadata, not fully primary confirmed); inferred T1078 / T1550 for stolen session or password reuse follow on.
Actor: Under Attribution.
Sector exposure: Any enterprise with traveling staff; professional services and executive travel densest.
Why training fails: The interception sits on the network path, not in the user’s inbox.
SourTrade in memory malware assembly via Bun runtime
Attack progression: Victim visits a fake Solana, Luno, or TradingView page. Malicious JavaScript instructs the browser to assemble a Windows PE directly in memory using the legitimate Bun runtime, avoiding a clean on disk first stage.
TTP indicators: T1566.002; T1204.001; T1027; T1620 Reflective Code Loading (inferred). Aggregator tags unconfirmed against full primary text.
Actor: Under Attribution.
Sector exposure: Financial services and cryptocurrency trading users.
Detection implication: File hash AV alone is the wrong primary control.
TELESHIM novel malware trio via Telegram C2
Attack progression: East Asia linked actor deploys TELESHIM, MIXEDKEY, and BINDCLOAK against Middle East government entities, routing C2 through Telegram to blend with allowed traffic.
TTP indicators: T1071.001; T1105 (mentioned unconfirmed / inferred).
Attribution: East Asia linked, not a named MITRE group. Confidence Low given single cycle secondary depth.
Sector / geo: Government Middle East focus in consulted sources.
Cross incident pattern analysis
Shared vulnerability pattern: pre auth or low privilege paths into high impact identity, collaboration, management, and AI flow control planes (SharePoint, AD FS, SmartConsole, Langflow).
Shared campaign pattern: abuse of trusted or legitimate infrastructure (Wi Fi appliances, Telegram, Bun runtime) to evade controls, rather than dependence on a brand new public CVE for every intrusion.
Healthcare pattern: exfiltration first and disclosure scale dominate; root vector opacity remains.
No shared IOC, named actor, or single CVE technically binds PEAR, TELESHIM, SourTrade, Wi Fi harvest, and the Microsoft ITW set into one campaign. Linkage is tradecraft level, not infrastructure level.
Board relevant synthesis: unpatched identity and collaboration flaws are under active abuse while a US federal AD FS fix deadline hits tomorrow, and separately attackers are stealing health data and credentials without needing a zero day headline every time.
Chapter 03 - Operational Response
Operational posture from consulted sources: identity plus SharePoint emergency patch and hunt; treat AD FS KEV deadline as hard stop; close AI gateway and management console exposure; force phishing resistant M365 controls for travel heavy populations; run healthcare legal tracks in parallel because data is already reported stolen.
SharePoint active chain: immediate response and containment
Containment priorities:
Do this NOW: Identify all internet facing and partner facing SharePoint Server instances; restrict to VPN or Zero Trust if unpatched.
Do this NOW: Deploy July 2026 SharePoint security updates including CVE-2026-56164 and related critical SharePoint CVEs (CVE-2026-50522, CVE-2026-58644, CVE-2026-55040, KEV linked CVE-2026-45659 as applicable).
Do this within 24 hours: Rotate IIS machine keys; hunt webshells, anomalous
w3wp.exechild processes, and unexpected SharePoint feature or timer job changes.Enable AMSI on SharePoint with Request Body Scan = Full until fully patched and validated.
Security hardening actions:
Remove SharePoint from direct internet exposure where business allows.
Enforce least privilege Site Owner roles (critical RCEs require Site Owner+).
Snapshot forensic images before mass remediation if compromise is suspected.
Internal security coordination:
Notify: Vuln Mgmt, IR, Identity, SharePoint platform owners, CISO.
Escalation trigger: webshell, stolen machine keys, or lateral movement from SharePoint host toward Domain Admin path.
External notification: only if confirmed personal data access per legal counsel (no named victim org breach confirmation for this SharePoint cluster in consulted sources this window).
AD FS CVE-2026-56155: immediate response and containment
Containment priorities:
Do this NOW: Inventory all AD FS servers; apply July 2026 AD FS update for CVE-2026-56155.
Do this within 24 hours: Review local privileged group membership and recent AD FS configuration or export changes; reset credentials for accounts that had low privilege shell access to AD FS hosts.
Validate KEV deadline compliance path for 28 July 2026.
Security hardening actions:
Harden AD FS admin tier (PAW, no email or browse on AD FS hosts).
Monitor federation trust and claim rule modifications.
Internal security coordination:
Notify Identity/IAM, Tier 0 owners, SOC.
Escalation: unexplained admin token issuance or trust changes after the exploitation window.
Langflow CVE-2026-55255: immediate response and containment
Containment priorities:
Do this NOW: Find Langflow instances; upgrade to 1.9.1+ or isolate from the network.
Do this within 24 hours: Rotate all API keys and secrets accessible to flows; review flow execution logs for foreign flow IDs and prompt injection strings.
Security hardening actions:
Put SSO/mTLS in front of any agent UI/API; never expose unauthenticated.
Least privilege tool credentials for agents (no long lived cloud keys in flow context).
SmartConsole CVE-2026-16232: immediate response and containment
Do this NOW: Apply Check Point SmartConsole fix; restrict management GUI to jump hosts.
Do this within 24 hours: Invalidate management sessions and tokens; audit admin actions during the exposure window.
MCBS and DentaQuest: immediate response and containment
Containment priorities:
If your organization is MCBS, DentaQuest, or a business associate, initiate vendor breach assessment now.
Engage legal counsel on HIPAA notification timelines immediately; preserve evidence before rebuild.
Review exfiltration monitoring and internal data access logging (directional T1020 / T1005 alignment only).
Downstream partners request official notice language; do not rely on social count summaries alone.
Coordination note: Response steps that imply victim environment changes require vendor or primary advisory confirmation. Consulted coverage is secondary for these two disclosures.
M365 credential harvesting via Wi Fi gateways: immediate response and containment
Do this NOW: Mandate phishing resistant MFA for all Microsoft 365 accounts without exception.
Do this within 24 hours: Review Conditional Access to require compliant or hybrid joined devices; flag authentication from untrusted or public network ranges.
Reset credentials and revoke sessions for users with travel correlated anomalous sign ins in the last 30 days.
SourTrade: immediate response and containment
Do this NOW: Confirm memory based behavioral detection (not file scan only) is active on endpoints.
Do this within 24 hours: Assess whether the Bun runtime is present or permitted; restrict via application control if not needed.
Warn treasury, trading, and crypto adjacent staff that fake Solana, Luno, and TradingView pages are active lure themes.
TELESHIM family: immediate response and containment
Do this NOW: Review network egress policy for Telegram traffic from servers and non user endpoints.
Do this within 24 hours: Load TELESHIM / MIXEDKEY / BINDCLOAK names into threat intel watches; concrete IOCs were not available in consulted sources at brief time.
Government dense environments baseline and alert on Telegram Bot API traffic from server subnets.
July infrastructure criticals (no ITW confirmation): response
Patch CVE-2026-57092, CVE-2026-56188, DHCP CVE-2026-50518 / CVE-2026-56159, CVE-2026-55944, and CVE-2026-56190 (if NLA disabled) inside the same emergency wave after identity and SharePoint.
BitLocker CVE-2026-50661: reinforce physical custody and lost device playbooks rather than internet emergency change.
Defender priority order (today)
AD FS CVE-2026-56155 — KEV deadline 28 July; identity crown jewel
SharePoint CVE-2026-56164 + related RCE/bypass/KEV set — confirmed ITW + chain potential + key rotation
Langflow CVE-2026-55255 — KEV, API key harvest pattern
SmartConsole CVE-2026-16232 — admin plane token theft
M365 phishing resistant MFA + Conditional Access — active Wi Fi harvest pattern, broadest identity blast radius for travelers
MCBS / DentaQuest legal and associate track — regulatory urgency; containment is largely post hoc because data is already reported stolen
Unauth network RCEs (CVE-2026-56188, DHCP 9.8s, RDP CVE-2026-56190 if NLA off) and VMSwitch CVE-2026-57092 — high blast radius even without ITW confirmation
SourTrade — memory detection and Bun control
TELESHIM set — Telegram egress baselining for government focused estates
SharePoint and July zero days
Date | Event |
|---|---|
2026 07 01 | CVE-2026-45659 (SharePoint RCE) reported added to CISA KEV per multi source brief citing KEV catalog activity |
2026 07 14 | Microsoft July 2026 Patch Tuesday: CVE-2026-56164 and CVE-2026-56155 fixed; both marked exploited in the wild; major analyses publish |
2026 07 14 | SharePoint hardening alert / KEV related actions cited alongside the patch wave |
2026 07 17 | Reported federal remediation deadline for CVE-2026-45659 (KEV linked) |
2026 07 26 to 2026 07 27 | No new deep technical package located in open retrieval for this 24h window; exploitation status remains confirmed from 14 Jul disclosures; operational urgency driven by residual unpatched estates and AD FS deadline |
AD FS CVE-2026-56155
Date | Event |
|---|---|
Date unconfirmed | Exploitation in the wild prior to patch (vendor aligned consulted sources) |
2026 07 14 | Patch released; DART researchers credited |
2026 07 27 | Status: patch available; deadline ~24h away for BOD covered entities |
2026 07 28 | Reported CISA KEV federal remediation deadline |
Langflow CVE-2026-55255
Date | Event |
|---|---|
2026 06 25 | First exploitation observed (Sysdig as cited in consulted coverage) |
2026 07 07 | CISA KEV addition cited (three vuln alert framing) |
2026 07 26 to 2026 07 27 | Still relevant for any unpatched AI stack inventory; fix bar 1.9.1+ |
SmartConsole CVE-2026-16232
Date | Event |
|---|---|
2026 07 22 | Consulted reporting: Check Point patched actively exploited SmartConsole zero day; admin login token theft pattern described |
2026 07 27 | Status: patch available; hunt residual admin token abuse if management plane was exposed |
MCBS and DentaQuest
Date | Event |
|---|---|
May 2026 (day not published) | DentaQuest network intrusion occurs per consulted reporting |
Date unconfirmed | MCBS intrusion and PEAR exfiltration begin; start day not published in available text |
2026 07 27 cycle | Both MCBS (PEAR, ~3 TB claimed, ~1.2M individuals) and DentaQuest (23M+ personal and dental health records) publicly disclosed via secondary security news in this cycle |
Wi Fi harvest, SourTrade, TELESHIM
Date | Event |
|---|---|
Insufficient source data | No firm first seen day for Wi Fi gateway M365 harvesting beyond active as of this cycle |
Insufficient source data | No firm first seen day for SourTrade Bun in memory malvertising beyond active campaign status |
Insufficient source data | No firm first seen day for TELESHIM / MIXEDKEY / BINDCLOAK beyond active reporting against Middle East government targets |
Collection window for this daily record
Date | Event |
|---|---|
2026 07 26 15:00 IST → 2026 07 27 21:26 IST | Intelligence collection window feeding the merged brief |
2026 07 27 | Report date (Monday) |
Timeline reading guide for operators
Compliance clocks: AD FS → 2026 07 28; SharePoint KEV linked items → verify live catalog (17 July class dates may already be overdue for covered entities).
Healthcare legal clocks: run from organizational discovery and applicable HIPAA / state law, not from Patch Tuesday.
First Observed Date at record level remains 2026 06 25 (Langflow exploitation anchor at day resolution).
Chapter 04 - Detection Intelligence
CVE-2026-56164: SharePoint missing authentication EoP
Attack vector: Network, unauthenticated.
Exploitation mechanism: Missing authentication for a critical function (CWE-306); remote elevation over network; low complexity; no user interaction.
Observed behavior: Exploited in the wild; public exploit code not disclosed at major analysis time. Pre patch: AMSI on SharePoint/IIS with full POST body scan.
Vulnerability details: Microsoft SharePoint Server; severity labeled Moderate by Microsoft despite ITW use.
CVE technical context: CVSS 5.3 in vendor aligned tables in consulted sources.
Patch status: Patched 14 July 2026 Patch Tuesday.
Chain context: Pair with CVE-2026-50522 / CVE-2026-58644 (CWE-502 deserialization RCE as Site Owner+, CVSS 9.8), CVE-2026-55040 (CWE-1390 weak authentication, unauth bypass/impersonation, CVSS 9.1), and KEV linked CVE-2026-45659. Persistence narrative includes IIS machine key theft and webshell class artifacts.
CVE-2026-56155: AD FS insufficient access control granularity
Attack vector: Local, low privileged authorized user.
Exploitation mechanism: CWE-1220 insufficient granularity of access control → administrator.
Observed behavior: ITW exploitation; no public exploit code at analysis time; discovered via DART IR activity.
CVSS: 7.8 Important.
Patch status: Patched 14 July 2026.
Operational technical note: Host admin on AD FS is an identity system compromise even without a separate cloud SaaS CVE.
CVE-2026-57092: VMSwitch guest to host
Mechanism: Use after free (CWE-416) via crafted network related requests from guest through Hyper V Virtual Switch; CVSS 9.9.
Patch status: Patched; exploitation ITW not stated in consulted sources.
CVE-2026-56188: Windows Server network driver RCE
Mechanism: Race condition (CWE-362); unauthenticated remote RCE via crafted network traffic; CVSS 9.8.
Patch status: Patched; ITW not stated.
CVE-2026-50518 / CVE-2026-56159: DHCP Server
Mechanism: Unauthenticated RCE via heap overflow class issues; CVSS 9.8.
Patch status: Patched; ITW not stated.
CVE-2026-55944: Dynamics NAV / Business Central on premises
Mechanism: Unauthenticated RCE via crafted login; CVSS 9.8.
Patch status: Patched; ITW not stated.
CVE-2026-56190: RDP with NLA disabled
Mechanism: Unauthenticated RCE when NLA is disabled; CVSS 9.8.
Patch status: Patched; ITW not stated. Discovery credit noted in consulted analyses.
CVE-2026-50661: BitLocker bypass
Mechanism: Protection mechanism failure (CWE-693); physical access; CVSS 6.1; publicly disclosed; no ITW evidence; Microsoft exploitation “less likely” in consulted characterization.
Patch status: Patched / update per July wave; treat as physical threat model.
CVE-2026-55255: Langflow IDOR
Mechanism: IDOR on
/api/v1/responsesenables execution of another user’s flow; combined with prompt injection for secret leakage. Versions before 1.9.1.Observed behavior: Exploitation since ~25 June 2026; API key and cloud credential harvest pattern; on CISA KEV.
Patch status: 1.9.1+.
Sibling: CVE-2026-33017 lower score but reportedly more often reached in some coverage.
CVE-2026-16232: SmartConsole
Mechanism: Authentication bypass → application login token with admin privileges to SmartConsole GUI.
Observed behavior: Actively exploited before patch per consulted reporting.
Patch status: Vendor addressed per 22 July class reporting.
PEAR / MCBS technical view
Attack vector: Unconfirmed in consulted sources.
Exploitation mechanism: Not published (no CVE).
Observed behavior: Claimed ~3 TB exfiltration; extortion pressure; ~1.2M individuals in notification scope.
Patch status: N/A (breach outcome cluster).
DentaQuest technical view
Attack vector: Network intrusion May 2026; vector not disclosed.
Exploitation mechanism: Not published.
Observed behavior: 23M+ personal and dental health records exposed; disclosure in current cycle.
Patch status: N/A.
M365 Wi Fi gateway harvesting technical view
Attack vector: Network adjacent compromised Wi Fi gateway appliance.
Exploitation mechanism: Man in the middle interception of authentication traffic at the gateway level.
Patch status: N/A as a classic software CVE in consulted text; appliance compromise mechanism not detailed.
Control plane that matters: Phishing resistant MFA, Conditional Access device posture, session revocation, token protection features where licensed.
SourTrade technical view
Attack vector: Web based malvertising lure pages (fake Solana / Luno / TradingView).
Exploitation mechanism: Malicious JS instructs browser to assemble a Windows PE in memory using the Bun runtime; no full malicious file required on disk during initial delivery.
Patch status: N/A (delivery technique campaign).
Control plane that matters: Memory behavioral EDR, application control on Bun, browser isolation for high risk user groups.
TELESHIM / MIXEDKEY / BINDCLOAK technical view
Attack vector: Not fully detailed; government targeted delivery implied.
Exploitation mechanism: Three family malware set with Telegram covert C2 to blend with allowed traffic.
Patch status: N/A.
Control plane that matters: Egress filtering and detection for Telegram API from servers; EDR family detections when samples appear.
Technical analysis quality note
Vulnerability track mechanics (CWE, CVSS, vector, patch day) are the strongest technical layer in consulted sources. Breach and campaign clusters are outcome and tradecraft rich but root cause poor. Do not invent exploit primitives where sources are silent.
Indicators of compromise (all clusters)
Type | Value | Context | Verdict |
|---|---|---|---|
CVE ID | CVE-2026-56155 | AD FS EoP zero day ITW; KEV deadline 28 July 2026 | Tracking (not a network IOC) |
CVE ID | CVE-2026-56164 | SharePoint EoP zero day ITW | Tracking |
CVE ID | CVE-2026-45659 | SharePoint RCE KEV linked | Tracking |
CVE ID | CVE-2026-50522 | SharePoint deserialization RCE CVSS 9.8 | Tracking |
CVE ID | CVE-2026-58644 | SharePoint deserialization RCE CVSS 9.8 | Tracking |
CVE ID | CVE-2026-55040 | SharePoint auth bypass CVSS 9.1 | Tracking |
CVE ID | CVE-2026-55255 | Langflow IDOR KEV; exploit since ~25 June 2026 | Tracking |
CVE ID | CVE-2026-33017 | Langflow sibling; reachability note in coverage | Tracking |
CVE ID | CVE-2026-16232 | SmartConsole auth bypass ITW | Tracking |
CVE ID | CVE-2026-57092 | VMSwitch guest to host CVSS 9.9 | Tracking |
CVE ID | CVE-2026-56188 | Network driver unauth RCE CVSS 9.8 | Tracking |
CVE ID | CVE-2026-50518 | DHCP unauth RCE CVSS 9.8 | Tracking |
CVE ID | CVE-2026-56159 | DHCP unauth RCE companion | Tracking |
CVE ID | CVE-2026-55944 | Dynamics NAV/BC on prem unauth RCE | Tracking |
CVE ID | CVE-2026-56190 | RDP unauth RCE if NLA off | Tracking |
CVE ID | CVE-2026-55008 | July Microsoft set rollup item | Tracking |
CVE ID | CVE-2026-48561 | July Microsoft set rollup item | Tracking |
CVE ID | CVE-2026-50661 | BitLocker physical bypass; not ITW | Tracking |
IP address | None published | All clusters | Absent |
Domain | None published as attacker infra | All clusters | Absent |
URL | No stable malicious lure URLs published | SourTrade described thematically only | Absent |
File hash | None published | SourTrade, TELESHIM family, PEAR payloads, webshells | Absent |
None published | All clusters | Absent | |
Wallet / payment | None published | PEAR extortion | Absent |
Telegram bot ID | None published | TELESHIM C2 | Absent |
Total classic network/file IOC count: 0 (matches Total IOC Count field). CVE rows are catalog tracking keys, not blocklist IOCs.
Malware and campaign labels (watchlist seeds, not IOCs)
Label | Type | Notes |
|---|---|---|
PEAR | Ransomware operator label | MCBS extortion; Low attribution confidence |
TELESHIM | Malware family | Middle East government focus; Telegram C2 |
MIXEDKEY | Malware family | Same set as TELESHIM |
BINDCLOAK | Malware family | Same set as TELESHIM |
SourTrade | Campaign label | Bun backed in memory PE assembly via fake trading pages |
Bun | Legitimate runtime abused | Application control candidate where not required |
Infrastructure patterns
Insufficient source data for attacker ASN, bulletproof hosting, registrar reuse, or shared C2 across clusters.
Defender relevant legitimate infrastructure abused or implicated (not attacker owned IOCs):
Public Wi Fi gateway appliances (compromise locus for M365 MITM)
Telegram API / Bot API style egress (TELESHIM blend in)
Bun JavaScript runtime (SourTrade in memory assembly)
SharePoint/IIS worker process space and machine key material (persistence locus)
Langflow
/api/v1/responsesobject model (IDOR locus)Check Point SmartConsole management path (token minting locus)
No evidence in consulted sources that PEAR, TELESHIM, SourTrade, and Microsoft ITW exploitation share one backbone.
Actor normalization evidence
Insufficient source data to collapse PEAR and the East Asia linked TELESHIM operator into one identity.
Insufficient source data to attribute Microsoft or Check Point ITW exploitation to either named label.
Discovery credits (DART, Mandiant IR, Google Cloud researchers, select CVE discovery credits) are researcher identities only.
Enrichment posture
IOC Enrichment Status remains Pending.
Open TI watchers on all CVE IDs and family labels above.
Do not fabricate placeholder IPs, domains, or hashes to fill this table.
When first concrete indicator publishes, version this record, increment Total IOC Count, and flip enrichment state.
Practical “indicator substitutes” for SIEM loading today
These are detection pivots, not IOCs:
Process:
w3wp.exe→cmd.exe/powershell.exe/pwsh.exe/certutil.exeFile: unexpected ASPX under SharePoint layouts/content trees
Config: IIS machine key / web.config changes outside change windows
Identity: Entra sign in anomalies from public Wi Fi ranges; new device registration; impossible travel
API: Langflow POST
/api/v1/responseswhere flow owner ≠ session user; body strings suggesting secret exfilEgress: Telegram API from server subnets
Endpoint: Bun execution from browser parents where Bun is not approved
Management: SmartConsole login or token issue from non jump host IPs
SharePoint unauth EoP and deserialization path
Detection engineering opportunities:
Alert on SharePoint /
w3wp.exespawning shells (cmd.exe,powershell.exe,pwsh,certutil,bitsadmin) or writing ASPX under SharePoint layouts/content treesAlert on AMSI blocks in SharePoint worker processes after enabling full request body scan
Alert on IIS machine key / web.config modifications outside change windows
Alert on anomalous POST volume to
_vti_style and SharePoint API endpoints from external networks
Immediate detection action (24h): Deploy process creation correlation: parent w3wp.exe + SharePoint app pool → suspicious children.
Hunt this week: Historical 30 day review of SharePoint servers for webshell file creates, unexpected ASPX, and machine key churn since 14 July 2026.
SIGMA pseudocode (behavioral; not a vendor published rule):
YARA pattern concept (webshell hunt; generic, not vendor supplied):
SIEM field logic:
Network: Spike in external POSTs to SharePoint with large bodies; new outbound from SharePoint hosts to rare destinations.
AD FS local EoP
Immediate detection action: Monitor AD FS hosts for unexpected local privilege changes, new local admins, and AD FS service account token anomalies after any low privilege logon.
Hunt this week: 14 to 28 July window: interactive/local logons by non admin users on AD FS servers followed by admin equivalent activity within 1 hour.
SIGMA pseudocode:
SIEM:
EDR: Alert on non SYSTEM processes loading AD FS configuration modules then spawning whoami/net group.
Langflow IDOR and prompt injection
Immediate detection action: WAF/API log rule: authenticated user A executing flow_id owned by user B on /api/v1/responses.
SIGMA like API pseudocode:
Hunt this week: API keys created or rotated outside CI; LLM provider billing spikes from Langflow service identities; versions still below 1.9.1 on any host.
SmartConsole token theft
Immediate detection action: Management audit log for admin sessions from new IPs or workstations without prior device posture; token minting without interactive MFA path.
SIEM:
M365 credential harvesting via compromised Wi Fi gateways
Detection engineering:
Monitor Entra ID / Azure AD sign in logs for impossible travel, unfamiliar device registration, and token replay indicators
Correlate successful sign ins with source networks classified as public Wi Fi or unknown hospitality ranges
Immediate detection action (24h): Enable Conditional Access alerts for auth from non corporate / public IP ranges.
Hunt this week: Review 30 day M365 sign in logs for travel correlated anomalous logins; revoke sessions and require password reset plus phishing resistant MFA enrollment where gaps exist.
SIEM pseudocode (illustrative):
SourTrade browser memory malware assembly
Detection engineering:
Alert on browser processes making unusual memory allocation or execution calls consistent with in process code assembly
Monitor for Bun runtime execution where not expected in the environment
Alert on browser parent spawning Bun or anomalous PE mapping without a prior reputable installer event
Immediate detection action (24h): Confirm EDR memory behavioral modules are enabled, not solely file hash or signature based.
Hunt this week: Search for Bun runtime binaries or child processes spawned from browser processes across the endpoint fleet; review proxy logs for themed lure hostnames impersonating Solana, Luno, or TradingView.
TELESHIM / MIXEDKEY / BINDCLOAK via Telegram C2
Detection engineering:
Flag outbound Telegram API traffic (
api.telegram.orgclass destinations) from server or non user endpoint contextsEDR alert on new persistence plus outbound messenger API patterns on government dense subnets
Immediate detection action (24h): Baseline and alert on any Telegram Bot API traffic from server subnets.
Hunt this week: 30 day egress review from Tier 0 and server VLANs for messenger API destinations; retain PCAP on first hit for protocol confirmation.
MCBS / DentaQuest post disclosure detection (associate side)
Detection engineering:
For business associates: heightened DLP and anomalous bulk export alerts on healthcare data stores
Vendor access review: disable stale VPN, B2B guest, and SFTP accounts tied to the disclosed entities until assurance letters arrive
Immediate detection action: Inventory all electronic connections to MCBS and DentaQuest ecosystems; alert on large outbound transfers from those integration identities.
Detection context quality
Need | Status in consulted sources |
|---|---|
Sysmon/EDR process | Required; rules above are behavioral |
IIS / SharePoint ULS | Required for web chain hunts |
Windows Security on AD FS | Required for local EoP aftermath |
API gateway logs for Langflow | Required for IDOR/prompt abuse |
Check Point management audit | Required for token theft |
Entra sign in logs | Required for Wi Fi harvest aftermath |
Proxy / DNS / firewall egress | Required for Telegram and lure domains |
Public ITW IOC lists | Absent → pure behavioral detection required |
Coverage gap statement: With Total IOC Count 0, any stack that only matches blacklists will miss the active tradecraft described in consulted sources. Ship behavioral rules first; enrich IOCs later when published.
Evidence rule for this field
Consulted sources did not publish official vendor ATT&CK T number mappings for the Microsoft July 2026 zero days, Langflow KEV item, or SmartConsole exploitation. Secondary aggregator metadata supplied some technique tags that were not verified against full primary article text. This section therefore separates Mentioned (unconfirmed) from Inferred (analyst alignment from CVE/CWE/behavior). Inferred IDs support hunt coverage. They are not actor quality attributions and must not be briefed as vendor confirmed.
Enterprise ATT&CK matrix coverage (merged)
Tactic | Technique ID | Technique name | Layer | Cluster linkage |
|---|---|---|---|---|
Initial Access | T1190 | Exploit Public Facing Application | Inferred | SharePoint CVE-2026-56164 and companions; July unauth network RCE class; exposed Langflow/SmartConsole |
Initial Access | T1566.002 | Phishing: Spearphishing Link | Mentioned unconfirmed | SourTrade fake Solana/Luno/TradingView pages |
Initial Access | T1133 | External Remote Services | Inferred | Federation/AD FS plane; RDP when NLA disabled |
Execution | T1204.001 | User Execution: Malicious Link | Mentioned unconfirmed | SourTrade victim click path |
Execution | T1059.001 | PowerShell | Inferred | SharePoint worker child processes |
Execution | T1059.003 | Windows Command Shell | Inferred | SharePoint worker child processes |
Execution | T1620 | Reflective Code Loading | Inferred | SourTrade in memory PE assembly via Bun |
Persistence | T1505.003 | Web Shell | Inferred | SharePoint/IIS persistence narrative |
Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Inferred | CVE-2026-56155 AD FS; CVE-2026-56164 SharePoint; CVE-2026-57092 VMSwitch |
Defense Evasion | T1027 | Obfuscated Files or Information | Mentioned unconfirmed | SourTrade delivery concealment |
Defense Evasion | T1620 | Reflective Code Loading | Inferred | File sparse memory assembly |
Credential Access | T1040 | Network Sniffing | Mentioned unconfirmed + inferred | Wi Fi gateway MITM |
Credential Access | T1556 | Modify Authentication Process | Mentioned unconfirmed | Gateway interception path |
Credential Access | T1552.001 | Credentials In Files | Inferred | Langflow flow secrets / API keys |
Credential Access | T1552.004 | Private Keys | Inferred | IIS machine key theft narrative |
Credential Access | T1550 | Use Alternate Authentication Material | Inferred | SmartConsole admin tokens; M365 token risk |
Credential Access | T1003 | OS Credential Dumping | Inferred follow on | Post EoP on AD FS/SharePoint hosts (tooling not named) |
Credential Access | T1078 | Valid Accounts | Inferred | Stolen M365 and federated sessions |
Discovery | T1659 | Content Injection | Inferred | Langflow prompt injection inside hijacked flows |
Lateral Movement | T1078 | Valid Accounts | Inferred | SSO blast radius after AD FS compromise |
Lateral Movement | T1550 | Alternate Authentication Material | Inferred | Token replay class risk |
Collection | T1005 | Data from Local System | Mentioned unconfirmed + inferred | MCBS/DentaQuest bulk data outcomes |
Command and Control | T1071.001 | Web Protocols | Mentioned unconfirmed + inferred | TELESHIM family Telegram/web style C2 |
Command and Control | T1105 | Ingress Tool Transfer | Mentioned unconfirmed + inferred | TELESHIM / MIXEDKEY / BINDCLOAK delivery |
Exfiltration | T1020 | Automated Exfiltration | Mentioned unconfirmed + inferred | MCBS multi TB claim pattern |
Impact | T1486 | Data Encrypted for Impact | Mentioned unconfirmed | PEAR ransomware narrative (exfil/extortion emphasized more than confirmed encryption telemetry in available text) |
Mapping by active problem set (operator view)
Identity and collaboration exploitation
Inferred: T1190, T1068, T1505.003, T1059.001, T1059.003, T1552.004, T1078, T1133
Official vendor map: not published in consulted sources
AI gateway KEV (Langflow)
Inferred: T1190 (if exposed), object level abuse as credential access T1552.001, T1659 Content Injection
Official vendor map: not published
Security management plane (SmartConsole)
Inferred: T1190, T1550, T1078
Official vendor map: not published
Wi Fi M365 harvest
Mentioned unconfirmed: T1040, T1556
Inferred follow on: T1078, T1550
SourTrade
Mentioned unconfirmed: T1566.002, T1204.001, T1027
Inferred: T1620
TELESHIM set
Mentioned unconfirmed: T1071.001, T1105
Inferred: same pair for egress hunting
Healthcare breach outcomes (MCBS, DentaQuest)
Mentioned unconfirmed: T1486, T1005, T1020
Root initial access technique: insufficient source data
Control coverage checklist (use as gap analysis, not attribution)
Technique emphasis | Control that should already exist | Gap if missing today |
|---|---|---|
T1190 / T1068 | Emergency patch SLA, attack surface reduction, WAF | Unpatched SharePoint/AD FS/edge roles |
T1505.003 | FIM on web trees, EDR webshell analytics | No ASPX integrity monitoring |
T1552.004 | Machine key rotation runbook | Patch without key rotation |
T1078 / T1550 | Phishing resistant MFA, Continuous Access Evaluation | Passwords only on M365 |
T1040 / T1556 | Device compliant CA, VPN preference for mail | Travel auth allowed from any network |
T1620 / T1027 | Memory behavioral EDR | Hash only AV |
T1071.001 / T1105 | Egress allowlists on servers | Telegram API open from Tier 0 |
T1005 / T1020 / T1486 | DLP, bulk export alerts, IR retainer | No exfil baseline |
Chapter 05 - Governance, Risk & Compliance
SharePoint + AD FS exploitation: regulatory and business risk exposure
Regulatory exposure:
Entities under CISA BOD KEV obligations: track CVE-2026-56155 deadline 28 July 2026 and any remaining SharePoint KEV items (including CVE-2026-45659 class due dates; verify live catalog)
If compromise leads to personal data access: evaluate GDPR (72 hour supervisory authority notice), DPDP Act 2023 (India, relevant for Bengaluru operators), HIPAA only if PHI systems ride on affected identity/SharePoint, SEC cyber disclosure for US public companies upon materiality determination
Preserve volatile evidence (memory, IIS logs, AD FS audit) before rebuild
Business risk impact:
Operational: Federation outage or forced password/key rotation waves; SharePoint collaboration downtime
Reputational: Identity compromise narratives travel faster than patch notes
Financial: IR retainers, forced crypto key/certificate re issue, potential ransomware follow on (not confirmed in consulted sources)
Threat actor attribution:
No confirmed attribution available for these exploitation events.
CISO risk decision: Escalate — KEV deadline + dual ITW zero days on identity/collaboration plane.
Langflow KEV: regulatory and business risk exposure
Regulatory exposure:
API keys often unlock cloud tenants holding regulated data; treat key leak as potential personal data breach precursor
AI processing of personal data may engage DPIA obligations under GDPR/DPDP if agents handle PII
Business risk impact:
Shadow AI instances outside asset inventory = untracked blast radius
Cloud spend fraud and secondary tenant compromise after key theft
CISO risk decision: Escalate for any production/internet Langflow; monitor lab only air gapped instances after upgrade to 1.9.1+.
SmartConsole: regulatory and business risk exposure
Compromise of security management plane can falsify logs and weaken control evidence for SOC2/ISO 27001 audits
Downstream: incorrect firewall policy push can create silent exposure windows
CISO risk decision: Escalate if management GUIs were internet reachable; else monitor after patch verification and token reissue.
MCBS PEAR extortion and DentaQuest disclosure: regulatory and business risk exposure
Regulatory exposure:
HIPAA breach notification duties for covered entities and business associates once discovery thresholds are met
State breach statutes in the United States may impose shorter or parallel clocks
DentaQuest scale (23M+) implies multi jurisdiction notice complexity and potential regulator inquiry
MCBS ~1.2M individuals plus claimed 3 TB exfiltration under active extortion: treat notification readiness as same day legal work
International parents or processors: GDPR/DPDP assessment if any EU or Indian personal data was in scope
Business risk impact:
Reputational and financial risk is significant at DentaQuest scale; regulatory fines are plausible but not quantified in consulted sources
Contractual cascade: employer groups, provider networks, and BAAs may trigger customer notice and audit rights
Extortion pressure (PEAR/MCBS) adds availability and disclosure timing risk beyond pure confidentiality
Threat actor attribution:
PEAR named for MCBS only at Low confidence; no attribution offered for DentaQuest intrusion in consulted sources.
CISO risk decision:
Escalate if you are the victim, a business associate, or hold interconnected PHI with either entity
Monitor if no data sharing relationship exists, but still watch for secondary fraud using leaked demographics
Evidence and counsel rules:
Verify victim counts and dates against primary notices before external statements
Preserve logs; do not destroy backup media that may hold forensic value
Public CTI secondary counts are not a substitute for counsel driven notification analysis
M365 Wi Fi harvest: regulatory and business risk exposure
Credential theft can become a personal data breach if mailbox or Files content is accessed after takeover
Public company materiality analysis may apply if widespread executive account compromise occurs
Control failure narrative: lack of phishing resistant MFA is increasingly difficult to defend to auditors after an active network layer harvest pattern is known
CISO risk decision: Escalate MFA and Conditional Access gaps to emergency IAM change; do not leave as quarterly roadmap.
SourTrade: regulatory and business risk exposure
Financial services and crypto adjacent staff at risk of workstation compromise and subsequent payment fraud
If corporate banking users are hit, expect rapid fraud desk coordination and possible SAR processes depending on jurisdiction
CISO risk decision: Monitor with targeted EDR assurance for finance users; Escalate on first confirmed in memory Bun delivery hit.
TELESHIM set: regulatory and business risk exposure
Government Middle East targets: national security and public sector information classification regimes apply
Partners and contractors connected to those governments should assume heightened spillover risk
CISO risk decision: Escalate for government and defense contractors in region; monitor for others via Telegram egress baselining.
July high CVSS infrastructure items without ITW confirmation
Still material for safety and uptime risk (Hyper V guest to host, DHCP RCE, RDP without NLA)
Governance angle: document risk acceptance only with time bounded exceptions if patch delays are unavoidable
Board level risk summary (today)
Attackers are actively abusing unpatched Microsoft identity and SharePoint flaws while a US federal fix deadline for AD FS hits tomorrow. AI workflow software has entered the same must patch now catalog as traditional edge bugs. In parallel, healthcare breach math jumped on secondary reporting (about 24 million people across two disclosures), and credential theft is happening on the network path rather than only in the inbox. The board question is not “did we install Patch Tuesday?” It is “can we prove AD FS, SharePoint, Langflow, and SmartConsole are patched, keys and tokens rotated, M365 requires phishing resistant MFA, and we know whether we are a healthcare business associate in the MCBS/DentaQuest blast radius?”
Chapter 06 - Adversary Emulation
Scope caveat
No official vendor ATT&CK technique map was published in consulted sources for the ITW zero days. Emulation below is CVE behavior based and inferred technique based for purple team validation of controls. It is not a claim that a named actor playbook was reverse engineered from primary IR telemetry. Do not run offensive tests on production federation, healthcare data stores, or third party systems without written authorization.
Validation track: SharePoint chain (inferred T1190 / T1068 / T1505.003 / T1552.004)
Defensive validation objectives:
Prove July SharePoint updates are installed on every farm
Prove AMSI full body scan is active where still required as compensating control
Prove machine keys rotated after patch
Prove EDR alerts when
w3wp.exespawns shells
Authorized test ideas (lab or change window only):
Pre/post patch configuration audit: build number and KB inventory versus Microsoft July 2026 baseline
AMSI: verify integration on SharePoint/IIS worker processes and Request Body Scan = Full before and after patch
FIM: touch a benign test ASPX in a non prod content path and confirm alert
Purple process test in non prod: simulated child process from a test app pool identity to validate SIEM rule fire (no real exploit payload)
Pass criteria:
100% internet reachable farms patched or isolated
Machine key rotation completed and documented
Alert fire on simulated worker child process within SOC MTTA target
Validation track: AD FS EoP (inferred T1068 / T1078)
Defensive validation objectives:
Prove CVE-2026-56155 cumulative is present before 28 July 2026 deadline
Prove low privilege interactive use on AD FS hosts is denied or closely watched
Prove federation change auditing is on
Authorized test ideas:
Lab AD FS: confirm July cumulative installed; regression test federation login and claim rules
Attempt standard user local logon to hardened AD FS PAW model (should fail)
Review and tabletop the 14 to 28 July auth and group membership timeline query
Pass criteria:
Patch evidence attached to KEV ticket
No unexplained new local admins in window
Trust/claim rule changes require dual control
Validation track: Langflow KEV (inferred T1552.001 / T1659)
Defensive validation objectives:
Prove no instance below 1.9.1 is reachable
Prove cross user
flow_idexecution is deniedProve secrets were rotated after exposure uncertainty
Authorized test ideas:
Purple style check on patched non prod: authenticated user A requests user B
flow_idon/api/v1/responses— expect denyInject benign canary string prompt in owned flow only; ensure monitoring catches suspicious secret oriented prompts in logs
Secret scan: confirm no long lived cloud keys remain in flow environment variables
Pass criteria:
Cross user execution denied
All production instances ≥ 1.9.1 or network isolated
Key rotation completion logged
Validation track: SmartConsole (inferred T1550 / T1078)
Defensive validation objectives:
Prove patched console versions only
Prove management GUI reachable only from jump hosts
Prove tokens issued outside jump hosts alert
Authorized test ideas:
Connect attempt from a non jump host VLAN (should fail at network policy)
Force logout all admin sessions post patch; require reauth
Confirm audit log entries for token issue are ingested by SIEM
Pass criteria:
Zero successful admin authentications from non jump hosts in 72h soak
Patch level inventory complete
Validation track: M365 Wi Fi harvest aftermath (inferred T1040 / T1556 / T1078)
Defensive validation objectives:
Prove phishing resistant MFA enrollment ≥ policy threshold (target 100% for staff, especially travelers)
Prove Conditional Access blocks or challenges low posture devices on public networks
Prove SOC sees impossible travel / new device signals
Authorized test ideas:
Tabletop: traveler on hospitality Wi Fi authenticates — expected controls and alerts
Staged non prod CA policy test with a break glass account in lab tenant
Sample 50 traveler accounts for MFA method quality (phishing resistant vs SMS)
Pass criteria:
SMS/voice not accepted as sole factor for corporate M365
CA reports show enforced device posture for Exchange/SharePoint Online
Validation track: SourTrade memory delivery (inferred T1620 / T1566.002)
Defensive validation objectives:
Prove EDR memory behavioral module enabled fleet wide
Prove Bun blocked or alerted where not approved
Prove proxy category controls for brand impersonation finance sites
Authorized test ideas:
In detonation lab only: benign Bun execution from browser parent to test detect/block policy (no criminal payloads)
EDR health check: memory scanning sensors reporting green on finance OU
Application control report: Bun allowlist exceptions reviewed
Pass criteria:
Memory detections enabled >95% endpoints
Unapproved Bun execution generates ticket
Validation track: TELESHIM Telegram C2 (inferred T1071.001 / T1105)
Defensive validation objectives:
Prove server subnets cannot reach Telegram API without exception
Prove alert path works when exception tags are abused
Authorized test ideas:
Controlled egress test from a lab server toward Telegram API endpoints — expect block+alert
DNS/proxy sinkhole list includes known Telegram API FQDNs for server policies
Pass criteria:
Default deny on server VLANs
Alert to SOC within MTTA target
Validation track: healthcare associate readiness (impact T1005 / T1020 / T1486 class outcomes)
Defensive validation objectives (no offensive emulation against victim environments):
Prove BAA and data flow map for MCBS/DentaQuest relationships exists
Prove notification decision tree and counsel contact tree work under tabletop
Prove bulk export alerts fire on a synthetic large query in non prod data mart
Pass criteria:
Named counsel and privacy lead on call roster
Tabletop completes notification timeline without unresolved ownership gaps
Emulation schedule suggestion (next 72 hours)
Order | Track | Why this order |
|---|---|---|
1 | AD FS patch validation | KEV 28 July |
2 | SharePoint patch, AMSI, keys, worker child alert | ITW chain |
3 | Langflow version and cross user deny | KEV + keys |
4 | SmartConsole jump host and tokens | Management plane |
5 | M365 MFA/CA traveler scenarios | Active harvest pattern |
6 | EDR memory + Bun | SourTrade |
7 | Telegram server egress | TELESHIM |
8 | Healthcare associate tabletop | Regulatory clocks |
Explicit non actions
Do not run public SharePoint or AD FS exploit code against production to “prove” ITW
Do not attempt real SmartConsole auth bypass outside vendor approved test guidance
Do not touch third party healthcare networks in the name of validation
Do not treat this chapter as a substitute for official ATT&CK mapped adversary emulation libraries until primary technique evidence improves
Component | Pull on score |
|---|---|
Microsoft ITW + CrowdStrike aligned CVSS/CWE depth | Strong up |
KEV deadline consistency for AD FS / SharePoint linked / Langflow | Strong up |
SmartConsole ITW patch narrative | Moderate up |
Same day fresh long form IR house volume | Down |
Classic IOC availability | Hard down (0) |
Actor attribution quality | Hard down |
Official ATT&CK in consulted sources | Hard down |
Healthcare breach scale via secondary news only | Down |
Dual track merge complexity | Mild down |
