Threat briefs · monthly Patch Tuesday intelligence

JULY 2026 · ITS-EXV-2026-0722

Check Point's Management Plane — Three Bypasses in One Release, One Already Exploited, and the Firewall Fleet Downstream

1 ACT
Read the brief →
JULY 2026 · ITS-EXV-2026-0723

AgentForger — When a Phishing Link Installs an AI Insider

0 ACT
Read the brief →
JULY 2026 · ITS-EXV-2026-0720

The Hugging Face Breach — A Sandbox With One Wall, Ordinary Bugs on the Way In, and the Defenders' Tools Refusing to Help

1 ACT
Read the brief →
JULY 2026 · ITS-EXV-2026-0513

Qilin Ransomware via PAN-OS GlobalProtect — Cookie Forgery, VPN Footholds, Domain-Wide Encryption

1 ACT
Read the brief →
JULY 2026 · ITS-EXV-2026-0715

Microsoft July 2026 Threat & Deployment Brief — Active Exploitation, Chain Cuts, End-of-Support Risks

4 ACT
Read the brief →
JUNE 2026 · ITS-EXV-2026-0609

Microsoft June 2026 Threat & Deployment Brief — Three Unauthenticated 9.8 RCEs, No Active Exploitation, Structural Risk

1 ACT
Read the brief →
MAY 2026 · ITS-EXV-2026-0512

Microsoft May 2026 Threat & Deployment Brief — Zero-Day-Free, Wormable Netlogon 9.8, Structural Risk

1 ACT
Read the brief →
APRIL 2026 · ITS-EXV-2026-0414

Microsoft April 2026 Threat & Deployment Brief — Active Exploitation, Unauthenticated 9.8, Patch-Quality Failures

3 ACT
Read the brief →
MARCH 2026 · ITS-EXV-2026-0310

Microsoft March 2026 Threat & Deployment Brief — No Active Exploitation, Prioritise Cycle, Cloud-Fixed 9.8

0 ACT
Read the brief →
FEBRUARY 2026 · ITS-EXV-2026-0210

Microsoft February 2026 Threat & Deployment Brief — Six Exploited Zero-Days, KEV on Release Day, Chain Cuts

2 ACT
Read the brief →
JANUARY 2026 · ITS-EXV-2026-0113

Microsoft January 2026 Threat & Deployment Brief — Exploited Zero-Day, Secure Boot Bypass, Severity Inversion

1 ACT
Read the brief →